Everest Ransomware Group Strikes VFOS with Data Breach Threat

Incident Date: Jun 04, 2024

Attack Overview
VICTIM
Voorhees Family Office Services
INDUSTRY
Healthcare Services
LOCATION
USA
ATTACKER
Everest
FIRST REPORTED
June 4, 2024

Everest Ransomware Group Targets Voorhees Family Office Services

Company Profile

Voorhees Family Office Services (VFOS) is a Registered Investment Advisory firm based in Irvine, California. Founded and led by Tim Voorhees, JD, MBA, VFOS specializes in wealth counseling, wealth blueprinting, and legacy planning services for high-net-worth individuals and families. The firm supports Million Voorhees Ziebold LLP (MVZ) by providing plan design, reporting, and case coordination services. VFOS employs approximately 14 people and is recognized for its expertise in advanced wealth planning techniques.

Attack Overview

The Everest Ransomware Group has claimed responsibility for a ransomware attack on VFOS. The attackers have exfiltrated 600 GB of sensitive data, including client files, private company data, and various folders with specific names. Everest has issued a 24-hour ultimatum for VFOS to contact them, threatening to publish the stolen data if their demands are not met.

Details of the Attack

The compromised data includes client lists, financial records, emails, and other sensitive information. The attackers have listed specific folders such as "Advisors 12723446 Asset Protection" and "857125 Client Lists" among others. This breach exposes VFOS to significant risks, including potential financial loss and reputational damage.

About Everest Ransomware Group

Active since December 2020, the Everest Ransomware Group is known for ransomware attacks, data exfiltration, and initial access brokering. The group targets various industries, including healthcare and public sectors, and has been linked to other ransomware groups like BlackByte. Everest uses AES and DES algorithms to encrypt files and often employs compromised user accounts and Remote Desktop Protocol (RDP) for lateral movement.

Penetration Tactics

Everest likely penetrated VFOS's systems through compromised user accounts or RDP vulnerabilities. The group's sophisticated tactics and focus on high-profile targets make organizations like VFOS particularly vulnerable. The attack underscores the importance of robust cybersecurity measures, especially for firms handling sensitive financial and personal data.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.