DragonForce Ransomware Hits Franciscan Friars
Incident Date:
July 2, 2024
Overview
Title
DragonForce Ransomware Hits Franciscan Friars
Victim
Franciscan Friars of the Atonement
Attacker
Dragonforce
Location
First Reported
July 2, 2024
Ransomware Attack on Franciscan Friars of the Atonement by DragonForce Group
Victim Profile: Franciscan Friars of the Atonement
The Franciscan Friars of the Atonement, a Roman Catholic religious order founded in 1898, is headquartered at Graymoor in Garrison, New York. With a mission centered on reconciliation and atonement, the order operates across the United States, Canada, England, Italy, and Japan. They specialize in religious institutions and personal services, employing approximately 87 individuals and generating an estimated revenue of $10.8 million. Their work spans from ecumenical efforts for Christian unity to social ministries aiding marginalized communities, making them a unique entity within their sector.
Attack Overview
The Franciscan Friars of the Atonement recently fell victim to a ransomware attack orchestrated by the group known as DragonForce. This attack involved the encryption of sensitive data and threats of its release unless a ransom was paid, a tactic known as double extortion. The attack was publicly claimed on DragonForce's dark web leak site, "DragonLeaks," where they often post about their exploits and negotiations with victims.
Ransomware Group: DragonForce
DragonForce is a newly emerged cyber threat group that surfaced in late 2023. Known for their double extortion tactics, they have quickly gained notoriety by targeting a variety of industries globally. Their ransomware code appears to be derived from the leaked LockBit ransomware builder, indicating a sophisticated level of technical capability in deploying ransomware attacks. DragonForce distinguishes itself by not only threatening the release of encrypted data but also by engaging in public negotiations and releasing audio recordings of these interactions on their platform.
Potential Vulnerabilities and Penetration Tactics
The Franciscan Friars of the Atonement, like many organizations in the religious and non-profit sector, may be perceived as having less stringent cybersecurity measures compared to large corporate entities. This can make them attractive targets for ransomware groups looking for easier penetration and potentially quicker ransom payments. The specific vector of attack used by DragonForce to infiltrate the Friars’ network has not been disclosed, but common tactics include phishing, exploiting unpatched software vulnerabilities, or accessing weak remote desktop protocols.
Sources
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.