Cybersecurity Breach: Ransomware Attack on Nikolaus & Hohenadel
Ransomware Attack on Nikolaus & Hohenadel by BianLian Group
Victim Profile: Nikolaus & Hohenadel, LLP
Nikolaus & Hohenadel, LLP is a prominent law firm based in Lancaster, PA, with additional offices in Columbia, PA. The firm, established with a strong regional presence, employs over 25 attorneys and offers a wide range of legal services. Known for its significant role in the local legal landscape, the firm handles everything from family law to corporate litigation. Their website serves as a portal for their clients and includes comprehensive information about their services, attorney profiles, and office locations.
Details of the Attack
The cyberattack on Nikolaus & Hohenadel was orchestrated by the ransomware group BianLian. The attackers managed to exfiltrate approximately 388 GB of sensitive data, including financial records, human resources documents, legal files, client communications, and email correspondences. The specifics of the ransom demand, if any, have not been disclosed publicly. This incident highlights significant vulnerabilities in the firm's cybersecurity measures, potentially in areas such as network security, data encryption, and endpoint protection.
Ransomware Group: BianLian
BianLian, originally known as a banking trojan, has evolved into a sophisticated ransomware group. Their operations have expanded from individual attacks to targeting large organizations, with a particular focus on sectors like healthcare, legal, and professional services. BianLian is known for its methodical approach to attacks, often gaining initial access through compromised Remote Desktop Protocol (RDP) credentials, followed by the deployment of custom backdoors and extensive use of scripting tools to evade defenses and exfiltrate data.
Potential Vulnerabilities and Entry Points
For a law firm like Nikolaus & Hohenadel, the primary vulnerabilities likely exploited by BianLian could include insufficiently secured RDP setups, lack of robust endpoint defenses, and possibly inadequate employee training on phishing and other social engineering attacks. Given the firm's significant data troves, including sensitive client information, it presents a high-value target for ransomware groups seeking financial gain through data exfiltration and extortion.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!