RansomHub Strikes Depew Gillen Law Firm in Major Data Breach

Incident Date: Nov 18, 2024

Attack Overview
VICTIM
Depew Gillen Rathbun & McInteer, LC
INDUSTRY
Law Firms & Legal Services
LOCATION
USA
ATTACKER
Ransomhub
FIRST REPORTED
November 18, 2024

RansomHub Ransomware Attack on Depew Gillen Rathbun & McInteer, LC

Depew Gillen Rathbun & McInteer, LC, a mid-sized law firm based in Wichita, Kansas, has recently fallen victim to a ransomware attack orchestrated by the notorious RansomHub group. This firm, known for its comprehensive legal services, has built a strong reputation in areas such as administrative and environmental law, aviation, business law, and litigation. With approximately 14 attorneys and an estimated annual revenue of $2 million, the firm is a significant player in the Kansas legal landscape.

Attack Overview

The RansomHub group claims to have accessed over 1,500 GB of sensitive data from Depew Gillen Rathbun & McInteer. The compromised data reportedly includes case details, accounting records, and client information, with samples of the stolen data being shared on a hidden website. The breach has exposed files such as payroll entries, invoices, attorney reports, and email filtering guides. The full extent of the data leak and its impact on the firm's operations remain uncertain.

RansomHub's Distinctive Approach

RansomHub, a Ransomware-as-a-Service (RaaS) group, emerged in February 2024 and quickly established itself as a formidable threat in the cyber landscape. The group is known for its aggressive affiliate model and double extortion tactics, encrypting victims' data while exfiltrating sensitive information to increase ransom demands. RansomHub's operations are characterized by their speed and efficiency, leveraging advanced data exfiltration techniques and targeting high-value sectors.

Potential Vulnerabilities

Depew Gillen Rathbun & McInteer's vulnerability to such an attack may stem from several factors. As a law firm handling sensitive client data, it presents an attractive target for ransomware groups seeking high-value information. The firm's reliance on digital systems for managing legal and accounting services could have been exploited through phishing campaigns or unpatched system vulnerabilities, common entry points for RansomHub affiliates.

Penetration Tactics

RansomHub affiliates are known to employ a variety of tactics to infiltrate target systems. These include phishing campaigns, exploiting vulnerabilities in unpatched systems, and using password spraying techniques. The group's ability to conduct multi-phase attacks involving network reconnaissance, privilege escalation, and data exfiltration before encrypting files highlights their operational complexity and sophistication.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.