Ransomware Attack on Findel Educational Resources Exposes 870 GB of Data

Incident Date:

August 21, 2024

World map

Overview

Title

Ransomware Attack on Findel Educational Resources Exposes 870 GB of Data

Victim

Findel Educational Resources

Attacker

Cicada 3301

Location

Hyde, United Kingdom

, United Kingdom

First Reported

August 21, 2024

Ransomware Attack on Findel Educational Resources by Cicada3301

About Findel Educational Resources

Findel Educational Resources, headquartered in Hyde, Cheshire, is a well-established company in the educational sector, operating since 1817. The company employs around 300 people and serves educational institutions in over 130 countries. Findel's portfolio includes several specialized brands such as Hope, GLS, Davies Sports, Philip Harris, and LDA, each catering to different educational needs. This extensive range allows Findel to offer over 32,000 products, making it a comprehensive provider of educational supplies.

What Makes Findel Stand Out

Findel is recognized for its commitment to supporting educators and enhancing learning experiences through a diverse range of high-quality products and services. The company's brands focus on various aspects of education, from primary and secondary education resources to sports equipment and science laboratory supplies. Findel's dedication to inclusivity is evident through its LDA brand, which provides resources tailored for Special Educational Needs (SEN).

Vulnerabilities and Targeting by Threat Actors

Despite its strong market position, Findel's extensive digital operations and global reach make it a lucrative target for cybercriminals. The company's reliance on eCommerce platforms and the handling of vast amounts of sensitive data, including customer information and financial records, present significant vulnerabilities. These factors likely contributed to Findel being targeted by Cicada3301.

Attack Overview

The ransomware attack by Cicada3301 resulted in the exfiltration of approximately 870 GB of sensitive data from Findel's systems. The compromised information includes passports, financial data, confidential documents, and the customer database. This breach poses significant risks to both the company and its clients, potentially leading to identity theft, financial loss, and reputational damage.

About Cicada3301

Cicada3301 is a new threat actor group that emerged in June 2024. Unlike traditional ransomware groups, Cicada3301 operates as a data broker, focusing on stealing sensitive data and selling it on dark web marketplaces. This approach signifies a shift from conventional ransomware tactics to more sustained and long-term damage strategies. Cicada3301's operations involve data theft and exfiltration, use of leak sites to pressure victims, and long-term exploitation of stolen data.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.