RansomHub Strikes Jorns and Associates in Major Data Breach

Incident Date: Nov 18, 2024

Attack Overview
VICTIM
Jorns & Associates
INDUSTRY
Business Services
LOCATION
USA
ATTACKER
Ransomhub
FIRST REPORTED
November 18, 2024

RansomHub Ransomware Attack on Jorns & Associates

On November 19, Jorns & Associates, a prominent consulting firm specializing in federal and state tax credits, fell victim to a ransomware attack orchestrated by the notorious RansomHub group. The attack resulted in the exfiltration and leak of 60GB of sensitive data, including screenshots and a file tree as evidence of the breach.

About Jorns & Associates

Jorns & Associates, headquartered in Wichita, Kansas, is a leader in the niche market of tax credit consulting. The firm assists businesses in navigating complex economic stimulus programs, such as the Employee Retention Tax Credit (ERC) and Paycheck Protection Program (PPP) Loan Forgiveness. With a proprietary software system and a team of experienced CPAs and tax specialists, the company has successfully helped thousands of businesses secure hundreds of millions of dollars in stimulus funding. Their commitment to transparency, efficiency, and community engagement sets them apart in the business services sector.

Vulnerabilities and Targeting

Jorns & Associates' reliance on critical client data and proprietary software systems made them an attractive target for RansomHub. The firm's extensive operations across multiple states, including New York, Ohio, and Mississippi, further increased their exposure to cyber threats. The attack highlights the vulnerabilities inherent in organizations that handle large volumes of sensitive financial data, making them prime targets for ransomware groups seeking high-value victims.

RansomHub's Modus Operandi

RansomHub, a Ransomware-as-a-Service (RaaS) group, emerged in February 2024 and quickly established itself as a formidable player in the ransomware landscape. Known for its aggressive affiliate model and double extortion tactics, RansomHub encrypts victims' data while exfiltrating sensitive information to leverage ransom demands. The group employs advanced techniques, including phishing campaigns, vulnerability exploitation, and password spraying, to infiltrate target systems.

Attack Overview

The attack on Jorns & Associates underscores the sophisticated nature of RansomHub's operations. By exploiting potential vulnerabilities in the firm's systems, the group was able to execute a multi-phase attack involving network reconnaissance, privilege escalation, and data exfiltration before encrypting files. The breach has left Jorns & Associates grappling with the aftermath, as they work to mitigate the impact on their clients and restore their operations.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.