RansomHub Hits Tolbert & Tolbert LLC in Major Data Breach

Incident Date: Nov 11, 2024

Attack Overview
VICTIM
Tolbert & Tolbert LLC
INDUSTRY
Finance
LOCATION
USA
ATTACKER
Ransomhub
FIRST REPORTED
November 11, 2024

RansomHub Ransomware Attack on Tolbert & Tolbert LLC

On November 12, Tolbert & Tolbert LLC, a law firm based in Gary, Indiana, became the latest victim of a ransomware attack by the notorious group RansomHub. This breach resulted in the exfiltration of approximately 260GB of sensitive data, including tax records, insurance documents, and confidential agreements. The attackers released a sample of the stolen data, highlighting the severity of the incident.

About Tolbert & Tolbert LLC

Tolbert & Tolbert LLC is a small law firm founded in 2015 by Michael and Shelice Tolbert. The firm is known for its faith-based approach, emphasizing compassionate and affordable legal services. Specializing in litigation services, they handle complex legal issues for a diverse clientele, including large insurance companies. Their commitment to fairness and efficiency has earned them a reputable standing in Northwest Indiana.

Vulnerabilities and Targeting

Despite their strong reputation, Tolbert & Tolbert LLC's small size and focus on client service may have left them vulnerable to cyber threats. As a firm handling sensitive legal documents, they present a lucrative target for ransomware groups like RansomHub, which seek high-value data for extortion. The firm's reliance on digital records and communications could have been exploited through phishing or unpatched system vulnerabilities.

RansomHub's Distinctive Approach

RansomHub, a Ransomware-as-a-Service group, emerged in February and quickly established itself as a formidable threat. Known for its aggressive affiliate model, the group employs double extortion tactics, encrypting data while exfiltrating sensitive information. Their ransomware is optimized for speed and cross-platform compatibility, targeting sectors like finance and legal services. RansomHub's ability to adapt and leverage vulnerabilities makes it a critical threat to organizations worldwide.

Attack Overview

The attack on Tolbert & Tolbert LLC underscores the growing threat of ransomware to small and medium-sized enterprises. By exploiting potential vulnerabilities in the firm's IT infrastructure, RansomHub was able to infiltrate and exfiltrate a significant amount of sensitive data. This incident highlights the need for enhanced cybersecurity measures, especially for firms handling critical and confidential information.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.