Cybersecurity Breach: Ransomware Attack on Nikolaus & Hohenadel

Incident Date: May 06, 2024

Attack Overview
VICTIM
Nikolaus and Hohenadel
INDUSTRY
Law Firms & Legal Services
LOCATION
USA
ATTACKER
Bianlian
FIRST REPORTED
May 6, 2024

Ransomware Attack on Nikolaus & Hohenadel by BianLian Group

Victim Profile: Nikolaus & Hohenadel, LLP

Nikolaus & Hohenadel, LLP is a prominent law firm based in Lancaster, PA, with additional offices in Columbia, PA. The firm, established with a strong regional presence, employs over 25 attorneys and offers a wide range of legal services. Known for its significant role in the local legal landscape, the firm handles everything from family law to corporate litigation. Their website serves as a portal for their clients and includes comprehensive information about their services, attorney profiles, and office locations.

Details of the Attack

The cyberattack on Nikolaus & Hohenadel was orchestrated by the ransomware group BianLian. The attackers managed to exfiltrate approximately 388 GB of sensitive data, including financial records, human resources documents, legal files, client communications, and email correspondences. The specifics of the ransom demand, if any, have not been disclosed publicly. This incident highlights significant vulnerabilities in the firm's cybersecurity measures, potentially in areas such as network security, data encryption, and endpoint protection.

Ransomware Group: BianLian

BianLian, originally known as a banking trojan, has evolved into a sophisticated ransomware group. Their operations have expanded from individual attacks to targeting large organizations, with a particular focus on sectors like healthcare, legal, and professional services. BianLian is known for its methodical approach to attacks, often gaining initial access through compromised Remote Desktop Protocol (RDP) credentials, followed by the deployment of custom backdoors and extensive use of scripting tools to evade defenses and exfiltrate data.

Potential Vulnerabilities and Entry Points

For a law firm like Nikolaus & Hohenadel, the primary vulnerabilities likely exploited by BianLian could include insufficiently secured RDP setups, lack of robust endpoint defenses, and possibly inadequate employee training on phishing and other social engineering attacks. Given the firm's significant data troves, including sensitive client information, it presents a high-value target for ransomware groups seeking financial gain through data exfiltration and extortion.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.