• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    Estée Lauder data breach

    Estée Lauder Confirms Cyberattack Affecting Personal Information

    Craneware data breach

    Craneware Confirms Data Breach, Employee Records Among Exposed Data

    Dubai Police fraudulent visa ads

    Dubai Police Warns Against Online Scams Promising Work and Visit Visas

    CVE-2026-42533

    CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw

    Fairlife ransomware attack

    Fairlife Ransomware Attack Hits Production Systems, U.S. Operations Suspended

    weekly round

    The Cyber Express Weekly Roundup: TikTok Age Verification Probe, Healthcare Data Breach, Qantas Ruling, and Major Cyberattacks

    ClickFix Attacks

    ClickFix Attacks Drive UAC-0145 Cyber Campaigns, CERT-UA Warns

    Chinese money laundering

    US Charges Two Over $43M Chinese Money Laundering Operation

    Notepad++ vulnerabilities

    Critical Notepad++ Bugs Could Lead to Code Execution, Patch Available

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    global crypto investment scam

    Dutch Police Arrest Key Suspect in €100M Global Crypto Investment Scam

    Australia-India PACTS

    Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

    FBI Warns of Malicious Traffic

    FBI Warns of a Hidden Web Tactic Fueling Phishing and Ransomware

    Ukraine Joins EU Cybersecurity Reserve

    What Ukraine’s Entry Into the EU Cybersecurity Reserve Means

    UK social media ban

    UK Social Media Ban for Under-16s Could Take Effect by Spring 2027

    Ransomware Preparedness

    Ransomware Preparedness Must Be a Boardroom Priority: NCSC Chief

    AI legal assistants

    AI Heads to UK Courts, Bringing New Cybersecurity and Governance Challenges

    VerdantBamboo

    China’s VerdantBamboo Experimented With Three Re-Entries and Three Malware in a Company Network

    Crypto Scam, Crypto

    New Threat Actor Targets Crypto Firms’ Development Infrastructure

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Australia-India PACTS

    Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

    Sunil Varkey

    Sunil Varkey Joins Hexaware Technologies as EVP & CISO

    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI, AI-assisted Cyberattacks

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    Estée Lauder data breach

    Estée Lauder Confirms Cyberattack Affecting Personal Information

    Craneware data breach

    Craneware Confirms Data Breach, Employee Records Among Exposed Data

    Dubai Police fraudulent visa ads

    Dubai Police Warns Against Online Scams Promising Work and Visit Visas

    CVE-2026-42533

    CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw

    Fairlife ransomware attack

    Fairlife Ransomware Attack Hits Production Systems, U.S. Operations Suspended

    weekly round

    The Cyber Express Weekly Roundup: TikTok Age Verification Probe, Healthcare Data Breach, Qantas Ruling, and Major Cyberattacks

    ClickFix Attacks

    ClickFix Attacks Drive UAC-0145 Cyber Campaigns, CERT-UA Warns

    Chinese money laundering

    US Charges Two Over $43M Chinese Money Laundering Operation

    Notepad++ vulnerabilities

    Critical Notepad++ Bugs Could Lead to Code Execution, Patch Available

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    global crypto investment scam

    Dutch Police Arrest Key Suspect in €100M Global Crypto Investment Scam

    Australia-India PACTS

    Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

    FBI Warns of Malicious Traffic

    FBI Warns of a Hidden Web Tactic Fueling Phishing and Ransomware

    Ukraine Joins EU Cybersecurity Reserve

    What Ukraine’s Entry Into the EU Cybersecurity Reserve Means

    UK social media ban

    UK Social Media Ban for Under-16s Could Take Effect by Spring 2027

    Ransomware Preparedness

    Ransomware Preparedness Must Be a Boardroom Priority: NCSC Chief

    AI legal assistants

    AI Heads to UK Courts, Bringing New Cybersecurity and Governance Challenges

    VerdantBamboo

    China’s VerdantBamboo Experimented With Three Re-Entries and Three Malware in a Company Network

    Crypto Scam, Crypto

    New Threat Actor Targets Crypto Firms’ Development Infrastructure

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Australia-India PACTS

    Australia-India PACTS to Deepen Cybersecurity and Tech Collaboration

    Sunil Varkey

    Sunil Varkey Joins Hexaware Technologies as EVP & CISO

    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI, AI-assisted Cyberattacks

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily Data Breach News

LockBit Ransomware Gang Claims Italian Winery Cantina Tollo as Victim

The perpetrators have left a warning for Cantina Tollo, threatening to publicly release all confidential information unless their demands for ransom are met.  

