Ransomware Attack on Eric Rossi CPA LLC Exposes 910 GB of Data

Incident Date:

August 30, 2024

World map

Overview

Title

Ransomware Attack on Eric Rossi CPA LLC Exposes 910 GB of Data

Victim

Eric Rossi CPA LLC

Attacker

Bianlian

Location

Pittsburgh, USA

Pennsylvania, USA

First Reported

August 30, 2024

Ransomware Attack on Eric Rossi CPA LLC by BianLian Group

Eric Rossi CPA LLC, a full-service accounting firm based in Pittsburgh, Pennsylvania, has recently been targeted by the notorious ransomware group BianLian. The firm, known for its comprehensive suite of financial services tailored for business owners, executives, and independent professionals, has suffered a significant data breach.

Company Profile

Eric Rossi CPA LLC operates as a Limited Liability Company (LLC) and is licensed in Pennsylvania. Established in 2004, the firm employs between 2 to 10 individuals and reported an annual revenue of approximately $669,969. The firm specializes in tax preparation, bookkeeping, payroll services, and business consulting, making it a valuable partner for clients seeking reliable accounting and financial advisory services in the Pittsburgh area.

Attack Overview

The BianLian group has claimed responsibility for the attack, compromising approximately 910 GB of sensitive data. This data includes financial records, human resources information, incidents and case files, court and litigation documents, exhibits, and clients' personally identifiable information (PII) and protected health information (PHI). Additionally, the breach encompasses mailboxes and both internal and external email correspondence. The attack poses significant risks to the firm's operations and the privacy of its clients.

About BianLian Ransomware Group

BianLian is a sophisticated ransomware group that has evolved from targeting individual users to launching high-profile attacks on businesses and organizations globally. Initially functioning as a banking trojan, BianLian transitioned into advanced ransomware operations, emphasizing extortion-based strategies. The group gained initial access through compromised Remote Desktop Protocol (RDP) credentials and employs various tools for discovery, lateral movement, collection, exfiltration, and impact.

Penetration and Vulnerabilities

BianLian's attack on Eric Rossi CPA LLC likely involved exploiting vulnerabilities in the firm's cybersecurity infrastructure. The group's tactics include using PowerShell and Windows Command Shell for defense evasion and implanting custom backdoors specific to each victim. The firm's small size and potentially limited cybersecurity resources may have made it an attractive target for the ransomware group.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.