Ransomware Hits Surfnet Communications in California

Incident Date: Oct 29, 2024

Attack Overview
VICTIM
Surfnet Communications
INDUSTRY
Telecommunications
LOCATION
USA
ATTACKER
Arcus Media
FIRST REPORTED
October 29, 2024

Ransomware Attack on Surfnet Communications by Arcus Media

Surfnet Communications, a broadband internet service provider based in Santa Cruz County, California, has recently fallen victim to a ransomware attack orchestrated by the notorious group Arcus Media. This incident underscores the persistent threat that cybercriminals pose to the telecommunications sector, particularly targeting companies that serve underserved and remote communities.

Company Profile and Vulnerabilities

Surfnet Communications, established in 2000, specializes in delivering high-speed internet solutions to rural and mountainous areas along California's Central Coast. The company primarily utilizes wireless broadband technology to reach customers in challenging geographical locations, offering download speeds of up to 100 Mbps. Surfnet is also expanding its services to include fiber broadband, with significant funding from the California Public Utilities Commission. Despite its small team of 1 to 10 employees, Surfnet has built a reputation for excellent customer service and community engagement. However, its focus on underserved areas and small workforce may present vulnerabilities, making it an attractive target for ransomware groups like Arcus Media.

Attack Overview

Arcus Media has claimed responsibility for the attack on Surfnet Communications, asserting that they have exfiltrated 52 GB of sensitive data. The group operates under a Ransomware-as-a-Service model, allowing other cybercriminals to utilize their tools. Their attack methods typically involve phishing emails to gain initial access, followed by data exfiltration and system encryption as part of a double extortion strategy. The breach of Surfnet's systems highlights the need for enhanced cybersecurity measures, especially for companies operating in critical infrastructure sectors like telecommunications.

Arcus Media's Distinctive Tactics

Arcus Media distinguishes itself through its rapid emergence and aggressive targeting of diverse industries, including telecommunications. The group employs custom-built ransomware binaries, often obfuscated to evade detection, and conducts negotiations through encrypted channels on a TOR-based website. Their ability to quickly gain notoriety and execute successful attacks reflects a broader trend in the ransomware landscape, where new groups are increasingly sophisticated and operationally capable.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.