LawDepot Hit by Rhysida Ransomware: 5.5 TB Data Stolen

Incident Date: Jul 23, 2024

Attack Overview
VICTIM
LawDepot
INDUSTRY
Business Services
LOCATION
Canada
ATTACKER
Rhysida
FIRST REPORTED
July 23, 2024

LawDepot Ransomware Attack by Rhysida Group

Overview of LawDepot

LawDepot is an online platform specializing in customizable legal documents and forms. Founded in 2002 and headquartered in Edmonton, Alberta, Canada, the company has additional offices in the United States. LawDepot employs approximately 172 individuals and generates around $11 million in revenue as of 2024. The platform has assisted over 4 million users in creating more than 10 million legal documents, saving an estimated $5 billion in legal fees. LawDepot's user-friendly interface and comprehensive resources make it a leader in the legal technology sector.

Details of the Attack

LawDepot has fallen victim to a ransomware attack orchestrated by the Rhysida group. The cybercriminals claim to have exfiltrated 5.5 TB of sensitive data, including a backup of the SQL database, full website copies, internal passwords, database certificates, and confidential customer information. This stolen data encompasses credit card and PayPal details, as well as legal documents from various countries. Additionally, the attackers have seized LawDepot's internal GitLab and wiki knowledge base. Rhysida is demanding a ransom of 30 Bitcoin, approximately $2 million, with a payment deadline set for July 30, 2024. If unpaid, the group threatens to auction the data on the dark web.

About the Rhysida Ransomware Group

The Rhysida Ransomware Group emerged in May 2023 and has targeted sectors such as education, healthcare, manufacturing, information technology, and government. The ransomware is written in C++ and primarily targets Windows operating systems. Rhysida employs a double extortion technique, stealing data before encrypting it and threatening to publish it unless a ransom is paid. The group uses the ChaCha20 encryption algorithm and demands Bitcoin payments. Rhysida has been active in various regions, including the U.K., U.S., and Chile, and has previously attacked organizations like Prospect Medical Holdings and the British Library.

Potential Vulnerabilities

LawDepot's extensive database of sensitive customer information makes it an attractive target for ransomware groups like Rhysida. The company's reliance on digital platforms and online services increases its vulnerability to cyberattacks. Rhysida likely penetrated LawDepot's systems through phishing campaigns or by leveraging valid credentials to establish network connections. The group's use of tools like Advance IP/Port Scanner and Sysinternals PsExec for lateral movement within the network further facilitated the attack.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.