Travis Pruitt Hit by Akira Ransomware Compromising Data

Incident Date: Nov 18, 2024

Attack Overview
VICTIM
Travis Pruitt & Associates
INDUSTRY
Construction
LOCATION
USA
ATTACKER
Akira
FIRST REPORTED
November 18, 2024

Ransomware Attack on Travis Pruitt & Associates by Akira Group

Travis Pruitt & Associates, Inc. (TPA), a well-established engineering firm based in Norcross, Georgia, has recently been targeted by the notorious Akira ransomware group. Founded in 1972, TPA specializes in civil engineering, land surveying, landscape architecture, and environmental science, serving a diverse range of sectors including commercial, healthcare, and infrastructure. With approximately 79 employees, TPA is recognized for its integrated approach to project management and its commitment to quality and efficiency.

Attack Overview

The Akira ransomware group has claimed responsibility for the attack on TPA, which resulted in the compromise of significant employee data. The attackers accessed sensitive information such as emails, Social Security numbers, passports, and driver's licenses. They exploited TPA's data downloading process, providing a torrent file for users to download the stolen data. The instructions included using torrent clients like Vuze and uTorrent, with an archives password provided, though redacted for security reasons.

About Akira Ransomware Group

Emerging in March 2023, Akira operates as a Ransomware-as-a-Service (RaaS) entity, employing a double extortion model. The group is known for its sophisticated encryption techniques and potential ties to the former Conti group. Akira targets sectors with high-stakes data, including healthcare and finance, and has recently expanded its capabilities with a Rust-based Linux variant for VMware ESXi environments. This adaptability allows Akira to conduct cross-platform attacks with increased efficacy.

Vulnerabilities and Penetration

TPA's focus on advanced technology and comprehensive solutions may have inadvertently exposed vulnerabilities that Akira exploited. The ransomware group likely penetrated TPA's systems through compromised VPN credentials or unpatched vulnerabilities, common tactics in Akira's modus operandi. The attack underscores the importance of cybersecurity measures, especially for firms handling sensitive data across multiple sectors.

Impact and Implications

The attack on TPA highlights the growing threat of ransomware groups like Akira, which continue to evolve and target high-value sectors. For TPA, the breach not only compromises sensitive employee data but also poses potential reputational and operational risks. As Akira continues to refine its strategies, organizations must remain vigilant and proactive in safeguarding their digital assets.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.