RansomHub Ransomware Attack Exposes 79GB of Data from BSG

Incident Date: Sep 09, 2024

Attack Overview
VICTIM
BSG (Business Strategy Group)
INDUSTRY
Business Services
LOCATION
Thailand
ATTACKER
Ransomhub
FIRST REPORTED
September 9, 2024

RansomHub Targets Business Strategy Group in Ransomware Attack

RansomHub, a notorious Ransomware-as-a-Service (RaaS) group, has claimed responsibility for a ransomware attack on Business Strategy Group (BSG), an Australian consultancy firm. The attack, disclosed on September 10, has resulted in the exfiltration of 79 gigabytes of sensitive data from BSG, which specializes in providing strategic business solutions and project management services.

About Business Strategy Group

BSG, headquartered in Victoria, Australia, is a boutique consultancy firm known for its comprehensive consulting services aimed at enhancing business performance and strategic decision-making. The company offers market research, business intelligence, merger and acquisition consulting, commercial due diligence, and corporate strategy development. BSG is particularly noted for its Asian Business Media Tracker and its role as the representative office for UFI in the Asia-Pacific region. The firm operates with a team of professionals and has an estimated annual revenue of approximately $21.9 million.

Attack Overview

The ransomware attack on BSG was orchestrated by an affiliate of the RansomHub group. The attackers have listed BSG on their darknet leak site, claiming to have exfiltrated 79 gigabytes of data. Among the documents posted are a bank statement from NAB linked to an account named “Big Bucks Bingo,” a document detailing hourly pay rates, and an expired passport scan. These documents span from 2017 to 2024, indicating the potential exposure of sensitive financial and personal information.

About RansomHub

RansomHub emerged in February 2024 and quickly established itself in the ransomware landscape through an aggressive affiliate model. The group is known for its speed and efficiency, using advanced data exfiltration techniques and intermittent encryption to minimize encryption time while maintaining impact. RansomHub affiliates primarily use phishing campaigns, vulnerability exploitation, and password spraying to gain initial access. The group targets high-value sectors such as healthcare, financial services, and government.

Penetration and Vulnerabilities

RansomHub likely penetrated BSG's systems through a combination of phishing campaigns and exploiting unpatched vulnerabilities. The group's affiliates are known for conducting multi-phase attacks involving network reconnaissance, privilege escalation, and data exfiltration before encrypting files. BSG's focus on handling sensitive financial and strategic data makes it an attractive target for ransomware groups like RansomHub.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.