Amourgis Associates Hit by Hunters International Ransomware

Incident Date: Nov 11, 2024

Attack Overview
VICTIM
Amourgis & Associates
INDUSTRY
Media & Internet
LOCATION
USA
ATTACKER
Hunters International
FIRST REPORTED
November 11, 2024

Ransomware Attack on Amourgis & Associates by Hunters International

On November 12, Amourgis & Associates, a well-established Ohio-based law firm, became the latest victim of a ransomware attack by the notorious cybercriminal group Hunters International. Specializing in personal injury and bankruptcy law, the firm operates multiple offices across Ohio, including in Cleveland, Akron, and Columbus. With approximately 44 employees, Amourgis & Associates is recognized for its consumer-focused legal services, exclusively representing individuals rather than businesses or insurance companies.

Attack Overview

The attack on Amourgis & Associates involved the exfiltration of sensitive data, although encryption was not employed. This breach highlights the firm's vulnerability to sophisticated cyber threats, particularly given its extensive handling of personal and financial information. The firm's commitment to consumer rights and its significant presence in Ohio's legal landscape make it a notable target for cybercriminals seeking to exploit sensitive data.

Hunters International: A Rising Threat

Hunters International, a Ransomware-as-a-Service (RaaS) group, emerged in October 2023, leveraging code from the dismantled Hive ransomware operation. Known for its double extortion tactics, the group combines data theft with encryption to pressure victims into paying ransoms. However, in the case of Amourgis & Associates, the group opted for data exfiltration without encryption, possibly to maximize leverage through the threat of public exposure.

Distinguishing Features of Hunters International

Hunters International distinguishes itself through its sophisticated use of Rust-based ransomware, allowing cross-platform attacks on Windows and Linux environments. The group is adept at bypassing advanced security measures, as demonstrated in previous high-profile attacks. Their modus operandi often involves phishing campaigns and exploiting remote desktop protocols to gain initial access, followed by lateral movement and data exfiltration.

Potential Vulnerabilities

Amourgis & Associates' extensive handling of sensitive client data, combined with its consumer-focused approach, may have made it an attractive target for Hunters International. The firm's reliance on digital systems for managing legal cases and client information could have provided multiple entry points for the attackers. This incident underscores the critical need for enhanced cybersecurity measures in law firms handling sensitive personal and financial data.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.