RansomHub Ransomware Attack Hits Faith Family Church Stealing 78GB Data

Incident Date: Sep 18, 2024

Attack Overview
VICTIM
Faith Family Church
INDUSTRY
Organizations
LOCATION
USA
ATTACKER
Ransomhub
FIRST REPORTED
September 18, 2024

RansomHub Targets Faith Family Church in Ransomware Attack

Faith Family Church, a vibrant community dedicated to spiritual growth and community engagement, has become the latest victim of a ransomware attack orchestrated by the notorious RansomHub group. The attack, discovered on September 17, 2024, resulted in a significant data breach, with 78GB of sensitive information exfiltrated.

About Faith Family Church

Faith Family Church operates multiple campuses, primarily located in North Canton, Ohio, and has additional locations in Baytown and Crosby, Texas. Founded in 1997, the church focuses on leading individuals into a growing relationship with Jesus Christ. It emphasizes community engagement through various programs and services, including worship services, outreach programs, and special events. The church's small organizational structure, with between 2 to 10 employees, relies heavily on donations and contributions from its congregation to support its operations.

Attack Overview

The ransomware attack on Faith Family Church was executed by RansomHub, a Ransomware-as-a-Service (RaaS) group known for its aggressive affiliate model and double extortion tactics. The attack led to the exfiltration of 78GB of sensitive data, significantly impacting the church's operations and potentially compromising the personal information of its members.

RansomHub's Modus Operandi

RansomHub, which emerged in February 2024, has quickly established itself as a formidable player in the ransomware landscape. The group employs a combination of encryption and data exfiltration to maximize pressure on victims. RansomHub's ransomware is optimized for speed and efficiency, targeting a wide range of systems, including Windows, Linux, and ESXi. The group primarily uses phishing campaigns, vulnerability exploitation, and password spraying to gain initial access to victims' networks.

Vulnerabilities and Penetration

Faith Family Church's small organizational structure and reliance on community donations may have contributed to its vulnerability. The church's systems could have been compromised through unpatched vulnerabilities or phishing attacks, common tactics used by RansomHub affiliates. The group's ability to exploit zero-day vulnerabilities and conduct multi-phase attacks involving network reconnaissance and privilege escalation further underscores the sophistication of the threat.

Impact and Implications

The ransomware attack on Faith Family Church highlights the growing threat posed by RansomHub and similar groups. The breach not only disrupts the church's operations but also raises concerns about the security of sensitive information within nonprofit organizations. As RansomHub continues to expand its reach, organizations across various sectors must remain vigilant and proactive in their cybersecurity efforts.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.