RansomHub Ransomware Breach Exposes 30GB of Data at Allan McNeill Accountants

Incident Date:

August 17, 2024

World map

Overview

Title

RansomHub Ransomware Breach Exposes 30GB of Data at Allan McNeill Accountants

Victim

Allan McNeill

Attacker

Ransomhub

Location

Feilding, New Zealand

, New Zealand

First Reported

August 17, 2024

RansomHub Ransomware Attack on Allan McNeill Chartered Accountants

About Allan McNeill Chartered Accountants

Allan McNeill is a well-established firm with over fifty years of experience in the Business Services sector. The firm specializes in providing a wide range of accounting and advisory services, particularly to businesses in the agribusiness sector. Their services include business planning, cash flow forecasting, financial reviews, and succession planning. The firm is known for its deep understanding of the unique financial dynamics of each business, enabling them to offer tailored solutions that support growth and sustainability.

One of the key areas of focus for Allan McNeill is agribusiness, a vital sector for New Zealand's economy. They provide specialized advice to farmers and agribusinesses, addressing critical issues such as succession planning and compliance with evolving regulations. Additionally, the firm offers a Chief Financial Officer service for medium-sized businesses, providing strategic financial insights without the need for a full-time CFO.

Details of the Attack

The ransomware attack on Allan McNeill was discovered on August 19, 2024. RansomHub claimed responsibility for the breach, which resulted in the leak of approximately 30GB of data. The compromised data could potentially include sensitive financial information, posing significant risks to the firm's clients and operations. The exact method of penetration remains unclear, but it is likely that the attackers exploited vulnerabilities in the firm's cybersecurity defenses.

About RansomHub

RansomHub is a relatively new ransomware group that has quickly made a name for itself in the cyber threat landscape. Believed to have roots in Russia, RansomHub operates as a Ransomware-as-a-Service (RaaS) group, with affiliates receiving 90% of the ransom money. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, without following a specific pattern. RansomHub's ransomware strains are written in Golang, a language that is becoming increasingly popular among ransomware developers.

RansomHub distinguishes itself by making claims and backing them up with data leaks, adding credibility to their threats. The group's ability to penetrate systems and exfiltrate large amounts of data suggests a high level of sophistication and resources.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.