Medusa Ransomware Strikes BRP Family Law Firm

Incident Date: Dec 06, 2024

Attack Overview
VICTIM
Brodsky Renehan Pearlstein & Bouquet, Chartered
INDUSTRY
Law Firms & Legal Services
LOCATION
USA
ATTACKER
Medusa
FIRST REPORTED
December 6, 2024

Medusa Ransomware Group Targets Brodsky Renehan Pearlstein & Bouquet, Chartered

The Medusa ransomware group has allegedly claimed responsibility for a cyberattack on Brodsky Renehan Pearlstein & Bouquet, Chartered (BRP Family Law), a distinguished law firm based in Gaithersburg, Maryland. Specializing in family law, BRP Family Law has been a trusted name in divorce and custody matters for over 70 years, serving clients across Maryland and Washington, D.C.

Victim Profile: BRP Family Law

BRP Family Law is a well-established firm with a focus on providing personalized legal services in family law, including divorce, custody disputes, and domestic violence cases. The firm employs 17 individuals, including eight attorneys, and is recognized for its commitment to excellence and client-centered approach. The firm's reputation and specialized focus make it a prominent target for cybercriminals seeking sensitive legal and personal data.

Attack Overview

The Medusa group claims to have infiltrated BRP Family Law's systems, extracting approximately 347.20 GB of sensitive data. This data reportedly includes bank details, confidential organizational information, email addresses, and personal identifiers. The group has threatened to release this data within 10 to 11 days, having already posted sample screenshots on their dark web portal to substantiate their claims. The breach was discovered on December 6, 2024, highlighting the firm's vulnerability to sophisticated cyber threats.

Medusa Ransomware Group

Since its emergence in 2021, the Medusa ransomware group has distinguished itself through its Ransomware-as-a-Service model, targeting a wide range of sectors globally. Known for its rapid encryption capabilities and multi-extortion strategies, Medusa employs advanced evasion techniques and exploits vulnerabilities in software to gain access to victim networks. The group typically uses phishing emails and compromised credentials to penetrate systems, making organizations like BRP Family Law susceptible to their attacks.

Potential Vulnerabilities

BRP Family Law's focus on handling sensitive family law matters makes it an attractive target for ransomware groups like Medusa. The firm's reliance on digital systems for managing confidential client information could have been a factor in the breach. The attack underscores the importance of comprehensive cybersecurity measures, particularly for organizations dealing with sensitive data.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.