ElDorado Ransomware Strikes Thunderbird Country Club
Incident Date:
June 6, 2024
Overview
Title
ElDorado Ransomware Strikes Thunderbird Country Club
Victim
Thunderbird Country Club
Attacker
ElDorado
Location
First Reported
June 6, 2024
ElDorado Ransomware Attack on Thunderbird Country Club
Overview of Thunderbird Country Club
Situated in Rancho Mirage, California, Thunderbird Country Club is a prestigious and historic institution known for its high-quality amenities and activities. With around 38 employees and an annual revenue of approximately $8 million, the club offers golf, tennis, wellness facilities, social events, and dining experiences. It is renowned for its role in defining the casual elegance of desert living in the Coachella Valley.
Details of the Ransomware Attack
Recently, the ransomware group ElDorado has claimed responsibility for an attack on Thunderbird Country Club. The attack resulted in the exfiltration of 28.9GB of data, which is now up for sale on ElDorado's dark web leak site. The group employs a double-extortion tactic, encrypting files and threatening to release sensitive data if ransom demands are not met.
About ElDorado Ransomware Group
Emerging in 2024, ElDorado quickly gained notoriety through a series of high-profile attacks. The group is known for its meticulous targeting and sophisticated techniques, including phishing attacks, exploiting unpatched vulnerabilities, and living-off-the-land tactics. Their ransom notes, typically named HOW_RETURN_YOUR_DATA.TXT, threaten ongoing attacks and data leaks if victims do not comply within seven days.
Vulnerabilities and Penetration Methods
Like many small hospitality organizations, Thunderbird Country Club may have been targeted due to potentially less robust cybersecurity defenses. ElDorado likely penetrated the club's systems through phishing emails or exploiting unpatched software vulnerabilities. Once inside, they conducted thorough reconnaissance to identify valuable data for exfiltration and encryption.
Impact and Implications
Significantly, the attack on Thunderbird Country Club underscores the growing threat of ransomware groups like ElDorado. The exfiltration and potential sale of 28.9GB of data could have significant repercussions for the club and its members, highlighting the critical need for enhanced cybersecurity measures in the hospitality sector.
Sources
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.