For Business

Investigating data breach and ransomware attack on a professional services firm with multiple contractors

A professional services firm with a high number of contractors faced a ransomware attack on their cloud virtual servers, with criminals encrypting their files and demanding money. Notion Digital Forensics was called in by the firm’s new IT Managed Service Provider (MSP) to investigate the breach, determine if any data was taken, assess the extent of the damage, and identify the potential cause of the breach.

Objectives

Determine the extent of the data breach, confirm if files were exfiltrated by the criminals, and identify whether the breach was caused by a contractor, the previous MSP, or unimplemented security protocols due to the client’s new status with the current MSP.

Approach

Results

Conclusion

Notion Digital Forensics successfully investigated the ransomware attack and data breach on the professional services firm’s cloud virtual servers. Through the use of advanced forensic techniques, Notion was able to confirm that files were indeed exfiltrated by the criminals and identify the potential cause of the breach. This information proved valuable for both the professional services firm and their new MSP in meeting legal obligations, taking appropriate actions, and planning remediation efforts.