RansomHub Ransomware Hits French Comic Art Institution CIBDI

Incident Date: Aug 30, 2024

Attack Overview
VICTIM
Cité Internationale de la Bande Dessinée et de l’Image (CIBDI)
INDUSTRY
Consumer Services
LOCATION
France
ATTACKER
Ransomhub
FIRST REPORTED
August 30, 2024

RansomHub Targets Cité Internationale de la Bande Dessinée et de l’Image in Ransomware Attack

The Cité Internationale de la Bande Dessinée et de l’Image (CIBDI), a renowned cultural institution in Angoulême, France, has become the latest victim of a ransomware attack orchestrated by the cybercriminal group RansomHub. This attack highlights the vulnerabilities faced by cultural institutions in the digital age.

About CIBDI

CIBDI is a prominent cultural institution dedicated to the art of comics and images. Located in Angoulême, a UNESCO Creative City, CIBDI plays a crucial role in the preservation, promotion, and study of comic art. The institution encompasses a museum, a public library, a documentation center, and the Maison des Auteurs, which supports comic creators. CIBDI is also closely linked to the Festival International de la Bande Dessinée (FIBD), one of the largest comic book festivals in the world.

Attack Overview

RansomHub has claimed responsibility for the attack on CIBDI, releasing several sample files to demonstrate their access to sensitive data. The attackers have threatened to publish the entirety of the 1.7 terabytes of data they claim to have exfiltrated if CIBDI does not make contact with them. The released files include "1Ravances@3JustifsP16aP21.pdf" (2.76 MB), "1Ravances@3LivresCaisseBQ.pdf" (1.27 MB), "3Rrecettesd3VtelLigneCOMCB.pdf" (915.41 KB), and "1Ravances03JusT2401.pdf" (294.95 KB).

About RansomHub

RansomHub is a Ransomware-as-a-Service (RaaS) group that emerged in February 2024. The group is known for its aggressive affiliate model and double extortion tactics, encrypting victims' data and exfiltrating sensitive information for additional leverage in ransom demands. RansomHub has quickly established itself as a formidable player in the ransomware landscape, targeting high-value sectors such as healthcare, financial services, and government.

Penetration and Vulnerabilities

RansomHub is renowned for its speed and efficiency, using a combination of phishing campaigns, vulnerability exploitation, and password spraying to gain initial access. The group targets large enterprises with valuable data and critical operations. In the case of CIBDI, the attackers likely exploited unpatched systems or used phishing techniques to infiltrate the institution's network. The attack underscores the critical need for comprehensive cybersecurity measures and prompt incident response to mitigate potential data breaches and their repercussions.

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.