LockBit 3.0 Ransomware Attack on Kings Academy Essex

Incident Date:

May 9, 2024

World map

Overview

Title

LockBit 3.0 Ransomware Attack on Kings Academy Essex

Victim

Kings Academy Essex

Attacker

Lockbit3

Location

Cheddar, United Kingdom

, United Kingdom

First Reported

May 9, 2024

<

Ransomware Attack on Kings Academy Essex

Victim Profile

Kings Academy Essex, a high-achieving secondary school located in Kowessex, UK, serves students aged 13-18. The school is known for its outstanding exam results, with students making excellent progress from Key Stage 2 to 4. Many students go on to attend top universities after completing their Sixth Form studies. Kings Academy positions itself as one of the top performing schools in the country, providing an engaging and effective teaching environment based on core values and up-to-date educational practices.

Vulnerabilities and Targeting

Kings Academy Essex was targeted by the LockBit 3.0 ransomware group, known for its advanced capabilities and evasive nature. The attack resulted in the exfiltration of 67 GB of data, including email correspondence, emphasizing the ongoing threat of ransomware attacks in the education sector.

Ransomware Group Overview

The LockBit 3.0 ransomware group is an evolution of the LockBit group, operating under a Ransomware-as-a-Service (RaaS) model. LockBit 3.0 is considered one of the most dangerous and disruptive ransomware threats, with features like file encryption, desktop modifications, and lateral movement through networks. The group has targeted a wide range of organizations globally, including major companies, making it a significant cyber threat.

LockBit May Attacks

This is part of the May 2024 attacks by LockBit 3.0, a cybercriminal group that resurfaced with vigor following the disruption of its infrastructure during "Operation Cronos." Despite arrests and the dismantling of its data leak site, LockBit swiftly returned, targeting over 50 victims within hours of reactivating its platform. These assaults spanned various sectors and countries.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.