ElDorado Ransomware Strikes Adams Homes in Devastating Attack

Incident Date:

June 6, 2024

World map

Overview

Title

ElDorado Ransomware Strikes Adams Homes in Devastating Attack

Victim

Adams Homes

Attacker

ElDorado

Location

Pensacola, USA

Florida, USA

First Reported

June 6, 2024

ElDorado Ransomware Group Targets Adams Homes in Devastating Attack

Overview of Adams Homes

Adams Homes, a prominent residential construction company, specializes in building single-family homes across the southeastern United States. Founded in 1991 by Wayne Adams in Pensacola, Florida, the company has grown to become one of the largest privately-held homebuilders in the country, with an estimated 466 employees and an annual revenue of $41 million. Adams Homes is known for its commitment to quality, affordability, and customer satisfaction, offering a variety of customizable floor plans and home designs.

Details of the Ransomware Attack

Recently, the ransomware group ElDorado has claimed responsibility for an attack on Adams Homes, as announced on their dark web leak site. The attack involved the exfiltration and encryption of sensitive data, which has now been put up for sale. ElDorado's double-extortion tactic not only disrupts operations but also threatens to release the stolen data if the ransom is not paid.

About ElDorado Ransomware Group

In June 2024, ElDorado emerged and quickly gained notoriety for its sophisticated and aggressive ransomware attacks. The group employs a meticulous approach, conducting thorough reconnaissance to identify valuable data before exfiltrating and encrypting it. Their ransom notes, typically named HOW_RETURN_YOUR_DATA.TXT, threaten ongoing attacks and data leaks if demands are not met. ElDorado uses a variety of tactics, including phishing, exploiting unpatched vulnerabilities, and leveraging weaknesses in Remote Desktop Protocol (RDP) configurations.

Potential Vulnerabilities and Penetration Methods

Like many small and medium-sized businesses, Adams Homes may have been targeted due to potentially less robust cybersecurity defenses. ElDorado likely penetrated the company's systems through phishing attacks or exploiting unpatched software vulnerabilities. Once inside, they used legitimate system administration tools to blend in with normal operations, making detection difficult. The group's sophisticated encryption algorithms further crippled Adams Homes' operations, leaving them with limited options but to consider the ransom demands.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.