Ransomware Attack Disrupts OzarksGo Services by Play Group

Incident Date: Oct 15, 2024

Attack Overview
VICTIM
OzarksGo
INDUSTRY
Telecommunications
LOCATION
USA
ATTACKER
Play
FIRST REPORTED
October 15, 2024

Ransomware Attack on OzarksGo: A Detailed Analysis

On October 7, OzarksGo, a telecommunications provider based in Fayetteville, Arkansas, became the latest victim of a ransomware attack by the notorious Play ransomware group. This incident has significantly disrupted OzarksGo's linear TV services, prompting the company to permanently discontinue this offering and transition customers to its streaming platform.

About OzarksGo

OzarksGo is a subsidiary of Ozarks Electric Cooperative, providing high-speed fiber-optic internet, cable television, and telephone services to Northwest Arkansas and Northeast Oklahoma. The company is known for its commitment to enhancing community connectivity, particularly in underserved areas. With a workforce of 11 to 50 employees, OzarksGo emphasizes personalized customer service and community engagement. This local focus, while beneficial, may also present vulnerabilities, as smaller companies often have fewer resources to dedicate to cybersecurity defenses.

Attack Overview

The Play ransomware group claimed responsibility for the attack on October 15, alleging that they had exfiltrated sensitive data, including client documents, budget details, and payroll data. They issued a ransom demand with a deadline of October 19, threatening to release the stolen data if their demands were not met. Despite these claims, OzarksGo has not confirmed receiving a ransom demand or making any payments. The attack forced the company to take certain systems offline, affecting service delivery and leading to the discontinuation of its linear TV services.

About the Play Ransomware Group

Active since June 2022, the Play ransomware group has targeted various industries, including IT, transportation, and government entities. Known for exploiting vulnerabilities in RDP servers and Microsoft Exchange, the group distinguishes itself by not including an initial ransom demand in its notes, instead directing victims to contact them via email. This approach, combined with their use of custom tools and techniques, makes them a formidable threat in the cybersecurity landscape.

Potential Vulnerabilities

OzarksGo's relatively small size and focus on community service may have made it an attractive target for the Play ransomware group. Smaller companies often lack the comprehensive cybersecurity infrastructure of larger firms, making them more susceptible to sophisticated attacks. The group's ability to exploit known vulnerabilities and use advanced tools likely facilitated their penetration into OzarksGo's systems.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.