Jefferson County Clerk's Office Hit by RansomHub Ransomware Attack

Incident Date:

August 11, 2024

World map

Overview

Title

Jefferson County Clerk's Office Hit by RansomHub Ransomware Attack

Victim

Jefferson County Clerk's Office.

Attacker

Ransomhub

Location

Louisville, USA

Kentucky, USA

First Reported

August 11, 2024

RansomHub Ransomware Attack on Jefferson County Clerk's Office

The Jefferson County Clerk's Office, a pivotal institution in Jefferson County, Kentucky, has recently been targeted by the ransomware group RansomHub. This attack has caused significant disruptions, affecting multiple County Clerk locations and leading to the temporary closure of eight branches across Louisville.

About the Jefferson County Clerk's Office

Led by Clerk Bobbie Holsclaw, the Jefferson County Clerk's Office is a state constitutional office responsible for managing a variety of public records and services. The office handles approximately 700,000 vehicle registrations annually, issues marriage licenses, notary commissions, and manages delinquent real estate taxes. Additionally, it oversees the electoral process, ensuring fair and transparent elections. The office employs a dedicated team, although specific employee numbers are not publicly detailed.

Attack Overview

The ransomware attack by RansomHub has led to significant system outages since Monday evening. The attack has necessitated the temporary closure of eight branches, causing delays for residents seeking services such as vehicle registrations, housing deeds, and marriage and notary licenses. Despite the disruption, officials have confirmed that no personal information was compromised, thanks to the office's use of dedicated servers for storing sensitive data. The recovery process has been slow, requiring each of the more than 300 computers to be individually checked and restored to ensure security.

About RansomHub

RansomHub is a relatively new ransomware group believed to have roots in Russia. Operating as a Ransomware-as-a-Service (RaaS) group, RansomHub distinguishes itself by making claims and backing them up with data leaks. Affiliates receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, with healthcare-related institutions being notable victims. RansomHub's ransomware strains are written in Golang, a trend in the ransomware world.

Potential Vulnerabilities

The Jefferson County Clerk's Office, like many government institutions, handles a vast amount of sensitive data and relies heavily on its IT infrastructure. This makes it a prime target for ransomware groups like RansomHub. The attack likely penetrated the office's systems through vulnerabilities in their network security, possibly exploiting outdated software or insufficiently trained staff on cybersecurity practices.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.