TPA Slovakia Group Under Siege: The Devastating Impact of the Underground Team's Ransomware Attack
Incident Date:
May 4, 2024
Overview
Title
TPA Slovakia Group Under Siege: The Devastating Impact of the Underground Team's Ransomware Attack
Victim
TPA Slovakia Group
Attacker
Underground Team
Location
First Reported
May 4, 2024
Analysis of the Ransomware Attack on TPA Slovakia by Underground Team
Company Profile: TPA Slovakia Group
TPA Slovakia, a significant entity within the TPA Group, specializes in audit, tax advisory, and business consulting primarily in Slovakia. Operating from Bratislava and Košice, the company employs over 100 staff. As part of the larger TPA Group, which boasts more than 1,500 employees across Central and South Eastern Europe, TPA Slovakia stands out for its effective communication, tailored solutions, and a strong focus on client success. The group's affiliation with the Baker Tilly Europe Alliance enhances its global reach and expertise in tax, audit, and consulting services.
Details of the Ransomware Attack
The Underground Team ransomware group has claimed responsibility for a severe attack on TPA Slovakia. This incident involved the deployment of a sophisticated ransomware strain, leading to the exfiltration of approximately 183.3 GB of sensitive data. The compromised data includes email communications, confidential agreements, accounting and tax reports, audit documents, financial records, and personal identification documents of clients. This breach has not only jeopardized the privacy of TPA Slovakia's clients but also exposed critical business information.
Ransomware Group Profile
The cybercriminal group, Underground Team, utilizes a 64-bit GUI based ransomware application, known for its capability to delete backups, modify registry settings, and halt critical services like MSSQLSERVER. This group's ransomware can identify system volumes, encrypt files while avoiding certain directories and file types, and disseminate a ransom note across multiple system folders. The primary infection vectors include phishing and other social engineering tactics, often involving deceptive emails and compromised website links.
Vulnerabilities and Attack Vectors
TPA Slovakia's vulnerabilities could stem from several areas, including but not limited to, insufficient employee training on phishing, inadequate endpoint protection, or gaps in network security. Given the nature of the data handled by TPA Slovakia, the firm is a high-value target for cybercriminals looking to exploit sensitive financial and personal information for monetary gain.
Sources
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.