Everest Ransomware Group Strikes VFOS with Data Breach Threat
Incident Date:
June 4, 2024
Overview
Title
Everest Ransomware Group Strikes VFOS with Data Breach Threat
Victim
Voorhees Family Office Services
Attacker
Everest
Location
First Reported
June 4, 2024
Everest Ransomware Group Targets Voorhees Family Office Services
Company Profile
Voorhees Family Office Services (VFOS) is a Registered Investment Advisory firm based in Irvine, California. Founded and led by Tim Voorhees, JD, MBA, VFOS specializes in wealth counseling, wealth blueprinting, and legacy planning services for high-net-worth individuals and families. The firm supports Million Voorhees Ziebold LLP (MVZ) by providing plan design, reporting, and case coordination services. VFOS employs approximately 14 people and is recognized for its expertise in advanced wealth planning techniques.
Attack Overview
The Everest Ransomware Group has claimed responsibility for a ransomware attack on VFOS. The attackers have exfiltrated 600 GB of sensitive data, including client files, private company data, and various folders with specific names. Everest has issued a 24-hour ultimatum for VFOS to contact them, threatening to publish the stolen data if their demands are not met.
Details of the Attack
The compromised data includes client lists, financial records, emails, and other sensitive information. The attackers have listed specific folders such as "Advisors 12723446 Asset Protection" and "857125 Client Lists" among others. This breach exposes VFOS to significant risks, including potential financial loss and reputational damage.
About Everest Ransomware Group
Active since December 2020, the Everest Ransomware Group is known for ransomware attacks, data exfiltration, and initial access brokering. The group targets various industries, including healthcare and public sectors, and has been linked to other ransomware groups like BlackByte. Everest uses AES and DES algorithms to encrypt files and often employs compromised user accounts and Remote Desktop Protocol (RDP) for lateral movement.
Penetration Tactics
Everest likely penetrated VFOS's systems through compromised user accounts or RDP vulnerabilities. The group's sophisticated tactics and focus on high-profile targets make organizations like VFOS particularly vulnerable. The attack underscores the importance of robust cybersecurity measures, especially for firms handling sensitive financial and personal data.
Sources:
- http://www.vfos.com
- https://timvoorhees.com
- https://www.zoominfo.com/p/Tim-Voorhees/1669684977
- https://www.vfos.com/welcome/index.asp?id=8
- https://www.familyofficelaw.com/Voorhees/
- https://www.linkedin.com/in/timvoorhees
- https://www.slcyber.io/everest-ransomware-group-increases-initial-access-broker-activity/
- https://www.salvagedata.com/everest-ransomware/
- https://socradar.io/on-the-horizon-ransomed-vc-ransomware-group-spotted-in-the-wild/
- https://research.nccgroup.com/2022/07/13/climbing-mount-everest-black-byte-bytes-back/
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.