Everest Ransomware Group Strikes VFOS with Data Breach Threat

Incident Date:

June 4, 2024

World map

Overview

Title

Everest Ransomware Group Strikes VFOS with Data Breach Threat

Victim

Voorhees Family Office Services

Attacker

Everest

Location

Voorhees Township, USA

New Jersey, USA

First Reported

June 4, 2024

Everest Ransomware Group Targets Voorhees Family Office Services

Company Profile

Voorhees Family Office Services (VFOS) is a Registered Investment Advisory firm based in Irvine, California. Founded and led by Tim Voorhees, JD, MBA, VFOS specializes in wealth counseling, wealth blueprinting, and legacy planning services for high-net-worth individuals and families. The firm supports Million Voorhees Ziebold LLP (MVZ) by providing plan design, reporting, and case coordination services. VFOS employs approximately 14 people and is recognized for its expertise in advanced wealth planning techniques.

Attack Overview

The Everest Ransomware Group has claimed responsibility for a ransomware attack on VFOS. The attackers have exfiltrated 600 GB of sensitive data, including client files, private company data, and various folders with specific names. Everest has issued a 24-hour ultimatum for VFOS to contact them, threatening to publish the stolen data if their demands are not met.

Details of the Attack

The compromised data includes client lists, financial records, emails, and other sensitive information. The attackers have listed specific folders such as "Advisors 12723446 Asset Protection" and "857125 Client Lists" among others. This breach exposes VFOS to significant risks, including potential financial loss and reputational damage.

About Everest Ransomware Group

Active since December 2020, the Everest Ransomware Group is known for ransomware attacks, data exfiltration, and initial access brokering. The group targets various industries, including healthcare and public sectors, and has been linked to other ransomware groups like BlackByte. Everest uses AES and DES algorithms to encrypt files and often employs compromised user accounts and Remote Desktop Protocol (RDP) for lateral movement.

Penetration Tactics

Everest likely penetrated VFOS's systems through compromised user accounts or RDP vulnerabilities. The group's sophisticated tactics and focus on high-profile targets make organizations like VFOS particularly vulnerable. The attack underscores the importance of robust cybersecurity measures, especially for firms handling sensitive financial and personal data.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.