Funksec Ransomware Targets Ekiti State Government Systems

Incident Date: Dec 15, 2024

Attack Overview
VICTIM
Ekiti State Government
INDUSTRY
Government
LOCATION
Nigeria
ATTACKER
Funksec
FIRST REPORTED
December 15, 2024

Ransomware Attack on Ekiti State Government by Funksec

The Ekiti State Government in Nigeria has fallen victim to a ransomware attack orchestrated by the cybercrime group Funksec. This incident underscores the persistent threat posed by sophisticated cybercriminals to governmental institutions worldwide.

Victim Profile: Ekiti State Government

Established in 1996, the Ekiti State Government oversees the administration of Ekiti State, located in Nigeria's southwestern region. The government operates through various ministries and agencies, focusing on fiscal responsibility, economic development, and public service delivery. A standout feature of the Ekiti State Government is its commitment to agricultural development, which serves as the primary income source for over 75% of its population. The state is known for producing cash crops like cocoa and oil palm, contributing significantly to its revenue. Despite its structured framework, the government remains vulnerable to cyber threats due to its extensive digital operations and data management systems.

Attack Overview

Funksec, an emerging ransomware group, claimed responsibility for the attack on December 16. The group alleges that it exfiltrated 300 MB of data from the Ekiti State Government's systems, posting sample screenshots on their dark web portal to substantiate their claims. The full extent of the data leak remains undisclosed by the government, highlighting the ongoing vulnerability of governmental institutions to cyber threats.

Funksec: A Rising Threat

First observed in December 2024, Funksec has quickly established itself in the cybercrime landscape. The group employs double extortion tactics, combining data exfiltration with encryption to pressure victims. Funksec's Tor-based data-leak site hosts breach announcements and a free DDoS tool, indicating their potential operations as a data broker. Their activities suggest a diversification of extortion methods, distinguishing them from other ransomware groups. Funksec's ability to penetrate the Ekiti State Government's systems may have been facilitated by exploiting vulnerabilities in the government's digital infrastructure, underscoring the need for robust cybersecurity measures.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.