APT73 Ransomware Breach Compromises Borrer Executive Search's Sensitive Data
APT73 Ransomware Attack on Borrer Executive Search
Company Profile
Borrer Executive Search, founded in 2010 and based in Lausanne, Switzerland, is a boutique search and selection firm accredited by AESC. Specializing in identifying and placing high-caliber executives, the firm operates across Switzerland, Europe, the Middle East, Africa, and Asia-Pacific. Led by Managing Partners Jennifer and Emile Borrer, the company focuses on management positions in global operations, commercial leadership, finance, and human resources. Known for its rigorous search process and transparent approach, Borrer Executive Search provides personalized attention and customized solutions for each client engagement.
Attack Overview
On June 14, 2024, Borrer Executive Search experienced a data breach perpetrated by the ransomware group APT73. The attack resulted in the compromise of 2.5MB of internal documents and agreements. The breach was announced on APT73's dark web leak site, ERALEIGNEWS, which follows a LockBit-styled approach. The exact method of penetration remains unclear, but APT73 typically employs phishing attacks to compromise systems and deploy ransomware.
Ransomware Group Profile
APT73 is a relatively new ransomware group that emerged in December 2023. The group operates a TOR-based data leak site and has previously targeted TRIFECTA, a U.S.-based customer service platform. APT73's modus operandi includes phishing attacks and the use of a LockBit-styled data leak site. The group operates from an IP address in Prague, Czechia, and utilizes AS9009, a network associated with various malicious activities. Despite some amateurish traits, APT73 poses a significant threat due to its sophisticated ransomware tactics.
Vulnerabilities and Impact
Borrer Executive Search's focus on high-level executive placements makes it a lucrative target for ransomware groups like APT73. The firm's extensive network and access to sensitive client information increase its vulnerability. The breach of internal documents and agreements could have severe implications for both the firm and its clients, potentially leading to financial losses and reputational damage.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!