Red Hot Cyber

Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Search

New Group Ransomware ‘Pryx’ Compromises 30,000 College Enrollment Data!

Pietro Melillo : 3 July 2024 13:34

A new player has emerged on the cybercrime landscape: the ransomware group “Pryx.” Pryx has claimed its first significant attack, announcing that it has compromised the systems of Rowan College at Burlington County (RCBC.edu) and stolen 30,000 university applications.

Incident Details

Pryx has claimed to have breached the IT systems of Rowan College and to be in possession of sensitive data from the institution. This announcement was made on their dataleak site, which is accessible both through the traditional internet and the dark web.

According to the statement from Pryx, the stolen data includes:

  • General Information:
    • NJ ReUp Program Participation
    • Legal name (first name, middle name/initial, last name, suffix)
  • Contact Information:
    • Email address, physical address, city, state, ZIP code, county
    • Cell phone number, home phone number
  • Demographic Information:
    • Date of birth, gender
    • Social Security Number (SSN)
    • Hispanic or Latino status, race
  • Citizenship and Military Affiliation:
    • US citizenship status
    • Military affiliation
  • High School Information:
    • High school graduation status, attended high school, graduation year
  • College Information:
    • Previous college/university attended, institution names
    • Entry term, program of study

Rowan College’s Reaction

As of now, Rowan College has not released any official statement regarding the incident on their website. This silence makes it difficult to precisely confirm the veracity of Pryx’s claims. Without an official response from the organization, the available information should be approached with caution.

Implications of the Breach

The amount and nature of the exposed data are extremely concerning. The personal information of students, including Social Security numbers and contact details, can be used for a variety of fraudulent and illegal activities, such as identity theft.

Pryx’s Dataleak Site

Pryx’s dataleak site is a platform where the group publishes information about victims who have not paid the demanded ransom. This site is publicly accessible on the internet and, as is common among ransomware groups, also through the dark web.

Pryx’s dataleak site features a menacing interface, dominated by the image of a spider web and the slogan “Get pryxed.” The platform includes various sections such as:

  • Contact Information
  • Public PGP Key
  • All Updates
  • Breaches and operations by Pryx

The site’s homepage invites visitors to “Get pryxed,” highlighting their intimidating and provocative approach.

Final Considerations

The emergence of Pryx and their first attack represent a further development in the growing threat posed by ransomware groups. The absence of an official statement from Rowan College underscores the need to closely monitor this situation. This article serves as an initial intelligence report, and future developments will be followed carefully to provide accurate and timely updates.

Warning

Given the still uncertain nature of the available information, it is important to treat this article as a preliminary report. Full verification of the breach’s authenticity can only occur through official confirmations from Rowan College or further evidence provided by reliable sources.

Stay tuned for more updates on this evolving story.

Our Customary Disclaimer

As is our custom, we always leave room for a statement from the company should they wish to provide updates on the matter. We will be happy to publish such information in a dedicated article, giving prominence to the issue.

RHC Dark Lab will monitor the situation closely to publish further news on the blog, should there be any substantial updates. If there are any individuals with knowledge of the facts who wish to provide information anonymously, they can use the encrypted whistleblower email.

Pietro Melillo
Head of the Dark Lab group. A Computer Engineer specialised in Cyber Security with a deep passion for Hacking and technology, currently CISO of WURTH Italia, he was responsible for Cyber Threat Intelligence & Dark Web analysis services at IBM, carries out research and teaching activities on Cyber Threat Intelligence topics at the University of Sannio, as a Ph.D, author of scientific papers and development of tools to support cybersecurity activities. Leads the CTI Team "RHC DarkLab"