Solomon Agency Corp Hit by CL0P Ransomware Attack: Key Details

Incident Date:

July 25, 2024

World map

Overview

Title

Solomon Agency Corp Hit by CL0P Ransomware Attack: Key Details

Victim

Solomon Agency Corp

Attacker

Clop

Location

Bayside, USA

New York, USA

First Reported

July 25, 2024

Ransomware Attack on Solomon Agency Corp by CL0P

Overview of Solomon Agency Corp

Solomon Agency Corp, operating under the domain solomonus.com, is a prominent insurance agency based in New York. The company specializes in providing a wide array of insurance products and services tailored to meet the needs of various sectors, including business, education, healthcare, and more. They offer comprehensive business insurance solutions, including property and casualty insurance, employee benefits, workers' compensation, and cyber liability coverage. Their client-centric approach and industry-specific expertise make them a leader in the insurance sector.

Details of the Ransomware Attack

On July 25, 2024, Solomon Agency Corp fell victim to a ransomware attack orchestrated by the notorious CL0P ransomware group. The attack targeted the company's website, solomonus.com. While the exact size of the data leak remains unknown, the incident underscores the persistent threat ransomware poses to critical sectors. Solomon Agency Corp is currently assessing the full impact of the breach and working to mitigate any potential damage.

About the CL0P Ransomware Group

The CL0P ransomware group is a highly sophisticated and financially motivated cybercriminal group that has been active since early 2019. Associated with the larger TA505 threat group, CL0P operates as a ransomware-as-a-service (RaaS) model. The group typically targets large enterprises, particularly in the financial, healthcare, manufacturing, and media sectors. CL0P spreads through malicious email attachments, websites, and links, as well as by exploiting known vulnerabilities like those in Accellion FTA and "ZeroLogon". In late 2020, CL0P began operating a data leak site called "CL0P^_-LEAKS" on the Tor network to publicly release stolen data from victims who do not pay the ransom.

Potential Vulnerabilities and Penetration Methods

Solomon Agency Corp, like many organizations in the insurance sector, handles sensitive client data, making it an attractive target for ransomware groups like CL0P. The group employs advanced techniques such as digital signatures to evade security controls and has been observed using tools like Cobalt Strike, web shells, and remote access trojans. The exact method of penetration in this case is not yet confirmed, but it could involve phishing attacks, exploitation of software vulnerabilities, or compromised credentials.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.