Ransomware Attack on Vannguard Utility Partners by Akira
Incident Date:
May 24, 2024
Overview
Title
Ransomware Attack on Vannguard Utility Partners by Akira
Victim
Vannguard Utility Partners
Attacker
Akira
Location
First Reported
May 24, 2024
Ransomware Attack on Vannguard Utility Partners by Akira
Victim Overview
Vannguard Utility Partners, a utility locating company operating in the Midwest, has fallen victim to a ransomware attack by the group known as Akira. The company provides services to utilities in several states and has grown significantly over the years, with a commitment to total damage prevention.
Company Profile
Vannguard Utility Partners, Inc. started with 4 employees in 2000 and has since expanded to 450 employees by 2018. The company stands out for its emphasis on quality, service, and integrity in the utility locating industry.
Attack Details
Akira claims to have accessed approximately 30GB of data from Vannguard Utility Partners, including sensitive information such as employment documents, confidential agreements, customer data, and project details. This data is set to be released on the dark web leak site.
Ransomware Group: Akira
Akira is a rapidly growing ransomware family that targets small to medium-sized businesses across various sectors. The group is known for its double extortion tactics, where they steal data before encrypting systems and demand a ransom for decryption and data deletion.
Attack Vector
Akira is believed to have penetrated Vannguard Utility Partners' systems through unauthorized access to VPNs, credential theft, and lateral movement to deploy the ransomware. The group has also been observed using tools like RClone, FileZilla, and WinSCP for data exfiltration.
Sources:
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.