Vice Society attacks Marist College Ashgrove

Incident Date:

October 24, 2022

World map

Overview

Title

Vice Society attacks Marist College Ashgrove

Victim

Marist College Ashgrove

Attacker

Vicesociety

Location

Brisbane, Australia

, Australia

First Reported

October 24, 2022

Vice Society Ransomware Attack on Marist College Ashgrove

The Vice Society ransomware gang has attacked Marist College Ashgrove. On August 4, 2022, an overseas-based cybercrime group gained unauthorized access to the College's IT systems, according to findings. The intrusion was carried out by an illegitimate third party. On September 19, 2022, the unauthorized party encrypted specific servers and issued a ransom note, demanding payment in exchange for decrypting the data. Despite the request, the College adhered to advice and guidance, including that provided by the Australian government, and did not yield to the demands. Immediate restoration efforts were initiated to recover the systems while enlisting the expertise of cybersecurity professionals to conduct forensic investigations.

Forensic investigations conducted by the experts revealed that a portion of the data had been extracted and subsequently made available on the dark web. This included 192 passport details, both current and expired within the past three years, as well as expired Blue Card information pertaining to several staff and volunteers, specifically from 2019. However, it should be noted that this Blue Card information cannot serve as primary identification. The investigations conducted by the experts have not uncovered any evidence indicating a compromise of financial information, bank details, human resources data, or driver's license information.

About Vice Society

Vice Society is a RaaS (Ransomware-as-a-Service) threat group that first emerged in 2021 and has used a variety of ransomware strains, including Hello Kitty/Five Hands and Zeppelin, before developing a custom ransomware strain. Tactics include attempts to compromise data backup solutions and clearing security logs on compromised systems to evade detection.

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.