Ransomware Attack on Vannguard Utility Partners by Akira

Incident Date:

May 24, 2024

World map

Overview

Title

Ransomware Attack on Vannguard Utility Partners by Akira

Victim

Vannguard Utility Partners

Attacker

Akira

Location

DeForest, USA

Wisconsin, USA

First Reported

May 24, 2024

Ransomware Attack on Vannguard Utility Partners by Akira

Victim Overview

Vannguard Utility Partners, a utility locating company operating in the Midwest, has fallen victim to a ransomware attack by the group known as Akira. The company provides services to utilities in several states and has grown significantly over the years, with a commitment to total damage prevention.

Company Profile

Vannguard Utility Partners, Inc. started with 4 employees in 2000 and has since expanded to 450 employees by 2018. The company stands out for its emphasis on quality, service, and integrity in the utility locating industry.

Attack Details

Akira claims to have accessed approximately 30GB of data from Vannguard Utility Partners, including sensitive information such as employment documents, confidential agreements, customer data, and project details. This data is set to be released on the dark web leak site.

Ransomware Group: Akira

Akira is a rapidly growing ransomware family that targets small to medium-sized businesses across various sectors. The group is known for its double extortion tactics, where they steal data before encrypting systems and demand a ransom for decryption and data deletion.

Attack Vector

Akira is believed to have penetrated Vannguard Utility Partners' systems through unauthorized access to VPNs, credential theft, and lateral movement to deploy the ransomware. The group has also been observed using tools like RClone, FileZilla, and WinSCP for data exfiltration.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.