Cybersecurity Breach: Ransomware Attack on Nikolaus & Hohenadel

Incident Date:

May 6, 2024

World map



Cybersecurity Breach: Ransomware Attack on Nikolaus & Hohenadel


Nikolaus and Hohenadel




Lancaster, USA

Pennsylvania, USA

First Reported

May 6, 2024

Ransomware Attack on Nikolaus & Hohenadel by BianLian Group

Victim Profile: Nikolaus & Hohenadel, LLP

Nikolaus & Hohenadel, LLP is a prominent law firm based in Lancaster, PA, with additional offices in Columbia, PA. The firm, established with a strong regional presence, employs over 25 attorneys and offers a wide range of legal services. Known for its significant role in the local legal landscape, the firm handles everything from family law to corporate litigation. Their website serves as a portal for their clients and includes comprehensive information about their services, attorney profiles, and office locations.

Details of the Attack

The cyberattack on Nikolaus & Hohenadel was orchestrated by the ransomware group BianLian. The attackers managed to exfiltrate approximately 388 GB of sensitive data, including financial records, human resources documents, legal files, client communications, and email correspondences. The specifics of the ransom demand, if any, have not been disclosed publicly. This incident highlights significant vulnerabilities in the firm's cybersecurity measures, potentially in areas such as network security, data encryption, and endpoint protection.

Ransomware Group: BianLian

BianLian, originally known as a banking trojan, has evolved into a sophisticated ransomware group. Their operations have expanded from individual attacks to targeting large organizations, with a particular focus on sectors like healthcare, legal, and professional services. BianLian is known for its methodical approach to attacks, often gaining initial access through compromised Remote Desktop Protocol (RDP) credentials, followed by the deployment of custom backdoors and extensive use of scripting tools to evade defenses and exfiltrate data.

Potential Vulnerabilities and Entry Points

For a law firm like Nikolaus & Hohenadel, the primary vulnerabilities likely exploited by BianLian could include insufficiently secured RDP setups, lack of robust endpoint defenses, and possibly inadequate employee training on phishing and other social engineering attacks. Given the firm's significant data troves, including sensitive client information, it presents a high-value target for ransomware groups seeking financial gain through data exfiltration and extortion.


Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.