AvidXchange hit by RansomHouse in its second ransomware incident of 2023
- Organization
- AvidXchange
- Exploit
- Ransomware
- Industry
- Financial Technology
AvidXchange, a North Carolina company that sells accounts payable and payment automation software, disclosed an incident in early May 2023 that TechCrunch reported as its second ransomware attack of the year. The RansomHouse group claimed responsibility and published stolen files on its dark web leak site.
A company spokesperson said the incident affected some of its systems and data, and that AvidXchange detected data exfiltration in early April. The company declined to say whether a ransom had been demanded or paid, and did not give a figure for how many customers or employees were affected.
According to TechCrunch, which reviewed the published material, the leak included non-disclosure agreements, employee payroll information and corporate bank account numbers. It also contained large numbers of account credentials: usernames, passwords and in some cases answers to security questions, covering cloud accounts, security software, smart door locks and surveillance cameras. Reporters noted that many of the passwords were weak, built from variants of the company name and the word password, and that some appeared to still be in use.
The incident followed an earlier 2023 compromise in which AvidXchange was among the organizations caught up in the mass exploitation of Fortra's GoAnywhere managed file transfer software, a campaign claimed by the Clop ransomware gang.