ElDorado Ransomware Attack: City of Pensacola Breached

Incident Date:

June 6, 2024

World map

Overview

Title

ElDorado Ransomware Attack: City of Pensacola Breached

Victim

City of Pensacola

Attacker

ElDorado

Location

Pensacola, USA

Florida, USA

First Reported

June 6, 2024

ElDorado Ransomware Attack on City of Pensacola

Overview of the City of Pensacola

The City of Pensacola, a government entity located in Pensacola, Florida, serves a population of 54,312 residents over an area of 40.7 square miles. The city's official website, is a comprehensive digital portal offering services and information to residents, businesses, and visitors. It provides essential services such as utility bill payments, permit applications, and public safety updates, while also supporting community engagement through resources related to health services, housing assistance, and social programs.

Details of the Ransomware Attack

In March, the ransomware group ElDorado executed a significant attack on the City of Pensacola, successfully exfiltrating 1.7TB of data. The group has since claimed responsibility and is now selling the stolen data. This attack has severely impacted the city's ability to provide services and maintain transparency with its residents.

About ElDorado Ransomware Group

ElDorado emerged in 2024 and quickly gained notoriety through a series of high-profile attacks. The group employs a double-extortion tactic, encrypting victims' files and exfiltrating sensitive data. Victims are threatened with the public release of this data if they do not comply with ransom demands. ElDorado's meticulous approach involves thorough reconnaissance to identify valuable data, which is then exfiltrated and encrypted.

Penetration Tactics

The ransomware group ElDorado uses a diverse set of tactics to infiltrate systems, including phishing attacks, exploiting unpatched vulnerabilities, and weaknesses in Remote Desktop Protocol (RDP) configurations. They also execute supply chain attacks, targeting vulnerabilities in software suppliers or third-party vendors. Once inside a network, they use legitimate system administration tools for malicious purposes, making their activities harder to detect.

Impact and Vulnerabilities

The City of Pensacola's extensive digital services and public-facing website made it a prime target for ElDorado. The attack has highlighted vulnerabilities in the city's cybersecurity defenses, particularly in areas such as software updates and RDP configurations. The exfiltration of 1.7TB of data underscores the severity of the breach and the potential risks to residents' personal information and city operations.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.