RansomHub Ransomware Hits Rational Enterprise: 2 TB Data Stolen

Incident Date:

August 8, 2024

World map

Overview

Title

RansomHub Ransomware Hits Rational Enterprise: 2 TB Data Stolen

Victim

Rational Enterprise

Attacker

Ransomhub

Location

Albany, USA

New York, USA

First Reported

August 8, 2024

RansomHub Ransomware Attack on Rational Enterprise

Rational Enterprise, a specialized provider of Information Governance and eDiscovery software, has recently fallen victim to a ransomware attack orchestrated by the RansomHub group. The attackers claim to have exfiltrated 2 TB of sensitive data and have threatened to publish it within the next few days, posing significant risks to the company's operations and client confidentiality.

About Rational Enterprise

Founded in 2006 and headquartered in New York City, Rational Enterprise offers industry-leading solutions designed for law firms and corporations. The company provides comprehensive software for managing unstructured data and streamlining the eDiscovery process. Their proprietary software includes advanced analytics and predictive coding technologies, which enhance usability for legal professionals and information specialists. Rational Enterprise is notable for being one of the few family-owned firms in the eDiscovery industry, emphasizing a reputation-driven approach.

Attack Overview

The ransomware attack on Rational Enterprise was claimed by RansomHub, a relatively new ransomware group. The group has stated that they have accessed 2 TB of sensitive organizational data and plan to release it within 3 to 4 days. This breach could severely impact Rational Enterprise's clients and operations, putting immense pressure on the company to respond swiftly and mitigate the damage.

RansomHub: The Ransomware Group

RansomHub is a new player in the ransomware landscape, believed to have roots in Russia. Operating as a Ransomware-as-a-Service (RaaS) group, RansomHub's affiliates receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, without following a specific pattern. Their ransomware strains are written in Golang, a relatively new trend in the ransomware world, which may indicate a shift towards future trends in ransomware development.

Potential Vulnerabilities

Rational Enterprise's focus on managing unstructured data and providing eDiscovery solutions makes it a prime target for ransomware groups like RansomHub. The sensitive nature of the data they handle, combined with the high stakes involved in legal and corporate compliance, increases the potential impact of such attacks. The company's commitment to data security and compliance with local regulations will be put to the test as they navigate this breach.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.