MBS Radio Hit by MetaEncryptor Ransomware, 130 MB of Data Stolen

Incident Date:

August 15, 2024

World map

Overview

Title

MBS Radio Hit by MetaEncryptor Ransomware, 130 MB of Data Stolen

Victim

MBS Radio

Attacker

MetaEncryptor

Location

Halifax, Canada

, Canada

First Reported

August 15, 2024

MetaEncryptor Ransomware Group Claims Attack on MBS Radio

MBS Radio, a prominent radio network based in Atlantic Canada, has recently fallen victim to a ransomware attack orchestrated by the MetaEncryptor group. The attack has resulted in the theft of 130 MB of sensitive data, putting the company at risk of data leaks or encryption unless a ransom is paid.

About MBS Radio

MBS Radio, part of the Maritime Broadcasting System, operates 24 radio stations across Nova Scotia, New Brunswick, and Prince Edward Island. Founded in Campbellton, New Brunswick, the network serves a diverse audience, reaching over one million listeners weekly. MBS Radio is dedicated to providing quality broadcasting that caters to the unique cultural and community needs of the Maritimes. The company generates approximately $10 million annually and employs over 100 staff members, making it a significant player in the local media landscape.

Attack Overview

The MetaEncryptor group, known for their sophisticated ransomware tactics, claims to have breached MBS Radio's systems and stolen 130 MB of data. The attack was announced on MetaEncryptor's dark web leak site, where the group threatened to leak or encrypt the stolen data unless a ransom is paid. This incident highlights the vulnerabilities that media companies face, particularly those with extensive digital operations and community outreach initiatives.

About MetaEncryptor

MetaEncryptor is a ransomware operation believed to have launched in August 2022. The group amassed twelve victims on their data leak site through July 2023 before rebranding as LostTrust in September 2023. MetaEncryptor's ransomware encryptor is based on the SFile2 ransomware encryptor, with significant code overlap between samples. The group describes themselves as specialists in network security with at least 15 years of experience, a claim that underscores their technical proficiency and the threat they pose to targeted organizations.

Potential Vulnerabilities

MBS Radio's extensive digital presence, including traditional radio broadcasting, websites, and social media platforms, makes it a lucrative target for ransomware groups like MetaEncryptor. The company's commitment to local and regional advertising, along with its community initiatives, further increases its exposure to cyber threats. The attack on MBS Radio serves as a stark reminder of the importance of cybersecurity measures, particularly for media organizations that handle sensitive data and maintain a significant online presence.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.