Compass Communications Targeted by RA World Ransomware

Incident Date: Dec 11, 2024

Attack Overview
VICTIM
Compass Communications
INDUSTRY
Telecommunications
LOCATION
New Zealand
ATTACKER
RA World
FIRST REPORTED
December 11, 2024

Ransomware Attack on Compass Communications by RA World

Compass Communications, a prominent telecommunications provider based in Auckland, New Zealand, has fallen victim to a ransomware attack orchestrated by the notorious RA World group. The attack has resulted in the exfiltration of 250 gigabytes of sensitive data, including financial records, customer information, and HR files. The cybercriminals have threatened to release this data on January 1, 2025, unless their demands are met.

About Compass Communications

Established in 1995, Compass Communications is a 100% Kiwi-owned company that has grown to become a key player in New Zealand's telecommunications sector. The company offers a wide range of services, including high-speed broadband, voice communication solutions, and managed IT services for both residential and business customers. With a workforce of over 100 employees, Compass is recognized for its customer-centric approach and commitment to providing reliable connectivity solutions across New Zealand, including challenging rural areas.

Details of the Attack

The RA World group, known for its sophisticated ransomware operations, listed Compass Communications on its darknet leak site, providing a 26.9-megabyte archive of sample data as proof of the breach. This sample includes service agreements, financial statements, and customer banking details. Compass Communications has confirmed the breach and is working with external security experts to assess the full impact. The company has also notified relevant authorities, including the Privacy Commissioner, and is in the process of contacting affected customers to mitigate potential risks.

RA World Ransomware Group

RA World, previously known as the RA Group, has been active since at least April 2023. The group distinguishes itself by using a customized version of Babuk ransomware, which encrypts data and allows victims to communicate with attackers via the qTox messaging app. RA World typically gains access through misconfigured internet-facing devices, stealing credentials and moving laterally within networks. Security researchers have noted a possible link between RA World and a Chinese threat actor known as Bronze Starlight.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.