CiphBit Ransomware Strikes António Belém & Gonçalves SROC

Incident Date: Dec 13, 2024

Attack Overview
VICTIM
António Belém & António Gonçalves
INDUSTRY
Business Services
LOCATION
Portugal
ATTACKER
Ciphbit
FIRST REPORTED
December 13, 2024

Ransomware Attack on António Belém & António Gonçalves SROC by CiphBit

António Belém & António Gonçalves SROC, a prominent auditing and financial consulting firm in Portugal, has recently fallen victim to a ransomware attack orchestrated by the CiphBit group. This attack highlights the growing threat of ransomware in the business services sector, particularly targeting firms with valuable financial data.

Company Profile and Vulnerabilities

Founded in the 1990s, António Belém & António Gonçalves SROC specializes in auditing and consulting services across various sectors, including public health, real estate, and family businesses. The firm is known for its commitment to integrity, competence, and independence, providing high-quality audit services that comply with international standards. Despite its strong reputation, the firm’s reliance on digital systems for managing sensitive financial data makes it a lucrative target for cybercriminals.

The firm’s size and operational capacity are not explicitly detailed, but it is known to employ a team of professionals with diverse expertise in management, economics, accounting, and auditing. This multi-disciplinary approach, while beneficial for tackling complex projects, also presents potential vulnerabilities if cybersecurity measures are not robustly implemented.

Attack Overview

The CiphBit ransomware group has claimed responsibility for the attack, threatening to release the firm’s sensitive data within a two to three-day timeframe. This tactic is part of CiphBit’s double-extortion strategy, which involves encrypting data and threatening to leak it unless a ransom is paid. Such strategies are designed to increase pressure on victims, compelling them to comply with ransom demands to avoid reputational damage and data loss.

About CiphBit Ransomware Group

CiphBit is a relatively new player in the ransomware landscape, first observed in April 2023. The group is known for its aggressive double-extortion tactics and has targeted various industries, including banking, healthcare, and manufacturing. CiphBit operates under a ransomware-as-a-service model, allowing affiliates to use their tools for a share of the profits. This model has contributed to their rapid rise in victim count, making them a significant threat in the cybercrime ecosystem.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.