Solomon Agency Corp Hit by CL0P Ransomware Attack: Key Details

Incident Date: Jul 25, 2024

Attack Overview
VICTIM
Solomon Agency Corp
INDUSTRY
Insurance
LOCATION
USA
ATTACKER
Clop
FIRST REPORTED
July 25, 2024

Ransomware Attack on Solomon Agency Corp by CL0P

Overview of Solomon Agency Corp

Solomon Agency Corp, operating under the domain solomonus.com, is a prominent insurance agency based in New York. The company specializes in providing a wide array of insurance products and services tailored to meet the needs of various sectors, including business, education, healthcare, and more. They offer comprehensive business insurance solutions, including property and casualty insurance, employee benefits, workers' compensation, and cyber liability coverage. Their client-centric approach and industry-specific expertise make them a leader in the insurance sector.

Details of the Ransomware Attack

On July 25, 2024, Solomon Agency Corp fell victim to a ransomware attack orchestrated by the notorious CL0P ransomware group. The attack targeted the company's website, solomonus.com. While the exact size of the data leak remains unknown, the incident underscores the persistent threat ransomware poses to critical sectors. Solomon Agency Corp is currently assessing the full impact of the breach and working to mitigate any potential damage.

About the CL0P Ransomware Group

The CL0P ransomware group is a highly sophisticated and financially motivated cybercriminal group that has been active since early 2019. Associated with the larger TA505 threat group, CL0P operates as a ransomware-as-a-service (RaaS) model. The group typically targets large enterprises, particularly in the financial, healthcare, manufacturing, and media sectors. CL0P spreads through malicious email attachments, websites, and links, as well as by exploiting known vulnerabilities like those in Accellion FTA and "ZeroLogon". In late 2020, CL0P began operating a data leak site called "CL0P^_-LEAKS" on the Tor network to publicly release stolen data from victims who do not pay the ransom.

Potential Vulnerabilities and Penetration Methods

Solomon Agency Corp, like many organizations in the insurance sector, handles sensitive client data, making it an attractive target for ransomware groups like CL0P. The group employs advanced techniques such as digital signatures to evade security controls and has been observed using tools like Cobalt Strike, web shells, and remote access trojans. The exact method of penetration in this case is not yet confirmed, but it could involve phishing attacks, exploitation of software vulnerabilities, or compromised credentials.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.