DNSC and CECCAR warn that a ransomware campaign is currently targeting accounting firms in Romania—here's how it works and what you can do to avoid becoming the next victim.
The National Directorate for Cybersecurity (DNSC), together with the Body of Certified Public Accountants and Authorized Accountants of Romania (CECCAR), has sounded the alarm regarding an aggressive campaign of ransomware attacks targeting accounting firms and finance departments. The attackers deliberately choose this time of year—tax filing season—when inboxes are full of messages with attachments and no one is looking closely at each one anymore.
The bait is an email that appears to be sent by a trusted source—CECCAR, a colleague, or a business partner. Sometimes it claims there’s an outstanding debt, requests payment, or asks for information, and the attachment contains a file: a Word document, a PDF, or, most often, a .zip or .rar archive. The moment someone at the company opens the file, the attack takes control and begins encrypting the databases and accounting documents on the computer.
The most dangerous part is the encryption method. Attackers use BitLocker, the encryption tool that comes built right into Windows. Since it’s a legitimate operating system program, its actions don’t appear suspicious, so traditional antivirus software doesn’t trigger any alerts. By the time you realize what’s happening, your data is already locked, and the attackers demand a ransom in cryptocurrency to unlock it. They primarily target companies that appear to have the resources to pay.
The good news is that staying safe doesn’t require an expensive program—just a few simple habits. Treat any unexpected .zip or .rar file as suspicious, even if it comes from a familiar sender, and confirm by phone before opening it. Do not make payments or send data based solely on an email. Keep a backup of important documents either offline or in the cloud—a backup that’s always online will get encrypted along with the rest. And if your company has already been targeted, report the incident to the DNSC at 1911, rather than paying the ransom in silence.
For a small business without its own IT specialist, the difference between a minor incident and the loss of all its accounting records lies in this instinct not to open the suspicious file—coupled with a backup that ransomware cannot access.
Sources:
- DNSC | https://www.dnsc.ro/citeste/alerta-intensificare-atacuri-cibernetice-de-tip-ransomware-prin-utilizarea-bitlocker
- Profit.ro | https://www.profit.ro/taxe-si-consultanta/alerta-transmisa-de-dnsc-contabili-vizati-de-atacuri-cibernetice-de-tip-ransomware-22024779
This article was generated with AI assistance.