The Snatch ransomware group reported on its dark-web site the Department of the Presidency of the American War Veterans of Florida as one of its most recent victims – as Federal Authorities warn organizations to be cautious of breach indications associated with the extortionist group.

To be clear: we cannot confirm that the hackers have actually stolen the veterans' data, as they claim.
Snatch is a ransomware-as-a-service operation and its affiliates have compromised a number of critical infrastructure sectors, including defense industrial base companies, food and agriculture , and IT companies.
Just last month, hackers affiliated with the gang leaked data that was supposedly stolen earlier from Modesto during a ransomware attack against that city in California.
Data theft and double blackmail tactics are common among Snatch affiliates, we are told.
The notice also includes a list of compromise indicators that were obtained through FBI investigations between September 2022 and June 2023, so we recommend that you pay particular attention to this section of the report.
According to the advisory, Snatch affiliates use several methods to gain access and maintain persistence on victims' networks . However, the primary method of breach and infiltration involves abusing the Remote Desktop Protocol (RDP) to compromise Windows systems , force login, and obtain administrator credentials to monitor organizations' networks .
In some cases, these criminals bought stolen or leaked RDP credentials on underground marketplaces and used those login details to infiltrate covertly, as they tell us.
It is also worth noting that the FBI and CISA issued in May a similar joint warning about limiting the use of RDP in order to reduce the risk of infection from the ransomware BianLian.
Information source: theregister.com
