lockbit2 attacks Empire Insurance Broker
Incident Date:
January 1, 2022
Overview
Title
lockbit2 attacks Empire Insurance Broker
Victim
Empire Insurance Broker
Attacker
Lockbit2
Location
First Reported
January 1, 2022
Empire Insurance Broker Suffers Ransomware Attack by LockBit2
Company Overview
Empire Insurance Broker, a premier provider of insurance brokerage services, has been serving clients across various industries for over 30 years. With a commitment to excellence, the company holds NAILBA certification, ensuring top-tier service and effective case resolutions for its clientele.
Company Size and Industry Standout
As a notable entity in the insurance sector, Empire Insurance Broker distinguishes itself by managing intricate cases and crafting tailored policies. Their unparalleled connections and industry knowledge set them apart from competitors.
Vulnerabilities and Targeting
The exact vulnerabilities exploited in the ransomware attack on Empire Insurance Broker remain unspecified. Nonetheless, the involvement of LockBit2, a notorious ransomware group with a history of targeting prominent organizations, including SpaceX, underscores the critical need for robust cybersecurity defenses. This group's activities are often attributed to a Russia-based leadership.
Response and Mitigation
In the absence of an official communication from Empire Insurance Broker regarding the attack or their response strategy, it underscores the importance of proactive cybersecurity practices. Organizations are urged to invest in employee cybersecurity training, regular system updates, and the implementation of comprehensive security measures to safeguard against future incidents.
Sources
- Empire Insurance Broker website: http://empireins.com
- LockBit attack on dental insurer impacts 8.9M patients: https://www.fiercehealthcare.com/health-tech/attack-notorious-ransomware-group-compromises-personal-data-89-million
- Empire Company Limited (Sobeys et al) ransomware attack: https://www.reddit.com/r/PersonalFinanceCanada/comments/yr0zsn/empire_company_limited_sobeys_et_al_ransomware/
- Empire State Building lands NY insurer: https://www.linkedin.com/posts/paul-e-hacker-713b51122_empire-state-building-lands-ny-insurer-with-activity-7156645807146876928-VyCA
- Dridex Banking Trojan Infections and PowerShell Empire Activity: https://ociso.ucla.edu/news/dridex-banking-trojan-infections-and-powershell-empire-activity-preceding-bitpaymer-ransomware
- Responding to a massive cyber-attack at a multi-national insurance broker: https://www.crai.com/engagements/responding-to-a-massive-cyber-attack-at-a-multi-national-insurance-broker/
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.