Hackers Stole and Encrypted Data of 5 US Law Firms

enovise.com
Published On 15 Feb 2022
Enovise
Summary
Hackers compromised five United States law firms and demanded two 100 Bitcoin ransoms from each firm — one to restore access to the data, one to delete their copy instead of selling it. The Maze group published part of the stolen data, threatening to release increasingly sensitive material unless paid.
Hackers compromised five United States law firms and demanded two 100 Bitcoin (BTC) ransoms from each firm: one to restore access to the data, and one to delete their copy instead of selling it. According to data shared with Cointelegraph by cybersecurity firm Emsisoft, the hacker group — called Maze — already started publishing part of the data stolen from the aforementioned firms. Two of the five law firms were hacked within the 24 hours leading to February 1st.
How the Attack Worked
The hackers published the stolen data on two websites. The Maze group first names hacked companies on its website and — if they do not pay — publishes a small part of the stolen data as proof, then keeps releasing increasingly sensitive parts over time. When a firm pays, the group removes its name from the website.
The group also published data in Russian hacker forums with a note to "use this information in any nefarious ways that you want." Brett Callow of Emsisoft noted: "It seems highly unlikely that a criminal enterprise would actually delete what it may be able to monetize at a later date."
Callow explained that ransomware groups started stealing data — instead of just encrypting it — at the end of 2019. Now cybercriminals are also threatening the victims with release of the data to extort payment. Sectors targeted include law firms, accounting firms, medical practices, medical testing labs, and insurance companies.
The Ransomware Economy
Emsisoft had over 200,000 ransomware submissions in 2019, estimated to represent about 25% of the total — equating to approximately 800,000 cases that year. The average ransom demand had surpassed $80,000, putting total ransoms demanded at an estimated $64 billion for the year.
Impact on Public Perception of Crypto
As ransomware began stealing particularly sensitive data, Callow noted it is "likely to result in more legal actions being taken against ransomware groups, web hosts and currency exchanges." He added: "Legal actions such as these, as well as the fact that the incidents result in very sensitive data being exposed, is likely to raise the profile of ransomware cases. In turn, that could result in the public thinking cryptocurrency is 'just for criminals', making it harder for crypto to become more mainstream."
High-profile ransomware attacks became increasingly frequent during this period. The European Union Agency for Law Enforcement Cooperation released a report in October 2019 noting that ransomware remained the top cybersecurity threat.
Original source: Cointelegraph
You May Also Like
View Blogs
Kenya Threat Landscape Report 2024
The Kenya Threat Landscape Report, prepared by SOCRadar and Enovise, highlights various aspects of the cyber threat environment around Kenya — where public administration, information, and finance sectors collectively account for over 43% of observed incidents.

Enovise Group and SOCRadar Partnership
Enovise has partnered with SOCRadar to deliver advanced, proactive cybersecurity solutions for organisations across Africa, integrating SOCRadar's Extended Threat Intelligence platform with Enovise's Managed Detection and Response services.

Garmin South Africa Hack
Customer data for purchases made through the Garmin South Africa shop has been stolen — including payment card numbers, CVV codes, names, physical addresses, phone numbers, and email addresses — containing all the information required to make fraudulent purchases.

Hackers Tricked 3 British Private Equity Firms
In a highly targeted business email compromise attack, the Florentine Banker group tricked three British private equity firms into wiring $1.3 million — approximately $700,000 permanently lost — using man-in-the-middle tactics and lookalike domains to intercept and manipulate financial communications.