APT73 Ransomware Breach Compromises Borrer Executive Search's Sensitive Data

Incident Date:

June 13, 2024

World map

Overview

Title

APT73 Ransomware Breach Compromises Borrer Executive Search's Sensitive Data

Victim

Borrer Executive Search

Attacker

APT73

Location

Lausanne, Switzerland

, Switzerland

First Reported

June 13, 2024

APT73 Ransomware Attack on Borrer Executive Search

Company Profile

Borrer Executive Search, founded in 2010 and based in Lausanne, Switzerland, is a boutique search and selection firm accredited by AESC. Specializing in identifying and placing high-caliber executives, the firm operates across Switzerland, Europe, the Middle East, Africa, and Asia-Pacific. Led by Managing Partners Jennifer and Emile Borrer, the company focuses on management positions in global operations, commercial leadership, finance, and human resources. Known for its rigorous search process and transparent approach, Borrer Executive Search provides personalized attention and customized solutions for each client engagement.

Attack Overview

On June 14, 2024, Borrer Executive Search experienced a data breach perpetrated by the ransomware group APT73. The attack resulted in the compromise of 2.5MB of internal documents and agreements. The breach was announced on APT73's dark web leak site, ERALEIGNEWS, which follows a LockBit-styled approach. The exact method of penetration remains unclear, but APT73 typically employs phishing attacks to compromise systems and deploy ransomware.

Ransomware Group Profile

APT73 is a relatively new ransomware group that emerged in December 2023. The group operates a TOR-based data leak site and has previously targeted TRIFECTA, a U.S.-based customer service platform. APT73's modus operandi includes phishing attacks and the use of a LockBit-styled data leak site. The group operates from an IP address in Prague, Czechia, and utilizes AS9009, a network associated with various malicious activities. Despite some amateurish traits, APT73 poses a significant threat due to its sophisticated ransomware tactics.

Vulnerabilities and Impact

Borrer Executive Search's focus on high-level executive placements makes it a lucrative target for ransomware groups like APT73. The firm's extensive network and access to sensitive client information increase its vulnerability. The breach of internal documents and agreements could have severe implications for both the firm and its clients, potentially leading to financial losses and reputational damage.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.