Ransomware Breach at Bogdan & Frasco by Cicada 3301

Incident Date:

September 24, 2024

World map

Overview

Title

Ransomware Breach at Bogdan & Frasco by Cicada 3301

Victim

Bogdan Frasco, LLP

Attacker

Cicada 3301

Location

San Francisco, USA

California, USA

First Reported

September 24, 2024

Ransomware Attack on Bogdan & Frasco, LLP by Cicada 3301

Bogdan & Frasco, LLP, a reputable accounting and tax firm based in San Francisco, has become the latest victim of a ransomware attack by the notorious group Cicada 3301. The firm, known for its personalized service and expertise in financial management, primarily serves small and medium-sized businesses and individual clients. Established in 1995, Bogdan & Frasco has built a strong reputation in the competitive San Francisco market.

Company Profile and Vulnerabilities

With approximately seven employees and an annual revenue of around $3 million, Bogdan & Frasco operates from the heart of San Francisco's financial district. The firm's focus on personalized service and responsiveness to client needs distinguishes it within the industry. However, its relatively small size and the nature of its operations may have made it an attractive target for threat actors like Cicada 3301, who often exploit vulnerabilities in small to medium-sized businesses.

Attack Overview

The ransomware attack resulted in the compromise of 338 GB of sensitive data, which was subsequently published on a dark web site on September 15. This breach poses significant risks to the firm's reputation and client trust, as the stolen data is now available for download. The attack highlights the growing threat of ransomware groups targeting businesses with valuable data, particularly those with potentially weaker cybersecurity defenses.

About Cicada 3301

Cicada 3301, a newly emerged Ransomware-as-a-Service and data broker group, first gained attention in mid-2024. Unlike traditional ransomware groups, Cicada 3301 focuses on exfiltrating and selling sensitive data rather than seeking quick ransom payments. Their operations involve a double-extortion model, threatening to release stolen data if demands are not met. The group is known for its sophisticated tactics, including the use of the Brutus botnet for initial access and PsExec for lateral movement.

Penetration and Distinctive Tactics

The attack on Bogdan & Frasco likely involved phishing campaigns or brute-forcing VPN credentials, common methods employed by Cicada 3301. Their use of advanced encryption techniques, such as ChaCha20, and the ability to delay encryption to evade detection, sets them apart from other ransomware groups. The group's focus on data brokerage and extortion, rather than immediate ransom demands, underscores their unique approach to cybercrime.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.