Jefferson County Clerk's Office Hit by RansomHub Ransomware Attack
RansomHub Ransomware Attack on Jefferson County Clerk's Office
The Jefferson County Clerk's Office, a pivotal institution in Jefferson County, Kentucky, has recently been targeted by the ransomware group RansomHub. This attack has caused significant disruptions, affecting multiple County Clerk locations and leading to the temporary closure of eight branches across Louisville.
About the Jefferson County Clerk's Office
Led by Clerk Bobbie Holsclaw, the Jefferson County Clerk's Office is a state constitutional office responsible for managing a variety of public records and services. The office handles approximately 700,000 vehicle registrations annually, issues marriage licenses, notary commissions, and manages delinquent real estate taxes. Additionally, it oversees the electoral process, ensuring fair and transparent elections. The office employs a dedicated team, although specific employee numbers are not publicly detailed.
Attack Overview
The ransomware attack by RansomHub has led to significant system outages since Monday evening. The attack has necessitated the temporary closure of eight branches, causing delays for residents seeking services such as vehicle registrations, housing deeds, and marriage and notary licenses. Despite the disruption, officials have confirmed that no personal information was compromised, thanks to the office's use of dedicated servers for storing sensitive data. The recovery process has been slow, requiring each of the more than 300 computers to be individually checked and restored to ensure security.
About RansomHub
RansomHub is a relatively new ransomware group believed to have roots in Russia. Operating as a Ransomware-as-a-Service (RaaS) group, RansomHub distinguishes itself by making claims and backing them up with data leaks. Affiliates receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, with healthcare-related institutions being notable victims. RansomHub's ransomware strains are written in Golang, a trend in the ransomware world.
Potential Vulnerabilities
The Jefferson County Clerk's Office, like many government institutions, handles a vast amount of sensitive data and relies heavily on its IT infrastructure. This makes it a prime target for ransomware groups like RansomHub. The attack likely penetrated the office's systems through vulnerabilities in their network security, possibly exploiting outdated software or insufficiently trained staff on cybersecurity practices.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!