Group-IB DFIR team contracted by Fawry to provide incident response support following LockBit attack

Group-IB, a leading creator of cybersecurity technologies to investigate, prevent, and fight digital crime, has been contracted by Fawry, one of the largest Egyptian e-payment companies, to investigate an incident after the ransomware group LockBit, on November 8 published on its dedicated leak site (DLS) a sample of data allegedly stolen during a breach of Fawry’s infrastructure.

Fawry selected Group-IB, which has more than two decades of Incident Response experience, due to Group-IB’s specialization in solving highly complicated cases and the fact that Group-IB Threat Intelligence has tracked LockBit since the group’s inception. Both Group-IB and Fawry coordinated on and consented to the publication of this statement.

As of November 24, Group-IB’s Digital Forensics and Incident Response (DFIR) team can confirm Fawry’s production segment was out of scope of the LockBit ransomware attack, and that data was exfiltrated from Fawry’s testing environment during a past attack.

Group-IB’s DFIR team started its incident response engagement on November 9. Over the course of three days, they deployed the company’s proprietary advanced monitoring solutions across 100% of Fawry’s server infrastructure. Both segments — production and testing environment — are clean as of November 24 of LockBit presence. The Fawry team has performed 100% incident eradication for observed indicators of LockBit compromise, and Group-IB experts confirmed the completion of network cleanup.

At the time of writing, Group-IB’s advanced monitoring solutions are covering 100% of Fawry’s production and testing environments, as confirmed by Fawry’s infrastructure team.

About Group-IB

Established in 2003, Group-IB is a leading creator of predictive cybersecurity technologies to investigate, prevent, and fight digital crime globally. Headquartered in Singapore, and with Digital Crime Resistance Centers in the Americas, Europe, Middle East and Africa, Central Asia, and the Asia-Pacific, Group-IB delivers predictive, intelligence-driven defense by analysing and neutralizing regional and country-specific cyber threats via its Unified Risk Platform, offering unparalleled defense through its industry-leading Cyber Fraud Intelligence Platform, Cloud Security Posture Management, Threat Intelligence, Fraud Protection, Digital Risk Protection, Managed Extended Detection and Response (XDR), Business Email Protection, and External Attack Surface Management solutions, catering to government, retail, healthcare, gaming, financial sectors, and beyond. Group-IB collaborates with international law enforcement agencies like INTERPOL, Europol, and AFRIPOL to fortify cybersecurity worldwide, and has been awarded by advisory agencies including Datos Insights, Gartner, Forrester, Frost & Sullivan, and KuppingerCole.

For more information, visit us at www.group-ib.com or connect with us on LinkedIn, X, Facebook, and Instagram.

Discover our podcasts to hear from leading voices on Masked Actors and Fraud Intel, where top cybersecurity experts share real-world experiences, emerging trends, and practical insights to help you stay one step ahead in the fight against cyber crime.