RansomHub Ransomware Hits McDowall Affleck: 470GB Data Stolen

Incident Date:

August 1, 2024

World map

Overview

Title

RansomHub Ransomware Hits McDowall Affleck: 470GB Data Stolen

Victim

McDowall Affleck

Attacker

Ransomhub

Location

Midland, Australia

, Australia

First Reported

August 1, 2024

RansomHub Ransomware Attack on McDowall Affleck

McDowall Affleck, a prominent engineering consultancy based in Perth, Western Australia, has confirmed a ransomware attack orchestrated by the cybercriminal group RansomHub. The attack, which was publicly announced by RansomHub on August 1, initially occurred on July 24. The attackers claimed to have encrypted the firm's network and extracted 470 gigabytes of sensitive data.

About McDowall Affleck

Established in 1978, McDowall Affleck specializes in civil, structural, and mechanical engineering. The firm is known for delivering high-quality engineering solutions across various sectors, including infrastructure, renewable energy, and land development. With a relatively small team of 11-50 employees, McDowall Affleck prides itself on personalized service and technical expertise. The company is also noted for its strong emphasis on employee development and community engagement.

Attack Overview

RansomHub claimed responsibility for the attack, stating that they had encrypted McDowall Affleck's network and stolen a significant amount of data, including blueprints, project-related documents, insurance files, contracts, and personal details of employees. The group alleged that they had contacted the company's director multiple times, threatening to publish the stolen data if a ransom was not paid. However, they did not provide concrete evidence of the breach beyond releasing contact information for key individuals within the company.

In response, McDowall Affleck confirmed the cyberattack and took immediate action to secure their systems. They brought in forensic experts to investigate the breach and assured that their systems are now secure and fully operational. The company is actively verifying the accuracy of the online claims and has communicated necessary precautions to those potentially affected. The incident has been reported to the Australian Cyber Security Centre and the Western Australia Police Force, with the firm cooperating fully with law enforcement in the ongoing investigation.

About RansomHub

RansomHub is a relatively new ransomware group believed to have roots in Russia. Operating as a Ransomware-as-a-Service (RaaS) group, RansomHub affiliates receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, without following a specific pattern. RansomHub's ransomware strains are written in Golang, a language choice that is becoming increasingly popular among ransomware developers.

The group distinguishes itself by making claims and backing them up with data leaks. In the case of McDowall Affleck, it is speculated that the attackers may have penetrated the company's systems through phishing emails or exploiting vulnerabilities in their network infrastructure.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.