ElDorado Ransomware Strikes Kansas State Vet College: Data Breach & Encryption Threat

Incident Date: Jun 06, 2024

Attack Overview
VICTIM
Kansas State University College of Veterinary Medicine
INDUSTRY
Education
LOCATION
USA
ATTACKER
ElDorado
FIRST REPORTED
June 6, 2024

ElDorado Ransomware Attack on Kansas State University College of Veterinary Medicine

Overview of the Victim

To begin with, the Kansas State University College of Veterinary Medicine is a prestigious educational institution dedicated to advancing animal health and welfare through education, research, and clinical services. The college offers rigorous academic programs, including Doctor of Veterinary Medicine (DVM) degrees and advanced graduate degrees. It is renowned for its cutting-edge research projects and comprehensive clinical services provided by the Veterinary Health Center. The institution has a rich history, being one of the oldest veterinary colleges in the United States, and has granted DVM degrees to over 7,000 individuals.

Details of the Attack

In a shocking turn of events, the ransomware group ElDorado has claimed responsibility for a cyberattack on the Kansas State University College of Veterinary Medicine. The attack involved the exfiltration and encryption of sensitive data, which is now being offered for sale on ElDorado's dark web leak site. The group left a ransom note named HOW_RETURN_YOUR_DATA.TXT, threatening to leak or sell the stolen data if their demands are not met within seven days. The attack has significantly disrupted the college's operations, affecting its educational, research, and clinical services.

About ElDorado Ransomware Group

ElDorado is a ransomware group that emerged in 2024, known for its double-extortion tactics. The group encrypts victims' files and exfiltrates sensitive data, increasing pressure to pay the ransom by threatening public release. ElDorado has claimed 15 victims over seven months, showcasing their aggressive and sophisticated approach. They employ various tactics, including phishing attacks, exploiting unpatched vulnerabilities, and leveraging weaknesses in Remote Desktop Protocol (RDP) configurations. Their meticulous targeting and use of robust encryption algorithms make them a formidable threat in the ransomware landscape.

Potential Vulnerabilities

It is important to note that the Kansas State University College of Veterinary Medicine, like many educational institutions, may have vulnerabilities that make it an attractive target for ransomware groups. These can include outdated software, insufficient cybersecurity measures, and a lack of regular security updates. The college's extensive use of digital systems for education, research, and clinical services further increases its risk profile, providing multiple entry points for cybercriminals.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.