Widespread Fallout after Lockbit Double Extortion Attack at Global Moving Services Provider, Sirva

March 3, 2025

INCIDENT

Moving services provider Sirva Relocation LLC is accused of insufficient security practices after a 2023 cyber attack exposed the financial, medical, and personal information of at least 480,000 individuals. A complaint was filed in the US District Court for the Central District of California.

Lockbit targeted Sirva between September and October 2023. The gang exfiltrated 1.5 terabytes worth of files. Sirva failed to implement and maintain reasonable security practices—such as encrypting consumer personal data. This violated the California Consumer Privacy Act.

The incident was a “double extortion event” with hackers both exfiltrating the data and orchestrating a ransomware attack on Sirva’s information systems to encrypt them and take them offline. A class action against Sirva was also filed in Canada in February over the same breach. The Canadian government has contracted with SIRVA Canada since at least 2009, government records show.

Incident Date

August 16, 2023

Estimated Cost

1.5 TB data, $15 Million ransom demanded

Type of Malware

No Malware identified

Threat Source