Yang Enterprises Hit by DragonForce Ransomware, 72GB Data Leaked

Incident Date: Aug 18, 2024

Attack Overview
VICTIM
Yang Enterprises
INDUSTRY
Business Services
LOCATION
USA
ATTACKER
Dragonforce
FIRST REPORTED
August 18, 2024

DragonForce Ransomware Attack on Yang Enterprises

Yang Enterprises, Inc. (YEI), a diversified technical services company, recently fell victim to a ransomware attack orchestrated by the group known as DragonForce. The attack resulted in the exfiltration of 72.08GB of sensitive data, which was subsequently posted on DragonForce's dark web leak site.

About Yang Enterprises

Founded in 1986 and headquartered in Oviedo, Florida, Yang Enterprises is a high-technology, woman-owned, small disadvantaged company. The firm specializes in providing applied engineering and information technology services to sectors including the U.S. Space Program/NASA, the Department of Defense, and numerous Fortune 500 companies. YEI's core competencies include design and analysis, environmental engineering, test and evaluation, logistics, architecture, and construction management. The company is financially secure and debt-free, with a strong commitment to excellence, customer satisfaction, and ethical practices.

Attack Overview

The ransomware attack on Yang Enterprises was claimed by DragonForce, a relatively new ransomware group that emerged in late 2023. DragonForce employs a double extortion tactic, encrypting victims' data and exfiltrating sensitive information, which they threaten to release publicly if the ransom is not paid. In this case, DragonForce exfiltrated 72.08GB of data from YEI and posted it on their dark web leak site, DragonLeaks.

About DragonForce

DragonForce is known for its sophisticated double extortion tactics and has claimed a series of high-profile attacks since its emergence. The group uses a combination of encrypting victims' data and exfiltrating sensitive data, threatening to release it publicly if the ransom is not paid. Researchers have found that DragonForce's ransomware code is based on a leaked builder from the infamous LockBit ransomware group, suggesting that DragonForce may have leveraged this code to quickly develop and deploy their own ransomware.

Potential Vulnerabilities

Yang Enterprises' extensive involvement in high-stakes sectors such as space, defense, and telecommunications makes it an attractive target for ransomware groups like DragonForce. The company's reliance on advanced electronic document management systems and computerized maintenance management systems could have provided multiple entry points for the attackers. Additionally, the company's partnerships with government entities and large corporations may have made it a more lucrative target for data exfiltration.

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.