Blacknevas ransomware targets Canadian greenhouse company | #ransomware | #cybercrime


On August 12, 2026, the ransomware group Blacknevas claimed responsibility for a cyberattack against Westbrook Greenhouse Systems (westbrooksystems.com), a prominent Canadian company operating in the commercial greenhouse sector. According to the group, sensitive company data will be released publicly unless a satisfactory negotiation takes place. In a statement, the threat actors said the full leak would be published soon unless a company representative made contact through the channels they provided.

The incident adds to a growing pattern of ransomware attacks affecting organizations of varying sizes across many industries, including agriculture and horticulture technology providers that may not traditionally see themselves as prime cybercrime targets. Security specialists note that companies in this sector often manage valuable operational, financial, and client data while running IT infrastructure that may not always keep pace with the sophistication of modern threat actors.

In light of incidents like this, cybersecurity experts recommend that organizations take a proactive, multi-layered approach to reducing their risk. This includes ongoing monitoring of the dark web and infostealer activity to catch breached credentials or leaked data before it can be exploited further, as well as conducting a full compromise assessment to understand how an intrusion occurred and whether attackers retain any lingering access. Ensuring backups are current, encrypted, and stored offline using immutable systems is also considered essential, since reliable backups can significantly limit the damage caused by encryption-based attacks.

Experts further advise integrating external threat intelligence feeds into existing security monitoring systems for faster detection and response, alongside strengthening employee awareness through phishing simulations and the enforcement of multi-factor authentication, since compromised or reused credentials remain one of the most common entry points for attackers. Should a breach occur, organizations are encouraged to involve professional incident response teams, threat analysts, and legal counsel before engaging in any communication with ransomware groups or intermediaries.

Threat intelligence firms such as DeXpose specialize in helping organizations detect these risks before they escalate into public incidents. The company’s approach combines automated monitoring of the deep and dark web, including ransomware leak sites, stolen credential markets, and malware log dumps, with surveillance of Telegram channels and underground forums, supported by human analyst verification. This allows for timely alerts when a breach is linked to a company’s domains, email addresses, or key personnel, and can help connect leaked credentials to underlying infostealer infections, sometimes weeks before a ransom demand becomes public. Such monitoring also extends to supply chain and third-party exposure, giving organizations broader visibility into risks beyond their own networks.

As ransomware attacks continue to affect companies across sectors, including those serving the horticulture and greenhouse industry, maintaining early visibility into potential exposure is increasingly viewed as a critical component of operational resilience.



Click Here For The Original Source.

——————————————————–

..........

.

.