AvidXchange hit by a second major ransomware attack this year

Ransomware attack on a computer
(Image credit: Kaspersky)

AvidXchange has suffered its second major ransomware attack of 2023 after hackers published a sample of the stolen data on their website and demanded a ransom be paid as soon as possible. 

The payment software company was attacked by a ransomware group calling itself RansomHouse, which has since leaked super sensitive information that can easily be used to commit acts of fraud and requiring the best identity theft protection to combat.

The data stolen includes non-disclosure agreements, employee payroll information, as well as corporate bank account numbers, the publication says, after analyzing a small sample. Other data stolen includes system login details, and answers to security questions for things such as cloud accounts and security software (smart door locks, surveillance cameras, and more). Analysis of this information showed that employees were using weak and easily guessable passwords, such as a derivation of the AvidXchange name together with the word “password”. 

Investigation ongoing

In fact, it would seem that some of the passwords are yet to be changed. 

In response to the leak, the company published a short statement on its website, saying it happened in early April, that it affected “some” of its systems, and that “some data”, was stolen. It further added that the investigation is ongoing. 

On Monday, the company held a first-quarter earnings call, TechCrunch added, during which it said it expected more costs due to the attack. Spokesperson Olivia Sorrellis, however, did not want to say if AvidXchange got a ransom demand, or if it paid it. 

AvidXchange is a cloud-based payments software provider, helping businesses automate invoicing and payment management. 

It is located in North Carolina, and in 2020 counted 1,500 employees and more than 7,000 customers, as per its website. It processed roughly 53 million transactions with more than $145 billion in spend under management in 2020 alone, and paid more than 700,000 suppliers in five years. 

Via: TechCrunch

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
security
Ransomware gangs allegedly hit two major US healthcare firms, 300,000 patients have data stolen
Data leak
US utility giant says MOVEit hack exposed stolen data
A person with a laptop using a credit card online.
Avery label maker confirms attack on its site, customer credit card info stolen
Security
American National Insurance Company breach data found online
Lock on Laptop Screen
United Healthcare data breach may have affected 190 million Americans
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
More reports claim 2024 was the worst year for ransomware attacks yet
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)