Family Guardian Insurance: Targeted by Cactus Ransomware

Incident Date: Jun 02, 2024

Attack Overview
VICTIM
Family Guardian Insurance Company Limited
INDUSTRY
Finance
LOCATION
Bahamas
ATTACKER
Cactus
FIRST REPORTED
June 2, 2024

Ransomware Attack on Family Guardian Insurance Company Limited

Company Overview

Established in 1965 in the Bahamas, Family Guardian Insurance Company Limited is a financial services company dedicated to helping individuals and families secure their financial future. They offer a diverse range of products and services, including life insurance, health insurance, retirement planning, and investment services. As a wholly-owned subsidiary of FamGuard Corporation Limited, Family Guardian is listed on the Bahamas International Securities Exchange (BISX).

Attack Overview

The Family Guardian Insurance Company Limited recently fell victim to the Cactus ransomware group, which leaked a significant amount of sensitive data. This data breach includes confidential client documents, corporate correspondence, personal data of company executives and employees, database backups, and other critical information. The compromised data comprises a mix of internal company documents and personal information related to clients and employees.

Ransomware Group Profile

Known for operating as a ransomware-as-a-service (RaaS), the Cactus ransomware group is notorious for exploiting vulnerabilities and using malvertising lures for their targeted attacks. This group has been observed exploiting the ZeroLogon vulnerability and utilizes unique encryption techniques to evade detection. Affiliates of Cactus ransomware deploy custom scripts to disable security tools and spread the ransomware, targeting organizations of all sizes across various industries.

Company Vulnerabilities

As a financial services company, Family Guardian Insurance Company Limited holds a substantial amount of sensitive financial and personal data, making them an attractive target for cybercriminals like the Cactus ransomware group. The company's extensive online presence and interconnected systems likely provided pathways for the ransomware group to infiltrate their networks and execute the attack.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.