alphv attacks GEMS Education

Incident Date:

February 25, 2022

World map

Overview

Title

alphv attacks GEMS Education

Victim

GEMS Education

Attacker

Alphv

Location

Dubai, United Arab Emirates

Dubai, United Arab Emirates

First Reported

February 25, 2022

GEMS Education Suffers Ransomware Attack by Alphv Group

GEMS Education, a prominent international education provider with operations in the UAE, Qatar, and Egypt, has been targeted by the ransomware group Alphv. The attack was disclosed through a leak on the group's dark web site, which showcased the victim's website.

GEMS Education manages a network of schools across various locations and curricula, providing diverse educational opportunities for students. The organization's extensive size and international presence render it an attractive target for cybercriminals. Despite the cybersecurity incident, GEMS Education has announced that all their schools continue to operate normally.

The Alphv ransomware group, notorious for its aggressive extortion tactics, frequently targets high-profile entities and demands substantial ransoms. Active since 2019, the group has been implicated in numerous significant cyberattacks, including those against the NHS Moorfields Hospital in Dubai and a Dubai-based contracting firm.

The ransomware attack on GEMS Education underscores the critical need for enhanced cybersecurity defenses within the education sector. Although the company has taken steps to counteract the threat, this incident serves as a stark reminder of the pervasive risk of cyberattacks facing organizations today.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.