ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

BHI Energy says Akira ransomware group stole 700 GB of data, encrypted internal systems

Massachusetts-based energy industrial services provider BHI Energy said that the notorious Akira ransomware group infiltrated its network and stole around 700 gigabytes of data in June this year.Based in Weymouth, Massachusetts, BHI Energy provides staffing solutions and other services to companies in the oil & gas, power generation, and transmission & distribution industries. Operating since 1979, the company presently has more than 8,500 experienced project management and technical, professional and craft personnel operating at over 130 global project locations.In a filing with the Office of the Maine Attorney General, BHI said that on 29th June, its IT team identified unauthorised access to certain systems hosted in the BHI network and the company immediately launched an internal investigation to understand the nature and scope of the security incident and took steps to remove the unauthorised access.“After a thorough investigation, on September 1, 2023, BHI learned that certain BHI business records stored in BHI’s network, including some records that contained personally identifiable information (“PII”), were subject to unauthorised access,” the company said in its data breach notice.The compromised information includes BHI’s users’ names, addresses, dates of birth, Social Security numbers, and health information. The filing with the regulator also confirms that at least 91,269 individuals have been affected by the data breach.On 4th October, BHI identified the individuals whose personal information was compromised as a result of the cyber security event and started informing them about the breach. Also, the company notified relevant law enforcement authorities and is working with them to resolve the incident.In a recent filing with the Office of the Attorney General of Iowa, BHI Energy confirmed that the incident was the work of the infamous Akira ransomware gang that infiltrated its systems on 30th May by using a previously-compromised user account of a third-party contractor.“Using that third-party contractor’s account, the TA [threat actor] reached the internal BHI network through a VPN connection. In the week following initial access, the TA used the same compromised account to perform reconnaissance of the internal network,” BHI said. On June 16, 2023, the TA returned to the network and performed further data reconnaissance, and on June 18, 2023, began staging data.”The company added that between June 20 and June 29, the ransomware group exfiltrated 690 gigabytes of data, including a copy of BHI’s Active Directory database. After the group finished exfiltrating data on June 29, it deployed malware to a subset of systems within BHI’s network and ultimately encrypted the desired systems.“The TA provided a file listing that referenced 767,035 files exfiltrated, totalling 690GB of uncompressed data. The TA created and subsequently deleted these archives on a BHI server,” it added.BHI Energy confirmed that it worked with experts from a third party cyber security firm to resolve the security incident and ultimately removed the malware from its network and decrypted the files without a decryption tool from the Akira ransomware group.BHI Energy has urged all impacted individuals to remain vigilant, review their financial statements on a regular basis and report any discrepancy to relevant authorities. Additionally, individuals can place a fraud alert or a security freeze on their credit file. The company is providing two years membership to Experian’s IdentityWorks where individuals need to enroll by January 31, 2024, to avail the benefits.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543