Ransomware Attack on Oseran Hahn P.S. by LockBit 3.0

Incident Date:

May 16, 2024

World map

Overview

Title

Ransomware Attack on Oseran Hahn P.S. by LockBit 3.0

Victim

Oseran Hahn P.S.

Attacker

Lockbit3

Location

Bellevue, USA

Washington, USA

First Reported

May 16, 2024

Ransomware Attack on Oseran Hahn P.S. by LockBit 3.0

Victim Overview

Oseran Hahn P.S. is a law firm based in Bellevue, Washington, founded in 1965 by Melville Oseran and Jerry Hahn. The firm is known for its diverse legal services, including major real estate transactions, corporate mergers and acquisitions, complex litigation matters, estate planning, and personal injury claims. They emphasize excellence, integrity, efficiency, and productivity in their operations. According to LinkedIn, Oseran Hahn P.S. has between 11 and 50 employees. The firm is recognized for being "deal makers" in the legal industry, focusing on facilitating successful transactions and resolving complex legal matters for their clients.

Attack Overview

The company fell victim to a ransomware attack orchestrated by the cybercrime group LockBit 3.0. The attack targeted the firm's website, compromising their online presence and potentially sensitive information. LockBit 3.0, also known as LockBit Black, is a highly sophisticated Ransomware-as-a-Service (RaaS) group that has evolved from previous versions of LockBit. The group is notorious for its advanced encryption techniques, obfuscation methods, and lateral movement capabilities within compromised networks.

Vulnerabilities and Penetration

Oseran Hahn P.S. may have been targeted by LockBit 3.0 due to the sensitive nature of the legal information they handle. Law firms are often prime targets for ransomware attacks due to the confidential data they possess, making them lucrative targets for threat actors. The ransomware group likely exploited vulnerabilities in the firm's cybersecurity defenses to gain unauthorized access to their systems and deploy the ransomware.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.