Ransomware Hits Mercury Theatre by Hunters International
Ransomware Attack on Mercury Theatre by Hunters International
The Mercury Theatre, a cultural cornerstone in Colchester, Essex, has recently been targeted by the notorious ransomware group, Hunters International. This attack underscores the persistent threat posed by cybercriminals to organizations across various sectors, including the arts and entertainment industry.
About Mercury Theatre
Established in 1972, the Mercury Theatre is a prominent cultural institution known for its diverse programming and community engagement. With a workforce of approximately 87 staff members, the theatre is recognized as the most active producing theatre in the East of England. It recently underwent a significant £11.3 million redevelopment to modernize its facilities, enhancing accessibility and expanding its capacity to host a wide array of performances. The theatre's commitment to inclusivity and artistic expression makes it a vital part of the local cultural landscape.
Attack Overview
Hunters International claims to have exfiltrated 414.6 GB of data from the Mercury Theatre, including 134,133 files. The compromised data reportedly contains sensitive financial records, email communications, and internal company information. This breach highlights the vulnerabilities that cultural institutions face, particularly those with significant digital footprints and community engagement initiatives.
About Hunters International
Emerging in October 2023, Hunters International is a Ransomware-as-a-Service (RaaS) group known for its sophisticated attacks and use of double extortion tactics. The group has a significant code overlap with the defunct Hive ransomware but claims independence. It targets industries where disruption can yield substantial leverage, employing techniques such as phishing, RDP exploitation, and social engineering to gain initial access.
Penetration and Impact
The attack on Mercury Theatre likely involved a multi-stage operation, beginning with network reconnaissance and lateral movement before data exfiltration and encryption. Hunters International's use of Rust-developed ransomware allows for cross-platform targeting, making it particularly effective against enterprise environments. The theatre's reliance on digital systems for operations and community engagement may have made it an attractive target for the group.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!