Volo Internet Tech Faces Ransomware Breach by Akira Group

Incident Date: Nov 20, 2024

Attack Overview
VICTIM
Volo Internet Tech
INDUSTRY
Media & Internet
LOCATION
USA
ATTACKER
Akira
FIRST REPORTED
November 20, 2024

Ransomware Attack on Volo Internet Tech by Akira Group

Volo Internet Tech, a locally owned internet service provider based in Central Illinois, has become the latest victim of a ransomware attack orchestrated by the notorious Akira group. The attack, which occurred on November 21, resulted in the leak of 49GB of sensitive internal data, including Social Security Numbers, Non-Disclosure Agreements, passports, and driver's licenses.

Company Profile and Industry Standing

Established in 2002, Volo Internet Tech has been a key player in expanding fiber internet networks in Central Illinois, particularly in areas such as Champaign-Urbana, Mahomet, and Thomasboro. The company offers high-speed fiber optic and wireless broadband services, along with comprehensive IT solutions for both residential and business clients. Despite its small size, employing between 1 to 10 individuals, Volo is known for its commitment to local service and customer satisfaction, providing tailored solutions at competitive prices.

Akira Ransomware Group

Emerging in March 2023, Akira operates as a Ransomware-as-a-Service (RaaS) entity, employing a double extortion model. The group is distinguished by its sophisticated encryption techniques and potential ties to the former Conti group.

Penetration and Impact

Akira's penetration into Volo's systems likely involved exploiting vulnerabilities in network security, possibly through compromised VPN credentials or unpatched software.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.