On June 11, an attacker or group operating under the alias “ByteToBreach” breached LVM’s internal “GeoServer” system, which the company uses for processing geospatial data. The attacker then scouted the internal systems and penetrated them ever deeper. On June 22, an active attack began, including the encryption and exfiltration of data.

The attacker breached the LVM system via a system that had not been updated for at least two years. Likely, it had not been updated for even longe...