Family Guardian Insurance: Targeted by Cactus Ransomware

Incident Date:

June 2, 2024

World map

Overview

Title

Family Guardian Insurance: Targeted by Cactus Ransomware

Victim

Family Guardian Insurance Company Limited

Attacker

Cactus

Location

Nassau, Bahamas

, Bahamas

First Reported

June 2, 2024

Ransomware Attack on Family Guardian Insurance Company Limited

Company Overview

Established in 1965 in the Bahamas, Family Guardian Insurance Company Limited is a financial services company dedicated to helping individuals and families secure their financial future. They offer a diverse range of products and services, including life insurance, health insurance, retirement planning, and investment services. As a wholly-owned subsidiary of FamGuard Corporation Limited, Family Guardian is listed on the Bahamas International Securities Exchange (BISX).

Attack Overview

The Family Guardian Insurance Company Limited recently fell victim to the Cactus ransomware group, which leaked a significant amount of sensitive data. This data breach includes confidential client documents, corporate correspondence, personal data of company executives and employees, database backups, and other critical information. The compromised data comprises a mix of internal company documents and personal information related to clients and employees.

Ransomware Group Profile

Known for operating as a ransomware-as-a-service (RaaS), the Cactus ransomware group is notorious for exploiting vulnerabilities and using malvertising lures for their targeted attacks. This group has been observed exploiting the ZeroLogon vulnerability and utilizes unique encryption techniques to evade detection. Affiliates of Cactus ransomware deploy custom scripts to disable security tools and spread the ransomware, targeting organizations of all sizes across various industries.

Company Vulnerabilities

As a financial services company, Family Guardian Insurance Company Limited holds a substantial amount of sensitive financial and personal data, making them an attractive target for cybercriminals like the Cactus ransomware group. The company's extensive online presence and interconnected systems likely provided pathways for the ransomware group to infiltrate their networks and execute the attack.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.