LawDepot Hit by Rhysida Ransomware: 5.5 TB Data Stolen

Incident Date:

July 23, 2024

World map

Overview

Title

LawDepot Hit by Rhysida Ransomware: 5.5 TB Data Stolen

Victim

LawDepot

Attacker

Rhysida

Location

Edmonton, Canada

, Canada

First Reported

July 23, 2024

LawDepot Ransomware Attack by Rhysida Group

Overview of LawDepot

LawDepot is an online platform specializing in customizable legal documents and forms. Founded in 2002 and headquartered in Edmonton, Alberta, Canada, the company has additional offices in the United States. LawDepot employs approximately 172 individuals and generates around $11 million in revenue as of 2024. The platform has assisted over 4 million users in creating more than 10 million legal documents, saving an estimated $5 billion in legal fees. LawDepot's user-friendly interface and comprehensive resources make it a leader in the legal technology sector.

Details of the Attack

LawDepot has fallen victim to a ransomware attack orchestrated by the Rhysida group. The cybercriminals claim to have exfiltrated 5.5 TB of sensitive data, including a backup of the SQL database, full website copies, internal passwords, database certificates, and confidential customer information. This stolen data encompasses credit card and PayPal details, as well as legal documents from various countries. Additionally, the attackers have seized LawDepot's internal GitLab and wiki knowledge base. Rhysida is demanding a ransom of 30 Bitcoin, approximately $2 million, with a payment deadline set for July 30, 2024. If unpaid, the group threatens to auction the data on the dark web.

About the Rhysida Ransomware Group

The Rhysida Ransomware Group emerged in May 2023 and has targeted sectors such as education, healthcare, manufacturing, information technology, and government. The ransomware is written in C++ and primarily targets Windows operating systems. Rhysida employs a double extortion technique, stealing data before encrypting it and threatening to publish it unless a ransom is paid. The group uses the ChaCha20 encryption algorithm and demands Bitcoin payments. Rhysida has been active in various regions, including the U.K., U.S., and Chile, and has previously attacked organizations like Prospect Medical Holdings and the British Library.

Potential Vulnerabilities

LawDepot's extensive database of sensitive customer information makes it an attractive target for ransomware groups like Rhysida. The company's reliance on digital platforms and online services increases its vulnerability to cyberattacks. Rhysida likely penetrated LawDepot's systems through phishing campaigns or by leveraging valid credentials to establish network connections. The group's use of tools like Advance IP/Port Scanner and Sysinternals PsExec for lateral movement within the network further facilitated the attack.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.