DarkVault Ransomware Hits Glazkov CPA in Israel, Data Threatened

Incident Date:

August 13, 2024

World map

Overview

Title

DarkVault Ransomware Hits Glazkov CPA in Israel, Data Threatened

Victim

Glazkov CPA

Attacker

DarkVault

Location

Tel Aviv-Jaffa, Israel

, Israel

First Reported

August 13, 2024

DarkVault Ransomware Group Targets Glazkov CPA in Israel

Glazkov CPA, a professional services firm based in Israel, has fallen victim to a ransomware attack orchestrated by the DarkVault group. The attackers have threatened to release the company's data publicly on August 20, 2024, unless their demands are met. This incident underscores the growing threat of ransomware attacks on businesses worldwide.

About Glazkov CPA

Founded in 2012 by Irena Glazkov, CPA, Glazkov Accountants specializes in a comprehensive array of accounting, tax planning, and business consulting services. The firm caters to both businesses and individuals, emphasizing a personalized approach to meet the specific needs of its clients. Their services include efficient tax planning, accounting services, and tax filings, with a particular focus on corporate tax planning and payroll management.

Glazkov CPA stands out in its field through its multilingual services, offering assistance in Hebrew, English, Russian, and Arabic. This ability to communicate effectively with a diverse clientele enhances its appeal, particularly to foreign investors looking to navigate the Israeli market. The firm also emphasizes a practical, no-nonsense approach to accounting and tax planning, which is designed to help businesses maximize their financial efficiency while ensuring compliance with local laws.

Attack Overview

The DarkVault ransomware group has claimed responsibility for the attack on Glazkov CPA via their dark web leak site. The attackers have threatened to release the company's data publicly, putting sensitive client information at risk. The exact method of penetration remains unclear, but it is likely that the attackers exploited vulnerabilities in the company's cybersecurity defenses.

About DarkVault Ransomware Group

DarkVault is a relatively new player in the ransomware landscape, having emerged recently with a dark web leak site that mirrors the design of the LockBit leak site. This group's tactics and targets are still being studied, but their appearance signifies a new threat in the realm of ransomware attacks. DarkVault's association with the dark web implies a clandestine and covert operational model, making it challenging for authorities to track and counter their activities effectively.

DarkVault's choice to establish a dark web leak site akin to LockBit's suggests a deliberate attempt to emulate successful ransomware operations. This imitation strategy could indicate a level of sophistication in their approach, potentially enabling them to exploit vulnerabilities in cybersecurity defenses. Given the rise in ransomware attacks globally, DarkVault's emergence adds to the urgency for organizations to enhance their cybersecurity measures.

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.