The Tech Interactive Falls Victim to 8Base Ransomware

Incident Date:

April 22, 2024

World map

Overview

Title

The Tech Interactive Falls Victim to 8Base Ransomware

Victim

The Tech Interactive

Attacker

8base

Location

San Jose, USA

, USA

First Reported

April 22, 2024

Ransomware Attack on The Tech Interactive by 8Base Group

Attack Overview

The Tech Interactive, a prominent non-profit science and technology museum based in San Jose, California, has recently fallen victim to a ransomware attack orchestrated by the cybercriminal group known as 8Base. The attack was first disclosed through 8Base's dark web leak site, where they claimed responsibility and threatened to release stolen data unless a ransom was paid. The stolen data includes a variety of sensitive information such as personal data, employment contracts, and confidential agreements.

Victim Profile

The non-profit organization is renowned for its hands-on science and technology exhibits and educational programs. Founded in 1983, it has been a pivotal institution in promoting STEM education through interactive exhibitions and initiatives like The Tech Challenge and The Tech Academies of Innovation. The organization is currently engaged in a $100 million capital campaign aimed at expanding its offerings and reach over the next decade.

Despite its significant role in the educational sector, The Tech Interactive's reliance on technology and digital platforms for educational and operational purposes makes it a potential target for cyber threats, including ransomware attacks.

Ransomware Group Profile

The 8Base group, active since April 2022, is notorious for its aggressive ransomware campaigns targeting small to medium-sized businesses across various sectors. They employ double-extortion tactics, threatening to leak stolen data if their ransom demands are not met. The group is known to use the Phobos ransomware variant, marked by the ".8base" file extension on encrypted data.

Implications and Industry Vulnerabilities

The attack on The Tech Interactive highlights a growing trend of ransomware attacks on non-profit organizations, which often lack the robust cybersecurity measures that larger corporations might implement. These entities are attractive targets due to their handling of large amounts of sensitive data and their typically limited resources for cybersecurity, making them less able to recover from such attacks without significant impact.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.