Ransomware Breach at Bogdan & Frasco by Cicada 3301
Ransomware Attack on Bogdan & Frasco, LLP by Cicada 3301
Bogdan & Frasco, LLP, a reputable accounting and tax firm based in San Francisco, has become the latest victim of a ransomware attack by the notorious group Cicada 3301. The firm, known for its personalized service and expertise in financial management, primarily serves small and medium-sized businesses and individual clients. Established in 1995, Bogdan & Frasco has built a strong reputation in the competitive San Francisco market.
Company Profile and Vulnerabilities
With approximately seven employees and an annual revenue of around $3 million, Bogdan & Frasco operates from the heart of San Francisco's financial district. The firm's focus on personalized service and responsiveness to client needs distinguishes it within the industry. However, its relatively small size and the nature of its operations may have made it an attractive target for threat actors like Cicada 3301, who often exploit vulnerabilities in small to medium-sized businesses.
Attack Overview
The ransomware attack resulted in the compromise of 338 GB of sensitive data, which was subsequently published on a dark web site on September 15. This breach poses significant risks to the firm's reputation and client trust, as the stolen data is now available for download. The attack highlights the growing threat of ransomware groups targeting businesses with valuable data, particularly those with potentially weaker cybersecurity defenses.
About Cicada 3301
Cicada 3301, a newly emerged Ransomware-as-a-Service and data broker group, first gained attention in mid-2024. Unlike traditional ransomware groups, Cicada 3301 focuses on exfiltrating and selling sensitive data rather than seeking quick ransom payments. Their operations involve a double-extortion model, threatening to release stolen data if demands are not met. The group is known for its sophisticated tactics, including the use of the Brutus botnet for initial access and PsExec for lateral movement.
Penetration and Distinctive Tactics
The attack on Bogdan & Frasco likely involved phishing campaigns or brute-forcing VPN credentials, common methods employed by Cicada 3301. Their use of advanced encryption techniques, such as ChaCha20, and the ability to delay encryption to evade detection, sets them apart from other ransomware groups. The group's focus on data brokerage and extortion, rather than immediate ransom demands, underscores their unique approach to cybercrime.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!