Vice Society attacks Marist College Ashgrove
Incident Date:
October 24, 2022
Overview
Title
Vice Society attacks Marist College Ashgrove
Victim
Marist College Ashgrove
Attacker
Vicesociety
Location
First Reported
October 24, 2022
Vice Society Ransomware Attack on Marist College Ashgrove
The Vice Society ransomware gang has attacked Marist College Ashgrove. On August 4, 2022, an overseas-based cybercrime group gained unauthorized access to the College's IT systems, according to findings. The intrusion was carried out by an illegitimate third party. On September 19, 2022, the unauthorized party encrypted specific servers and issued a ransom note, demanding payment in exchange for decrypting the data. Despite the request, the College adhered to advice and guidance, including that provided by the Australian government, and did not yield to the demands. Immediate restoration efforts were initiated to recover the systems while enlisting the expertise of cybersecurity professionals to conduct forensic investigations.
Forensic investigations conducted by the experts revealed that a portion of the data had been extracted and subsequently made available on the dark web. This included 192 passport details, both current and expired within the past three years, as well as expired Blue Card information pertaining to several staff and volunteers, specifically from 2019. However, it should be noted that this Blue Card information cannot serve as primary identification. The investigations conducted by the experts have not uncovered any evidence indicating a compromise of financial information, bank details, human resources data, or driver's license information.
About Vice Society
Vice Society is a RaaS (Ransomware-as-a-Service) threat group that first emerged in 2021 and has used a variety of ransomware strains, including Hello Kitty/Five Hands and Zeppelin, before developing a custom ransomware strain. Tactics include attempts to compromise data backup solutions and clearing security logs on compromised systems to evade detection.
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.