LawDepot Hit by Rhysida Ransomware: 5.5 TB Data Stolen
Incident Date:
July 23, 2024
Overview
Title
LawDepot Hit by Rhysida Ransomware: 5.5 TB Data Stolen
Victim
LawDepot
Attacker
Rhysida
Location
First Reported
July 23, 2024
LawDepot Ransomware Attack by Rhysida Group
Overview of LawDepot
LawDepot is an online platform specializing in customizable legal documents and forms. Founded in 2002 and headquartered in Edmonton, Alberta, Canada, the company has additional offices in the United States. LawDepot employs approximately 172 individuals and generates around $11 million in revenue as of 2024. The platform has assisted over 4 million users in creating more than 10 million legal documents, saving an estimated $5 billion in legal fees. LawDepot's user-friendly interface and comprehensive resources make it a leader in the legal technology sector.
Details of the Attack
LawDepot has fallen victim to a ransomware attack orchestrated by the Rhysida group. The cybercriminals claim to have exfiltrated 5.5 TB of sensitive data, including a backup of the SQL database, full website copies, internal passwords, database certificates, and confidential customer information. This stolen data encompasses credit card and PayPal details, as well as legal documents from various countries. Additionally, the attackers have seized LawDepot's internal GitLab and wiki knowledge base. Rhysida is demanding a ransom of 30 Bitcoin, approximately $2 million, with a payment deadline set for July 30, 2024. If unpaid, the group threatens to auction the data on the dark web.
About the Rhysida Ransomware Group
The Rhysida Ransomware Group emerged in May 2023 and has targeted sectors such as education, healthcare, manufacturing, information technology, and government. The ransomware is written in C++ and primarily targets Windows operating systems. Rhysida employs a double extortion technique, stealing data before encrypting it and threatening to publish it unless a ransom is paid. The group uses the ChaCha20 encryption algorithm and demands Bitcoin payments. Rhysida has been active in various regions, including the U.K., U.S., and Chile, and has previously attacked organizations like Prospect Medical Holdings and the British Library.
Potential Vulnerabilities
LawDepot's extensive database of sensitive customer information makes it an attractive target for ransomware groups like Rhysida. The company's reliance on digital platforms and online services increases its vulnerability to cyberattacks. Rhysida likely penetrated LawDepot's systems through phishing campaigns or by leveraging valid credentials to establish network connections. The group's use of tools like Advance IP/Port Scanner and Sysinternals PsExec for lateral movement within the network further facilitated the attack.
Sources
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.