Ransomware Attack on PVJOBS: BianLian Group Compromises 950GB Data

Incident Date:

July 24, 2024

World map

Overview

Title

Ransomware Attack on PVJOBS: BianLian Group Compromises 950GB Data

Victim

Playa Vista Job Opportunities and Business Services

Attacker

Bianlian

Location

Los Angeles, USA

California, USA

First Reported

July 24, 2024

Ransomware Attack on PVJOBS by BianLian Group

Overview of PVJOBS

Playa Vista Job Opportunities and Business Services (PVJOBS) is a nonprofit organization established in 1998 to provide career-track employment opportunities for at-risk youth, adults, and veterans, primarily in the construction industry. The organization was created to fulfill a mandate from the Los Angeles City Council, ensuring local residents benefit from job opportunities arising from the Playa Vista development project. PVJOBS has evolved into a national leader in job training and placement programs, partnering with over 130 community-based organizations.

Impact of the Ransomware Attack

The ransomware group BianLian has claimed responsibility for a cyberattack on PVJOBS, compromising approximately 950 GB of sensitive data. This includes financial records, human resources data, and personal identifiable information (PII) of candidates, participants, and members. The breach has also affected internal and external email correspondence, mailboxes, and data related to partners and recruitment activities. Given PVJOBS operates with a revenue of less than $5 million, the organization now faces significant challenges in securing its data and mitigating the impact of this cyberattack.

About the BianLian Ransomware Group

BianLian is a sophisticated ransomware group that has evolved from targeting individual users to launching high-profile attacks on businesses, governmental organizations, healthcare facilities, and educational institutions globally. Initially functioning as a banking trojan, BianLian transitioned into advanced ransomware operations, emphasizing extortion-based strategies. The group gained initial access through compromised Remote Desktop Protocol (RDP) credentials, implanting custom backdoors specific to each victim, and employing various tools for discovery, lateral movement, collection, exfiltration, and impact.

Penetration and Vulnerabilities

BianLian's attack on PVJOBS likely exploited vulnerabilities in the organization's cybersecurity infrastructure. The group is known for using compromised RDP credentials to gain initial access, followed by the deployment of custom backdoors and the use of PowerShell and Windows Command Shell for defense evasion. The attack underscores the importance of robust cybersecurity measures, especially for organizations handling sensitive data and operating with limited financial resources.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.