APT73 Ransomware Attack Threatens Gannons Solicitors' Client Data

Incident Date:

June 14, 2024

World map

Overview

Title

APT73 Ransomware Attack Threatens Gannons Solicitors' Client Data

Victim

Gannons Solicitors

Attacker

APT73

Location

London, United Kingdom

, United Kingdom

First Reported

June 14, 2024

APT73 Ransomware Attack on Gannons Solicitors

Overview of Gannons Solicitors

Gannons Solicitors, a boutique commercial law firm based in London, specializes in providing legal services to private companies, entrepreneurs, and investors. The firm, incorporated in 2014 as Gannons Commercial Law Limited, is known for its niche expertise, commercial acumen, and personalized approach. Gannons offers a range of legal services, including corporate and commercial law, employment law, intellectual property, and dispute resolution. The firm prides itself on delivering high-quality, cost-effective legal services to SMEs often overlooked by larger law firms.

Details of the Ransomware Attack

On June 2024, Gannons Solicitors fell victim to a ransomware attack orchestrated by the group APT73. The attackers have threatened to release 2.3MB of sensitive documentation and agreements if their demands are not met by June 25, 2024. The compromised data could potentially expose confidential client information, posing significant risks to the firm's reputation and client trust.

About APT73

APT73 is an emerging ransomware group that has recently surfaced in the cyber threat landscape. The group operates a TOR-based data leak site named "ERALEIGNEWS," where they publish stolen data. APT73's modus operandi includes phishing attacks to compromise systems and deploy ransomware. The group exhibits similarities to the LockBit ransomware variant, particularly in its data leak site design and operational tactics.

Potential Vulnerabilities

Gannons Solicitors, like many law firms, handles a vast amount of sensitive and confidential information, making it an attractive target for ransomware groups. The firm's reliance on digital systems for managing client data and legal documents could have been a vulnerability exploited by APT73. Phishing attacks, a common entry point for ransomware, may have been used to gain initial access to the firm's systems.

Implications and Next Steps

The attack on Gannons Solicitors underscores the growing threat of ransomware to the legal sector. Firms must remain vigilant and adopt robust cybersecurity measures to protect sensitive client information. The incident serves as a reminder of the importance of cybersecurity in safeguarding the integrity and confidentiality of legal services.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.