Army Welfare Trust Targeted by RansomHouse Cybercriminals

Incident Date:

April 24, 2024

World map

Overview

Title

Army Welfare Trust Targeted by RansomHouse Cybercriminals

Victim

Army Welfare Trust

Attacker

Ransomhouse

Location

Rawalpindi, Pakistan

, Pakistan

First Reported

April 24, 2024

RansomHouse Cyberattack on Army Welfare Trust

Company Overview

The Army Welfare Trust (AWT), also known as Askari Group of Companies, is a substantial conglomerate based in Rawalpindi, Pakistan. Established in 1971, AWT has diversified into various sectors including insurance, aviation, agriculture, manufacturing, and real estate, among others. With an asset base exceeding Rs 40 billion (approximately $240 million USD), AWT plays a pivotal role in the welfare of Pakistan Army personnel's families by providing employment and generating funds for orphans, widows, and disabled army personnel.

Managed predominantly by ex-military personnel, AWT's significant presence in the insurance sector through Askari Life Assurance and its investment arm, AWT Investments Limited, highlights its influence in financial services. The conglomerate's broad reach and substantial financial dealings make it a notable entity in Pakistan's commercial landscape.

Details of the RansomHouse Attack

In a recent cybersecurity incident, the Army Welfare Trust was targeted by the cybercriminal group RansomHouse. This attack resulted in the exfiltration of approximately 400 GB of data. The specifics of the data type remain undisclosed, and no ransom demand has been reported thus far. However, the breach led to the online leakage of some data samples.

In-depth analyses have revealed compromised credentials affecting 6 employees and 118 users, along with potential vulnerabilities in 1 employee URL and 21 user URLs. These compromised credentials and external surface attacks expose the organization to further cyber threats.

Implications and Industry Impact

The attack on AWT by RansomHouse not only jeopardizes sensitive data but also highlights the vulnerabilities that large conglomerates face in safeguarding their digital assets. This incident serves as a critical reminder of the importance of robust cybersecurity measures, especially for entities with extensive financial and personal data.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.