Ashish Khaitan by Ashish Khaitan
February 8, 2023
in Data Breach News, Firewall Daily
0
Italian Winery Cantina Tollo
640
SHARES
3.6k
VIEWS
Share on LinkedInShare on Twitter

Premier Italian winery Cantina Tollo has disclosed a malicious cyber attack. The announcement came close on the  heels of LockBit ransomware gang claiming Cantina Tollo as a victim. 

On January 30, 2023, an unknown threat actor struck the company, leaving it to mitigate the damage. 

In the last few days we have been doing everything necessary to fix the situation in order to avoid further consequences on the privacy and security of the personal data of our customers and our company,” said the company announcement.

Following that event, necessary measures were put in place to remedy possible violations of personal data.

The Cyber Express has reached out to Cantina Tollo regarding the said cyber attack and is yet to receive a response from them.   

Cantina Tollo data breach explained 

The LockBit ransomware gang posted a threat note on its leak site on Tuesday, February 7, hours before the company disclosed the incident. However, the company disclosure does not mention that it was a ransomware attack.

According to the threat note, the data was accessed on January 30, the day of attack mentioned in the company disclosure. The ransomware gang threatens to publish the data if ransom is not Paid by February 15.

In a bid to negotiate, the ransomware gang has put a $1000 bill to extend the deadline by 24 hours. To destroy the data, the gang has asked for a payment of $249,999.

Ironically, the gang has asked for the same amount for downloading the data. 

lockBit

Cantina Tollo, ransomware, and attack mitigation

Cantina Tollo claims to have taken swift action in response to the attack, including disabling and separation of the impacted systems from its network.

“These measures, while involving the interruption of some services for a limited period of time, are necessary to avoid the increasing of the the consequences of the attack,” said the company disclosure.

Being an Italian company, the company is bound to make the disclosure as per the guideline outlined in Article 34 of the EU Regulation 2016/679 (GDPR). 

Cantina Tollo is known for its sprawling vineyards spanning 2,500 hectares, producing wine only from the indigenous and signature grapes of the area, grown in the temperate Mediterranean climate.

LockBit ransomware gang: Mode of operation

The LockBit ransomware gang operates through a mode of encrypting and exfiltrating files on targeted devices, then demanding a ransom payment for their return.

Their latest strain, LockBit 3.0, is also known as LockBit Black and was first discovered in September 2019. It primarily targets organizations with the ability to pay large ransom amounts and has the ability to self-propagate.

LockBit 3.0, discovered in late 2022, has retained most of its previous functionality and added new behaviors, making it harder to analyze.

It may require an affiliate to enter a 32-character password to launch the ransomware binary. The typical attack process involves infecting the device, encrypting files, deleting services, and altering the wallpaper.

Failure to pay the ransom may result in the sale of the stolen data on the dark web. LockBit 3.0 is known to exploit Windows Defender to deploy Cobalt Strike and cause a chain of malware infections.

The LockBit group operates as a Ransomware-as-a-Service model, collaborating with affiliates who may not have the necessary resources for an attack.

According to a December 2022 alert by the U.S. Department of Health & Human Services, a portion of the ransom payment goes back to the affiliated hacker.

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: Cantina TolloCantina Tollo Cyber Attack
Previous Post

OpenSSL Releases Update to Fix High Severity Vulnerability, And More

Next Post

ChatGPT Continues to Fail in Fight Against Malicious Content

Next Post
ChatGPT

ChatGPT Continues to Fail in Fight Against Malicious Content

Q1 2026 Threat Reports

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

Estée Lauder data breach
Firewall Daily

Estée Lauder Confirms Cyberattack Affecting Personal Information

July 21, 2026
Craneware data breach
Firewall Daily

Craneware Confirms Data Breach, Employee Records Among Exposed Data

July 20, 2026
Dubai Police fraudulent visa ads
Cyber News

Dubai Police Warns Against Online Scams Promising Work and Visit Visas

July 20, 2026
CVE-2026-42533
Firewall Daily

CVE-2026-42533 Exposes Critical Pre-Auth nginx RCE Flaw

July 20, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information