RSH Legal Targeted: A Deep Dive into the dAn0n Ransomware Attack

Incident Date:

May 4, 2024

World map

Overview

Title

RSH Legal Targeted: A Deep Dive into the dAn0n Ransomware Attack

Victim

RSH legal

Attacker

dAn0n

Location

Cedar Rapids, USA

Iowa, USA

First Reported

May 4, 2024

Ransomware Attack on RSH Legal by dAn0n Group

Overview of the Attack

The ransomware group dAn0n has recently claimed responsibility for a significant cyber attack on RSH Legal, a law firm based in Iowa. The attack resulted in the theft of approximately 6 TB of sensitive data, including financial records, employee information, client personal data, medical records, and legal documents. This breach was publicly disclosed on dAn0n's dark web leak site, marking a severe security incident for RSH Legal.

Victim Profile

RSH Legal, established in 1988, is a medium-sized law firm known for its strong advocacy in personal injury, disability, and employment law. Located at 425 2nd St. SE Suite 1140, Cedar Rapids, Iowa, the firm has built a reputation for its commitment to justice and fairness, particularly in supporting underprivileged communities. The firm operates in the Law Firms & Legal Services industry, generating approximately $5.6M in revenue.

dAn0n Ransomware Group Profile

dAn0n is a relatively new player in the ransomware landscape, having first appeared with multiple data leaks in April. The group is known for its aggressive targeting and rapid publication of stolen data on its dark web platforms. The attack on RSH Legal is part of a broader pattern of targeting vulnerable systems in high-value sectors such as legal services.

Potential Vulnerabilities and Attack Vectors

The exact method of penetration by dAn0n into RSH Legal's network has not been disclosed. However, common vulnerabilities in similar cases include phishing attacks, exploitation of unpatched software, or compromised credentials. Law firms like RSH Legal are attractive targets due to the sensitive nature of the data they handle, which includes personal, medical, and financial information.

Implications of the Attack

The breach poses significant risks not only to the privacy of RSH Legal's clients but also to the firm's operational integrity. The exposure of sensitive client data can lead to legal repercussions and damage to the firm's reputation. Furthermore, the leak of internal documents and financial information could have long-term financial implications for RSH Legal.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.