lockbit2 attacks PWMA

Incident Date:

February 14, 2022

World map

Overview

Title

lockbit2 attacks PWMA

Victim

PWMA

Attacker

Lockbit2

Location

Cleynhenslaan, Belgium

Keerbergen, Belgium

First Reported

February 14, 2022

Ransomware Attack on PWMA: Analyzing the Impact and Vulnerabilities

Company Size and Industry Standing

The Private Wealth Management Association (PWMA), an industry association established in 2013 to foster the growth and development of the private wealth management industry in Hong Kong, has been targeted by the ransomware group Lockbit2. The attack was announced on the dark web leak site, and the victim's website is https://www.pwma.org.hk/. PWMA operates in the Finance sector and is known for its mission to enhance the competency framework of its members through the Enhanced Competency Framework (ECF).

Vulnerabilities and Targeting

The ransomware attack on PWMA highlights the vulnerabilities of the organization and the industry as a whole. Ransomware is a form of malware designed to encrypt files on a device, rendering any files and the systems that rely on them unusable. The attackers demand a ransom payment for the decryption key, placing organizations in a position where paying the ransom is often the easiest and cheapest way to regain access to their data.

Ransomware attacks can gain access to an organization's systems through various vectors, including phishing emails and Remote Desktop Protocol (RDP). In the case of PWMA, the attackers may have exploited vulnerabilities in the organization's systems or used social engineering tactics to gain access.

Mitigation Strategies

To mitigate the risks of ransomware attacks, organizations should implement good cyber hygiene habits, such as conducting regular vulnerability scanning, maintaining offline, encrypted backups of data, and regularly patching and updating software and operating systems. In the event of an attack, victims should report to federal law enforcement and can request technical assistance or provide information to help others by contacting the Cybersecurity and Infrastructure Security Agency (CISA).

The ransomware attack on PWMA underscores the importance of cybersecurity in the finance sector and the need for organizations to implement robust security measures to protect against such threats. By understanding the vulnerabilities and taking proactive steps to mitigate risks, organizations can better safeguard their data and operations from ransomware attacks.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.