Funksec Ransomware Targets Arka Jain University Data

Incident Date: Dec 15, 2024

Attack Overview
VICTIM
Arka Jain University
INDUSTRY
Education
LOCATION
India
ATTACKER
Funksec
FIRST REPORTED
December 15, 2024

Ransomware Attack on Arka Jain University by Funksec

On December 16, Arka Jain University, a prominent private educational institution in Jharkhand, India, became the latest victim of a ransomware attack orchestrated by the cybercrime group Funksec. This incident highlights the growing threat of ransomware attacks on educational institutions, which are often seen as vulnerable targets due to their extensive data repositories and sometimes limited cybersecurity measures.

About Arka Jain University

Established in 2017, Arka Jain University (AJU) is a private university located in Gamharia, near Jamshedpur, Jharkhand. It is recognized by the University Grants Commission (UGC) and offers a wide range of academic programs across disciplines such as engineering, management, commerce, health sciences, and law. With over 5,000 students and approximately 252 staff members, AJU is known for its commitment to providing industry-relevant education and fostering entrepreneurial skills among its students. The university's robust placement network and strategic partnerships with various industries further enhance its reputation in the educational sector.

Details of the Ransomware Attack

The ransomware attack on AJU involved the exfiltration of a database containing documents exceeding 300MB in size. Funksec, the group behind the attack, substantiated their claim by releasing two screenshots of the exfiltrated files on their dark web leak site. The exact volume of the leaked data remains unspecified, and the university has yet to disclose further details regarding the nature of the compromised data or any potential impact on its operations.

Profile of Funksec

Funksec is an emerging ransomware group first observed in December 2024, known for its double extortion tactics. The group combines data exfiltration with encryption to pressure victims into paying ransoms. Funksec operates a Tor-based data-leak site where they announce breaches and host a free DDoS tool allegedly developed in-house. Their activities suggest potential operations as a data broker, diversifying their extortion methods. Funksec has claimed responsibility for over 10 breaches across various industries, including education, media, IT, and retail, targeting organizations in multiple countries.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.