TPA Slovakia Group Under Siege: The Devastating Impact of the Underground Team's Ransomware Attack
Analysis of the Ransomware Attack on TPA Slovakia by Underground Team
Company Profile: TPA Slovakia Group
TPA Slovakia, a significant entity within the TPA Group, specializes in audit, tax advisory, and business consulting primarily in Slovakia. Operating from Bratislava and Košice, the company employs over 100 staff. As part of the larger TPA Group, which boasts more than 1,500 employees across Central and South Eastern Europe, TPA Slovakia stands out for its effective communication, tailored solutions, and a strong focus on client success. The group's affiliation with the Baker Tilly Europe Alliance enhances its global reach and expertise in tax, audit, and consulting services.
Details of the Ransomware Attack
The Underground Team ransomware group has claimed responsibility for a severe attack on TPA Slovakia. This incident involved the deployment of a sophisticated ransomware strain, leading to the exfiltration of approximately 183.3 GB of sensitive data. The compromised data includes email communications, confidential agreements, accounting and tax reports, audit documents, financial records, and personal identification documents of clients. This breach has not only jeopardized the privacy of TPA Slovakia's clients but also exposed critical business information.
Ransomware Group Profile
The cybercriminal group, Underground Team, utilizes a 64-bit GUI based ransomware application, known for its capability to delete backups, modify registry settings, and halt critical services like MSSQLSERVER. This group's ransomware can identify system volumes, encrypt files while avoiding certain directories and file types, and disseminate a ransom note across multiple system folders. The primary infection vectors include phishing and other social engineering tactics, often involving deceptive emails and compromised website links.
Vulnerabilities and Attack Vectors
TPA Slovakia's vulnerabilities could stem from several areas, including but not limited to, insufficient employee training on phishing, inadequate endpoint protection, or gaps in network security. Given the nature of the data handled by TPA Slovakia, the firm is a high-value target for cybercriminals looking to exploit sensitive financial and personal information for monetary gain.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!