lockbit2 attacks KHS

Incident Date:

May 17, 2022

World map

Overview

Title

lockbit2 attacks KHS

Victim

KHS

Attacker

Lockbit2

Location

, Germany

Koln, Germany

First Reported

May 17, 2022

KHS, a German Steuerberatungs- und Wirtschaftsprüfungsgesellschaft, Targeted by Lockbit2 Ransomware Group

KHS, a German company specializing in tax consulting and auditing, has been targeted by the ransomware group Lockbit2. The attack was announced on the group's dark web leak site, and the victim's website is KHS operates in the Business Services sector and is known for its expertise in national and international tax law, as well as its services in accounting and business valuation.

Company Profile

KHS is a mid-sized company based in Cologne, Germany. It provides tax consulting and auditing services to both national and international clients, including businesses and individuals. The company's team of tax advisors and auditors has a recognized expertise in national and international tax law, and they combine this knowledge with expertise in accounting and business valuation.

Vulnerabilities and Targeting

The specific vulnerabilities that led to KHS being targeted by Lockbit2 are not publicly disclosed. However, ransomware groups often exploit unpatched software, weak passwords, or phishing attacks to gain access to a target's network. In the case of KHS, it is unclear whether the company had any specific vulnerabilities that made it more susceptible to a ransomware attack.

Impact and Response

The ransomware attack on KHS has caused disruptions to the company's internal IT systems and has taken some of its subsidiary websites offline. KHS has hired external cybersecurity experts to recover from the incident and is in touch with its insurers. The company has not disclosed whether it has paid a ransom to the attackers.

Mitigation Strategies

To mitigate the risk of ransomware attacks, companies should regularly conduct vulnerability scanning to identify and address vulnerabilities, especially on internet-facing devices. They should also maintain offline, encrypted backups of data and regularly test backups. Regularly patching and updating software and operating systems is also crucial in preventing ransomware attacks.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.