Everest Ransomware Hits Cukierski & Associates, LLC: A Growing Cyber Threat

Incident Date:

June 13, 2024

World map

Overview

Title

Everest Ransomware Hits Cukierski & Associates, LLC: A Growing Cyber Threat

Victim

Cukierski & Associates, LLC

Attacker

Everest

Location

Arlington Heights, USA

Illinois, USA

First Reported

June 13, 2024

Everest Ransomware Group Targets Cukierski & Associates, LLC

Overview of the Victim

Cukierski & Associates, LLC, a full-service accounting firm based in Arlington Heights, Illinois, has been providing professional tax and accounting services for over 40 years. The firm offers a wide range of services including tax planning and preparation, accounting and bookkeeping, business consulting, and financial planning. Known for its personalized and high-quality services, Cukierski & Associates is a trusted name in the finance sector, serving businesses, community associations, nonprofits, and individuals.

Details of the Attack

On June 14, 2024, the Everest ransomware group claimed responsibility for an attack on Cukierski & Associates, LLC. The attack was announced on Everest's dark web leak site, although the exact size of the data breach remains unknown. The ransomware group is notorious for its sophisticated tactics, including data exfiltration and the use of compromised user accounts and Remote Desktop Protocol (RDP) for lateral movement within targeted networks.

About Everest Ransomware Group

Active since December 2020, the Everest ransomware group has evolved from a data exfiltration outfit to a full-fledged ransomware operator. The group has been linked to the EverBe 2.0 family and has connections with other ransomware groups like BlackByte. Everest is known for targeting high-profile organizations across various industries, including finance, healthcare, and the public sector. The group employs advanced encryption algorithms such as AES and DES, adding the “.EVEREST” extension to encrypted files.

Potential Vulnerabilities

Cukierski & Associates, LLC, like many firms in the finance sector, handles sensitive financial data, making it an attractive target for ransomware groups. The firm's reliance on digital systems for tax preparation, accounting, and financial planning could have exposed vulnerabilities that Everest exploited. The use of compromised user accounts and RDP for lateral movement suggests that the attackers may have gained initial access through phishing or exploiting weak passwords.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.