RansomHub attacks McKim & Creed

Incident Date:

March 14, 2024

World map

Overview

Title

RansomHub attacks McKim & Creed

Victim

McKim & Creed

Attacker

Ransomhub

Location

City, Country

City, State

First Reported

March 14, 2024

McKim & Creed Faces Ransomware Threat

McKim & Creed has allegedly been compromised by the RansomHub ransomware group. The breach reportedly involves the exfiltration of 500 GB of data, and a ransom deadline of 21 March has been given. McKim & Creed is an employee-owned engineering and surveying firm of people helping people. It combines national expertise with a local perspective to deliver innovative solutions that serve its clients and our communities.

RansomHub: A New Threat on the Horizon

RansomHub is a relatively new ransomware-as-a-service operation whose darknet site features an index page where all its victims are listed, as well as About and Contact pages. The group claims to be a team of attackers from around the world, motivated by one thing – financial gain. However, the gang does say that it does not allow attacks against certain targets, including CIS, Cuba, North Korea, and China.

Operational Rules and Restrictions

The group also lists a few general rules that it follows, as well as rules for its affiliates. RansomHub does not allow non-profit organizations to be targeted, and nor does it allow “re-attacks” – follow-up attacks on victims who have already paid.

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.