Ransomware Attack Exposes 1.3 TB of Data at Italian Law Firm Isolabella

Incident Date:

August 24, 2024

World map

Overview

Title

Ransomware Attack Exposes 1.3 TB of Data at Italian Law Firm Isolabella

Victim

Studio Legale Associato Isolabella

Attacker

Bianlian

Location

Milano, Italy

, Italy

First Reported

August 24, 2024

Ransomware Attack on Studio Legale Associato Isolabella by BianLian

Studio Legale Associato Isolabella, a prominent Italian law firm specializing in criminal law, has fallen victim to a ransomware attack by the notorious BianLian group. The firm, founded by Lodovico Isolabella in the early 1960s, is renowned for its expertise in corporate criminal law, handling complex legal issues related to corporate liability, financial crimes, and environmental law.

About Studio Legale Associato Isolabella

Based in Milan, Italy, Studio Legale Associato Isolabella employs over 25 professionals, including partners Francesco Isolabella and Luigi Isolabella. The firm has built a strong reputation for its commitment to client loyalty and independence, encapsulated in its motto, "The Client is our flag." The firm's legal professionals are highly trained and experienced, focusing on both malicious and negligent crimes, compliance matters, and internal investigations.

Attack Overview

The BianLian ransomware group claims to have exfiltrated 1.3 TB of sensitive data from Studio Legale Associato Isolabella. The compromised data includes financial records, human resources information, case files, court documents, exhibits, clients' personally identifiable information (PII), protected health information (PHI), and internal and external email correspondence. This breach poses significant risks to the firm's operations and the privacy of its clients.

About BianLian Ransomware Group

BianLian is a sophisticated ransomware group known for its evolution from a banking trojan to advanced ransomware operations. The group employs extortion-based strategies, initially gaining access through compromised Remote Desktop Protocol (RDP) credentials. BianLian uses custom backdoors, PowerShell, and Windows Command Shell for defense evasion, and various tools for discovery, lateral movement, collection, exfiltration, and impact.

Penetration and Impact

BianLian's attack on Studio Legale Associato Isolabella underscores the vulnerabilities faced by law firms handling sensitive data. The group's shift towards exfiltration-based extortion highlights the evolving threat landscape. The attack on Studio Legale Associato Isolabella not only threatens the firm's operations but also the confidentiality of its clients' information, emphasizing the need for enhanced cybersecurity measures in the legal sector.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.