LEXCO Cobranzas Hit by MEOW Ransomware: Data Breach Details

Incident Date: Nov 07, 2024

Attack Overview
VICTIM
LEXCO Cobranzas
INDUSTRY
Business Services
LOCATION
Chile
ATTACKER
Meow
FIRST REPORTED
November 7, 2024

Ransomware Attack on LEXCO Cobranzas: A Detailed Analysis

In a significant cybersecurity incident, LEXCO Cobranzas, a leading debt collection agency based in Chile, has fallen victim to a ransomware attack orchestrated by the MEOW ransomware group. This breach underscores the vulnerabilities faced by companies in the business services sector, particularly those handling sensitive financial and personal data.

About LEXCO Cobranzas

LEXCO Cobranzas is a prominent player in the Chilean debt collection industry, offering a range of services including pre-legal, legal, and out-of-court debt recovery. The company is known for its tailored collection strategies, which cater to various sectors such as healthcare and insurance. With a workforce of 11 to 50 employees and an estimated revenue between $500,000 to $1 million, LEXCO is recognized for its professional approach and compliance with legal standards. This reputation, however, has been challenged by the recent data breach.

Details of the Ransomware Attack

The MEOW ransomware group claims to have exfiltrated 28 GB of sensitive data from LEXCO Cobranzas. The compromised information includes personal details of employees, client contact information, service agreements, contracts, insurance policies, and financial documents. The breach also exposed personal data such as dates of birth and medical information, posing a significant threat to the agency's operational integrity and reputation.

Profile of the MEOW Ransomware Group

Emerging in late 2022, the MEOW ransomware group is associated with the Conti v2 ransomware variant. Known for targeting industries with sensitive data, the group employs various infection methods, including phishing emails and exploiting RDP vulnerabilities. MEOW's resurgence in 2024 has seen them primarily targeting organizations in the United States, although their reach extends globally. The group distinguishes itself by using the ChaCha20 and RSA-4096 algorithms for encryption and maintaining a data leak site for victims who refuse to pay the ransom.

Potential Vulnerabilities and Penetration Methods

LEXCO Cobranzas' reliance on digital systems for managing sensitive data may have made it an attractive target for the MEOW group. The attack could have been facilitated through common vulnerabilities such as unpatched software, weak network security, or inadequate employee training on phishing threats. This incident highlights the critical need for effective cybersecurity measures to protect against sophisticated ransomware attacks.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.