HomeSecurityArtech: IT staffing company suffered a data breach due to ransomware attack

Artech: IT staffing company suffered a data breach due to ransomware attack

Artech Information Systems, one of the largest IT staffing companies in the US, has revealed that it suffered a data breach, which was caused by a ransomware attack that affected some of systems earlier this year. The privately held company had estimated annual revenue of $810 million in 2019 and approximately 11,000 employees and consultants in 40 states in the US, Canada, China and India.

Artech

Artech provides personnel and workforce solutions, program management and government services, with a client list that includes more than 80 Fortune 500as well as U.S. federal entities.
The company discovered the ransomware attack after it found ransomware on some of its systems after noticing reports of unusual activity related to one of its employee accounts.

A data breach notification letter to affected individuals states that on the same day, Artech hired a leading forensics firm to assess the security of its systems and confirm the nature and scope of the security incident. In mid-January, the investigation determined that someone gained unauthorized access to Artech systems between January 5, 2020, and January 8, 2020.

data breach

BleepingComputer learned of the attack on Artech’s servers on January 11, 2020 , when the Revil/Sodinokibi ransomware gang leaked 337MB of the files it claimed to have stolen from the company’s servers, noting that this was only a small portion of what was stolen. Furthermore, the Revil operators threatened that if the company did not take necessary action, they would sell the rest of the data they had collected. The data included commercial, financial, and personal information.

An email shared with BleepingComputer by an Artech employee states that the company had to shut down all of its systems, but was able to restore critical services and servers from backup data.

ransomware attack-ransomware

REvil is a ransomware-as-a-service (RaaS) enterprise that compromises corporate networks via exposed remote desktop services, as well as service provider administrators, using exploits and spam emails. Once they gain access to a victim’s network, REvil operators steal sensitive and confidential data to later use as a “weapon” to convince their victims to pay a ransom to prevent the stolen information from being leaked. Furthermore, once they gain administrative access to a domain and steal data from servers and workstations, REvil operators deploy ransomware payloads to all computers on the compromised network.

Artech discovered personal, health, and financial information of multiple individuals stored on the compromised systems. Around June 25, 2020 , when the company completed its investigation into the alleged attack, it was able to identify the individuals whose information was exposed in the data breach. This information is estimated to include the following: names, social security numbers, medical information, health insurance information, financial information, credit card information, driver’s license/ID numbers, passport numbers, visa numbers, digital signatures, usernames, and passwords. However, it is worth noting that the combination of exposed information varies for each affected individual.

REvil/Sodinokibi ransomware

After discovering the attack, Artech changed its credentials to secure its systems, while also beginning to work with external security experts to improve its existing security procedures and protocols.

Finally, Artech recommends that affected individuals who received notification of the data breach monitor their account statements for suspicious activity and be constantly vigilant for any incidents of fraud or attempted identity theft. The company also provides them with free card monitoring and identity protection services through Kroll.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS