DragonForce Ransomware Hits Franciscan Friars

Incident Date:

July 2, 2024

World map

Overview

Title

DragonForce Ransomware Hits Franciscan Friars

Victim

Franciscan Friars of the Atonement

Attacker

Dragonforce

Location

Garrison, USA

New York, USA

First Reported

July 2, 2024

Ransomware Attack on Franciscan Friars of the Atonement by DragonForce Group

Victim Profile: Franciscan Friars of the Atonement

The Franciscan Friars of the Atonement, a Roman Catholic religious order founded in 1898, is headquartered at Graymoor in Garrison, New York. With a mission centered on reconciliation and atonement, the order operates across the United States, Canada, England, Italy, and Japan. They specialize in religious institutions and personal services, employing approximately 87 individuals and generating an estimated revenue of $10.8 million. Their work spans from ecumenical efforts for Christian unity to social ministries aiding marginalized communities, making them a unique entity within their sector.

Attack Overview

The Franciscan Friars of the Atonement recently fell victim to a ransomware attack orchestrated by the group known as DragonForce. This attack involved the encryption of sensitive data and threats of its release unless a ransom was paid, a tactic known as double extortion. The attack was publicly claimed on DragonForce's dark web leak site, "DragonLeaks," where they often post about their exploits and negotiations with victims.

Ransomware Group: DragonForce

DragonForce is a newly emerged cyber threat group that surfaced in late 2023. Known for their double extortion tactics, they have quickly gained notoriety by targeting a variety of industries globally. Their ransomware code appears to be derived from the leaked LockBit ransomware builder, indicating a sophisticated level of technical capability in deploying ransomware attacks. DragonForce distinguishes itself by not only threatening the release of encrypted data but also by engaging in public negotiations and releasing audio recordings of these interactions on their platform.

Potential Vulnerabilities and Penetration Tactics

The Franciscan Friars of the Atonement, like many organizations in the religious and non-profit sector, may be perceived as having less stringent cybersecurity measures compared to large corporate entities. This can make them attractive targets for ransomware groups looking for easier penetration and potentially quicker ransom payments. The specific vector of attack used by DragonForce to infiltrate the Friars’ network has not been disclosed, but common tactics include phishing, exploiting unpatched software vulnerabilities, or accessing weak remote desktop protocols.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.