RansomHub Ransomware Attack Exposes 79GB of Data from BSG

Incident Date:

September 9, 2024

World map

Overview

Title

RansomHub Ransomware Attack Exposes 79GB of Data from BSG

Victim

BSG (Business Strategy Group)

Attacker

Ransomhub

Location

Bangkok, Thailand

, Thailand

First Reported

September 9, 2024

RansomHub Targets Business Strategy Group in Ransomware Attack

RansomHub, a notorious Ransomware-as-a-Service (RaaS) group, has claimed responsibility for a ransomware attack on Business Strategy Group (BSG), an Australian consultancy firm. The attack, disclosed on September 10, has resulted in the exfiltration of 79 gigabytes of sensitive data from BSG, which specializes in providing strategic business solutions and project management services.

About Business Strategy Group

BSG, headquartered in Victoria, Australia, is a boutique consultancy firm known for its comprehensive consulting services aimed at enhancing business performance and strategic decision-making. The company offers market research, business intelligence, merger and acquisition consulting, commercial due diligence, and corporate strategy development. BSG is particularly noted for its Asian Business Media Tracker and its role as the representative office for UFI in the Asia-Pacific region. The firm operates with a team of professionals and has an estimated annual revenue of approximately $21.9 million.

Attack Overview

The ransomware attack on BSG was orchestrated by an affiliate of the RansomHub group. The attackers have listed BSG on their darknet leak site, claiming to have exfiltrated 79 gigabytes of data. Among the documents posted are a bank statement from NAB linked to an account named “Big Bucks Bingo,” a document detailing hourly pay rates, and an expired passport scan. These documents span from 2017 to 2024, indicating the potential exposure of sensitive financial and personal information.

About RansomHub

RansomHub emerged in February 2024 and quickly established itself in the ransomware landscape through an aggressive affiliate model. The group is known for its speed and efficiency, using advanced data exfiltration techniques and intermittent encryption to minimize encryption time while maintaining impact. RansomHub affiliates primarily use phishing campaigns, vulnerability exploitation, and password spraying to gain initial access. The group targets high-value sectors such as healthcare, financial services, and government.

Penetration and Vulnerabilities

RansomHub likely penetrated BSG's systems through a combination of phishing campaigns and exploiting unpatched vulnerabilities. The group's affiliates are known for conducting multi-phase attacks involving network reconnaissance, privilege escalation, and data exfiltration before encrypting files. BSG's focus on handling sensitive financial and strategic data makes it an attractive target for ransomware groups like RansomHub.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.