Ransomware Hits Howard CPAs ElDorado Breach Exposes Data

Incident Date:

October 1, 2024

World map

Overview

Title

Ransomware Hits Howard CPAs ElDorado Breach Exposes Data

Victim

Howard CPAs

Attacker

ElDorado

Location

Lake Mary, USA

Florida, USA

First Reported

October 1, 2024

Ransomware Attack on Howard CPAs: A Closer Look at the ElDorado Breach

Howard CPAs, a prominent accounting firm based in Florida, has recently fallen victim to a ransomware attack orchestrated by the ElDorado group. Known for its comprehensive suite of accounting services, Howard CPAs serves small to mid-sized businesses, offering accounting, bookkeeping, payroll management, tax preparation, and business consulting. The firm operates under various names, including Howard, Howard and Hodges, and Howard CPA, LLC, and is recognized for its client-centric approach and professional affiliations.

Company Profile and Vulnerabilities

Howard CPAs has established itself as a standout in the accounting sector, emphasizing personalized service and building valuable relationships with clients across diverse industries. Despite its strong market presence, the firm’s handling of sensitive financial data makes it an attractive target for cybercriminals. The attack underscores the vulnerabilities inherent in professional service firms that manage large volumes of confidential information.

Attack Overview

The ransomware group ElDorado, which emerged in early 2024, has claimed responsibility for the attack on Howard CPAs. The group operates as a Ransomware-as-a-Service (RaaS) platform, utilizing advanced techniques to infiltrate and encrypt data. ElDorado's malware, written in Golang, targets both Windows and Linux systems, including VMware ESXi. The attack on Howard CPAs involved the encryption of files, potentially compromising sensitive client data and financial records.

ElDorado Ransomware Group

ElDorado distinguishes itself through its cross-platform capabilities and sophisticated encryption methods. The group uses ChaCha20 for file encryption and RSA-OAEP for key encryption, making it a formidable threat. ElDorado's recruitment of affiliates and pentesters on dark web forums further enhances its operational reach. The group’s ability to customize attack parameters allows for tailored assaults on specific targets, increasing the likelihood of successful breaches.

Potential Penetration Methods

While specific details of the breach remain undisclosed, ElDorado likely exploited vulnerabilities in Howard CPAs' network infrastructure. The ransomware's ability to encrypt files on shared networks using the SMB protocol and its tactic of removing shadow volume copies on Windows systems suggest a well-coordinated attack. The firm's reliance on digital systems for managing client data may have provided an entry point for the cybercriminals.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.