Menu
Browse

Cyber Incident Victim: Stor-a-File

Date:

Aug 2021

Location:

United Kingdom

Summary

A British data storage firm suffered a ransomware attack exploiting an unpatched SolarWinds Serv-U FTP vulnerability, leading to unauthorized data access and leaks by the Clop ransomware group. The incident compromised sensitive medical records, including HIV clinic files and oncology documents processed for healthcare clients, with some information published on a Tor leak site. The company notified affected clients and authorities, refused ransom demands, and removed third-party software from its systems to prevent recurrence. Attackers leveraged CVE-2021-35211, a critical flaw patched months earlier, with security researchers noting thousands of vulnerable Serv-U instances remained exposed post-patch. Services included long-term document processing for NHS healthcare providers, though specific breach impacts were under assessment.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

The ransomware attack on Stor-a-File occurred in September 2021 after threat actors exploited an unpatched vulnerability (CVE-2021-35211) in SolarWinds' Serv-U FTP server software. Microsoft had disclosed this critical flaw in July 2021, specifically affecting Serv-U versions 15.2.3 HF1 and earlier. Stor-a-File was running one of these vulnerable versions, which the Clop ransomware gang leveraged for initial access to the company's systems. Upon discovering the breach, Stor-a-File immediately contacted the UK Information Commissioner's Office (ICO) and law enforcement authorities. The company later notified affected clients after determining their data might have been compromised. Stor-a-File publicly confirmed it refused to pay the ransom demand. Subsequent analysis by NCC Group revealed that 2,784 Serv-U instances worldwide remained publicly accessible and vulnerable three months after Microsoft's patch release, indicating widespread exposure to this attack vector.

Cyber Incident Image

The breach compromised sensitive medical records processed by Stor-a-File, including HIV test results, genitourinary clinic records, oncology files, and human resources documents. At least one medical-sector client was impacted, though Stor-a-File did not publicly identify affected organizations. Archived web records showed the company had provided document conversion services to the UK National Health Service for over 35 years, though the NHS scanning service page was removed post-incident. The Clop gang leaked some stolen data on a Tor-based blog, consistent with their double-extortion tactics previously observed in attacks such as the Bombardier breach involving FTP software exploitation. Stor-a-File responded by eliminating all third-party software from its secure systems to prevent future compromises. The incident exposed vulnerabilities in legacy document management infrastructure used by healthcare-adjacent service providers.

Sources
Sources available to members
1 source