BlackSuit Ransomware Hits Stepping Stone San Diego Nonprofit

Incident Date: Nov 12, 2024

Attack Overview
VICTIM
Stepping Stone of San Diego
INDUSTRY
Manufacturing
LOCATION
USA
ATTACKER
Black Suit
FIRST REPORTED
November 12, 2024

BlackSuit Ransomware Targets Stepping Stone of San Diego

In a recent cyberattack, the BlackSuit ransomware group has claimed responsibility for targeting Stepping Stone of San Diego, a nonprofit organization renowned for its addiction recovery and mental health services tailored to the LGBTQ+ community. This attack highlights the vulnerabilities faced by healthcare organizations, particularly those with limited resources for cybersecurity defenses.

About Stepping Stone of San Diego

Founded in 1976, Stepping Stone of San Diego is a nonprofit organization dedicated to providing comprehensive addiction recovery services. It stands out in the industry for its focus on the LGBTQ+ community, offering a range of evidence-based treatment programs, including residential treatment, outpatient services, and sober living facilities. The organization operates with a relatively small team of 11 to 50 staff members, which allows for personalized care but may also contribute to its vulnerability to cyber threats.

Details of the Ransomware Attack

The attack on Stepping Stone involved the encryption of a significant volume of files, totaling 154,608, with a combined size of over 534 billion bytes. Critical operational and financial data, including directories such as Finance, Payroll Returns, Contracts, and Corporate Documents, were compromised. The attack has potentially exposed sensitive information, posing a significant risk to the organization's operations and the privacy of its clients.

BlackSuit Ransomware Group

BlackSuit is a relatively new ransomware group that emerged in 2023, known for its double extortion tactics. This involves encrypting victim data and exfiltrating sensitive information to pressure victims into paying ransoms. The group is linked to the Royal ransomware syndicate, indicating a continuation of sophisticated cybercrime tactics. BlackSuit typically gains access to networks through phishing emails, compromised RDP credentials, and exploitation of public-facing applications.

Potential Vulnerabilities

Stepping Stone's focus on providing affordable care and its relatively small size may have contributed to its vulnerability to cyberattacks. Nonprofit organizations often face challenges in allocating resources for cybersecurity measures, making them attractive targets for ransomware groups like BlackSuit. The attack underscores the need for heightened cybersecurity awareness and defenses, particularly in the healthcare sector.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.