31 May 2023

Lawtech platform Casepoint reportedly hit with BlackCat ransomware


Lawtech platform Casepoint reportedly hit with BlackCat ransomware

Casepoint, a legal technology platform used by multiple US government entities, has been added to a list of victims on a dark web data leak website run by Russia-linked ransomware cartel BlackCat (aka ALPHV).

Casepoint is a cloud-based legal discovery platform used by corporations, law firms, and government organizations. The company works with many high-profile clients such as the US Securities and Exchange Commission (SEC), the Department of Defence (DoD), the US National Credit Union Administration (NCUA), hotel operator Marriott, German industrial giant ThyssenKrupp, academic medical center Mayo Clinic, railway operator BNSF Railway, and others.

The group claims to have stolen 2TB of sensitive data from Casepoint. As proof the cybercrooks posted some samples of allegedly stolen information, including what appears to be visa details, a report and a certificate.

The BlackCat ransomware operation first debuted in November 2021 and since then has consistently been listed among the top ten most active ransomware groups. BlackCat was linked to now-defunct BlackMatter/DarkSide ransomware. In 2022, BlackCat affiliates were linked to attempted extortion of entities globally across multiple sectors including education, government, and energy.

In March 2023, the BlackCat group stole sensitive data from data storage devices maker Western Digital and then mocked the company by leaking a series of screenshots of internal emails and video conferences indicating they still had access to WD’s systems while it was dealing with the hack.


Back to the list

Latest Posts

US authorities charge two Russians with 2011 Mt. Gox hack

US authorities charge two Russians with 2011 Mt. Gox hack

Bilyuchenko and Verner allegedly stole about 647,000 bitcoins from Mt. Gox between September 2011 through at least May 2014.
12 June 2023
Pro-Ukraine hackers take down Russian telco, disrupt banking operations

Pro-Ukraine hackers take down Russian telco, disrupt banking operations

The breach at Infotel is said to have impacted multiple major banks across Russia who were unable to make online payments for more than a day.
12 June 2023
Cyber security week in review: June 9, 2023

Cyber security week in review: June 9, 2023

The world in brief: Clop likely has been exploiting the MOVEit 0Day since 2021, over $35M in crypto stolen in the Atomic Wallet hack, and more.
9 June 2023