Jefferson County Clerk's Office Hit by RansomHub Ransomware Attack

Incident Date: Aug 11, 2024

Attack Overview
VICTIM
Jefferson County Clerk's Office.
INDUSTRY
Government
LOCATION
USA
ATTACKER
Ransomhub
FIRST REPORTED
August 11, 2024

RansomHub Ransomware Attack on Jefferson County Clerk's Office

The Jefferson County Clerk's Office, a pivotal institution in Jefferson County, Kentucky, has recently been targeted by the ransomware group RansomHub. This attack has caused significant disruptions, affecting multiple County Clerk locations and leading to the temporary closure of eight branches across Louisville.

About the Jefferson County Clerk's Office

Led by Clerk Bobbie Holsclaw, the Jefferson County Clerk's Office is a state constitutional office responsible for managing a variety of public records and services. The office handles approximately 700,000 vehicle registrations annually, issues marriage licenses, notary commissions, and manages delinquent real estate taxes. Additionally, it oversees the electoral process, ensuring fair and transparent elections. The office employs a dedicated team, although specific employee numbers are not publicly detailed.

Attack Overview

The ransomware attack by RansomHub has led to significant system outages since Monday evening. The attack has necessitated the temporary closure of eight branches, causing delays for residents seeking services such as vehicle registrations, housing deeds, and marriage and notary licenses. Despite the disruption, officials have confirmed that no personal information was compromised, thanks to the office's use of dedicated servers for storing sensitive data. The recovery process has been slow, requiring each of the more than 300 computers to be individually checked and restored to ensure security.

About RansomHub

RansomHub is a relatively new ransomware group believed to have roots in Russia. Operating as a Ransomware-as-a-Service (RaaS) group, RansomHub distinguishes itself by making claims and backing them up with data leaks. Affiliates receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, with healthcare-related institutions being notable victims. RansomHub's ransomware strains are written in Golang, a trend in the ransomware world.

Potential Vulnerabilities

The Jefferson County Clerk's Office, like many government institutions, handles a vast amount of sensitive data and relies heavily on its IT infrastructure. This makes it a prime target for ransomware groups like RansomHub. The attack likely penetrated the office's systems through vulnerabilities in their network security, possibly exploiting outdated software or insufficiently trained staff on cybersecurity practices.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.