TPA Slovakia Group Under Siege: The Devastating Impact of the Underground Team's Ransomware Attack

Incident Date:

May 4, 2024

World map

Overview

Title

TPA Slovakia Group Under Siege: The Devastating Impact of the Underground Team's Ransomware Attack

Victim

TPA Slovakia Group

Attacker

Underground Team

Location

Stare Mesto, Slovakia

, Slovakia

First Reported

May 4, 2024

Analysis of the Ransomware Attack on TPA Slovakia by Underground Team

Company Profile: TPA Slovakia Group

TPA Slovakia, a significant entity within the TPA Group, specializes in audit, tax advisory, and business consulting primarily in Slovakia. Operating from Bratislava and Košice, the company employs over 100 staff. As part of the larger TPA Group, which boasts more than 1,500 employees across Central and South Eastern Europe, TPA Slovakia stands out for its effective communication, tailored solutions, and a strong focus on client success. The group's affiliation with the Baker Tilly Europe Alliance enhances its global reach and expertise in tax, audit, and consulting services.

Details of the Ransomware Attack

The Underground Team ransomware group has claimed responsibility for a severe attack on TPA Slovakia. This incident involved the deployment of a sophisticated ransomware strain, leading to the exfiltration of approximately 183.3 GB of sensitive data. The compromised data includes email communications, confidential agreements, accounting and tax reports, audit documents, financial records, and personal identification documents of clients. This breach has not only jeopardized the privacy of TPA Slovakia's clients but also exposed critical business information.

Ransomware Group Profile

The cybercriminal group, Underground Team, utilizes a 64-bit GUI based ransomware application, known for its capability to delete backups, modify registry settings, and halt critical services like MSSQLSERVER. This group's ransomware can identify system volumes, encrypt files while avoiding certain directories and file types, and disseminate a ransom note across multiple system folders. The primary infection vectors include phishing and other social engineering tactics, often involving deceptive emails and compromised website links.

Vulnerabilities and Attack Vectors

TPA Slovakia's vulnerabilities could stem from several areas, including but not limited to, insufficient employee training on phishing, inadequate endpoint protection, or gaps in network security. Given the nature of the data handled by TPA Slovakia, the firm is a high-value target for cybercriminals looking to exploit sensitive financial and personal information for monetary gain.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.