DisclosureLens
GLOBALUnknownRansomwareCubaLow

Rock County, Wisconsin

bd_e45cf3980eb47af6 · schema v1 · pii pii-v1

Severity

Low

Discovered

Filed

Sep 29, 2023

To disclose

Affected

Not disclosed

Linked

2 filings

Confidence

60%
Full breach record for Rock County, Wisconsin

Press / market disclosure — not a breach-notification filing

A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.

Cybersecurity attack steals Rock County Human Services info. Rock County: Personal and sensitive information of employees and clients was stolen in a ransomware cyberattack against the Rock County Department of Human Services, following an email phishing campaign. The attack, which took place between September 22 and September 30, was claimed by the Cuba ransomware gang, unrelated to the country, and resulted in a $1.9 million ransom demand, which was not paid. Affected victims will receive a mail notice with instructions and an offer of free credit monitoring, although no fraud or identity theft has been reported following the incident. Linked ransomware group: cuba.

Incident timeline — mostly unverified

? — ?

Breach window unknown

Sep 29, 2023

Press report

Corroborated · see linked filings

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Attack → press

Compliance clock

Not assessable

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market reportThis record

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • incident type + narrative only (may be machine-translated)
  • discovery date
  • materiality
  • affected count
  • data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.

About this groupFirst seen 2021-02-03

cuba

According to ransomware.live, The Cuba Ransomware, also known as Colddraw Ransomware, was first identified in the threat landscape in 2019 and built a relatively small but selected list of victims. The group is also known as Fidel Ransomware, due to a characteristic marker placed at the beginning of all encrypted files. This file marker is used as an indicator for the ransomware and its decoder that the file has been encrypted. Despite its name and the Cuban nationalist style on its leak site, it is difficult to assert any connection or affiliation with the Republic of Cuba. The group has been linked to a Russian-language threat actor by Profero researchers due to some details of incorrect translation they discovered, as well as the discovery of a 404 page containing text in Russian on the threat actor's own leak site. According to BlackBerry, based on the analysis of the code strings used in the campaign analyzed in 2023, there were indications that the developer behind the Cuba ransomware speaks Russian. The ransomware operators use a double extortion approach, and following the USA, in August 2022, it was believed that the Cuba ransomware group had compromised 101 entities, demanding $145 million in ransom payments and receiving up to $60 million. The group used a similar set of TTPs, with only a slight change each year, as they generally consist of LOLBins (executables that are part of the operating system and can be exploited to support an attack), exploits, off-the-shelf and custom malware, as well as intrusion tools like Cobalt Strike and Metasploit. In 2022, the group allegedly developed a relationship with operators of the Industrial Spy market, using their platform as a means of data leakage. Source: https://github.com/crocodyli/ThreatActors-TTPs

103 victims claimed globally103 tracked hereFull profile →