BianLian Ransomware Hits Falco Sult & Company in Major Breach

Incident Date: Nov 05, 2024

Attack Overview
VICTIM
Falco Sult
INDUSTRY
Business Services
LOCATION
USA
ATTACKER
Bianlian
FIRST REPORTED
November 5, 2024

BianLian Ransomware Group Targets Falco Sult & Company, P.S.

Falco Sult & Company, P.S., a distinguished accounting and business consulting firm based in Redmond, Washington, has fallen victim to a ransomware attack orchestrated by the notorious BianLian group. The breach, discovered on November 6, involves the exfiltration of 2.2 terabytes of sensitive data, highlighting the ongoing threat posed by ransomware actors to professional service providers.

About Falco Sult & Company, P.S.

Founded in 1991 by Chris Falco and Bruce Sult, Falco Sult is a non-traditional CPA firm that emphasizes personalized financial services. With a workforce of 25 to 100 employees, the firm serves a diverse range of industries, including manufacturing, bio-science, real estate, and niche markets like cannabis and wine. Their unique approach focuses on holistic financial strategies and long-term client relationships, setting them apart in the business services sector.

Falco Sult's commitment to personalized service and strategic guidance makes them a valuable partner for privately-held businesses. However, this also makes them a lucrative target for cybercriminals, as they handle vast amounts of confidential client data.

Attack Overview

The BianLian ransomware group, known for its sophisticated tactics, claims to have exfiltrated a significant volume of data from Falco Sult's systems. While the specific nature of the data remains undisclosed, the sheer volume suggests a potentially extensive exposure of sensitive financial and business information. This attack underscores the vulnerabilities faced by firms in the professional services sector, which often hold critical client data.

About BianLian Ransomware Group

BianLian, a rapidly evolving ransomware group, has gained notoriety since its emergence in 2022. Initially appearing as an Android banking trojan, the group has transformed into a sophisticated ransomware operation. Known for its adaptability, BianLian employs a multi-stage attack methodology, often gaining initial access through compromised RDP credentials or phishing. The group has shifted from a double-extortion model to a pure data exfiltration approach, focusing on stealing data and threatening to release it to compel victims to pay.

BianLian's ability to adapt and employ diverse attack strategies makes them a formidable threat. Their focus on high-value sectors, such as healthcare and finance, highlights their strategic targeting of organizations that handle sensitive data.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.