{"id":84253,"date":"2023-01-13T05:45:00","date_gmt":"2023-01-13T05:45:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/84253"},"modified":"2023-01-13T05:45:00","modified_gmt":"2023-01-13T05:45:00","slug":"lockbit-cartel-suspected-of-royal-mail-cyber-attack","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=84253","title":{"rendered":"LockBit cartel suspected of Royal Mail cyber attack"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2023\/01\/lockbit-cartel-suspected-of-royal-mail-cyber-attack.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>The infamous LockBit ransomware cartel is suspected of being behind <a href=\"https:\/\/www.computerweekly.com\/news\/252529095\/Royal-Mail-overseas-services-hit-by-major-cyber-attack\">an ongoing cyber security incident at the UK\u2019s Royal Mail<\/a>, which has crippled IT systems and left the postal service unable to dispatch letters and parcels overseas.<\/p>\n<p><a href=\"https:\/\/www.telegraph.co.uk\/business\/2023\/01\/12\/russia-linked-hackers-behind-royal-mail-cyber-attack\/\">Leaked copies of the ransomware note<\/a> appear to identify the prolific Russia-based gang as the culprits. As is standard practice, the perpetrators claimed to have both encrypted and stolen Royal Mail\u2019s data. The value of the ransom being demanded was not disclosed, although it is likely to be at the high end of the scale.<\/p>\n<p>Although the ransom note is understood to include genuine links to dark web leak sites and negotiation tools used by LockBit, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/royal-mail-cyberattack-linked-to-lockbit-ransomware-operation\/\">security news website <em>Bleeping Computer<\/em> earlier reported<\/a> there is a chance that the threat actor behind the attack is using a leaked version of LockBit\u2019s ransomware builder and may not be directly associated with the gang.<\/p>\n<p>Royal Mail has neither confirmed nor denied the veracity of the claims. In a service update earlier this morning (Friday 13 January), the organisation said: \u201cRoyal Mail is experiencing severe service disruption to our international export services following a cyber incident.<\/p>\n<p>\u201cWe are temporarily unable to despatch items to overseas destinations. We strongly recommend that you temporarily hold any export mail items while we work to resolve the issue. Items that have already been despatched may be subject to delays. We would like to sincerely apologise to impacted customers for any disruption this incident is causing.<\/p>\n<p>\u201cOur import operations continue to perform a full service, with some minor delays. Parcelforce Worldwide export services are still operating to all international destinations though customers should expect delays of one to two days.<\/p>\n<p>\u201cOur teams are working around the clock to resolve this disruption and we will update you as soon as we have more information. We immediately launched an investigation into the incident and we are working with external experts. We have reported the incident to our regulators and the relevant security authorities.\u201d<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"Multiple victims\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Multiple victims<\/h3>\n<p>LockBit has claimed multiple victims in the UK in the past six months \u2013 <a href=\"https:\/\/www.computerweekly.com\/news\/252526099\/Advanced-Healthcare-data-was-stolen-in-LockBit-30-attack\">including NHS software supplier Advanced<\/a> \u2013 and is one of the most highly active ransomware cartels on the current scene.<\/p>\n<p>It is also considered to be one of the more sophisticated operations in play, and <a href=\"https:\/\/www.computerweekly.com\/news\/252527830\/Latest-LockBit-ransomware-versions-have-wormable-capabilities\">its locker malware is regularly updated and upgraded<\/a> to make it a more dangerous threat, and to throw investigators, researchers and journalists off the gang\u2019s scent.<\/p>\n<p>One of its most recent high-profile attacks took place on Christmas Day 2022, <a href=\"https:\/\/therecord.media\/port-of-lisbon-website-still-down-as-lockbit-gang-claims-cyberattack\/\">against the Port of Lisbon Administration (APL) in Portugal<\/a>.<\/p>\n<p>Tim Mitchell, <a href=\"https:\/\/www.secureworks.com\/\">Secureworks<\/a> Counter Threat Unit senior security researcher, said: \u201cIf this was the work of LockBit, the scale of the impact of the incident will very much depend on the particular affiliate involved.<\/p>\n<p>\u201cThe core individuals behind LockBit ransomware run arguably the most prolific ransomware-as-a-service scheme, so it\u2019s no wonder it accounted for nearly a third of named victims across all ransomware leak sites in 2022,\u201d he said.<\/p>\n<p>\u201cLockBit has been used to perform everything from broad network-wide encryptions that have crippled organisations through to deploying ransomware to only a few hosts with limited impact on the victim&#8217;s operations.<\/p>\n<p>\u201cUntil we know the details of this incident, we won\u2019t know for sure how impactful this will be long term on Royal Mail,\u201d added Mitchell.<\/p>\n<p><a href=\"https:\/\/www.orangecyberdefense.com\/\">Orange Cyberdefense<\/a>&nbsp;head of UK strategy, Dominic Trott, said as a result of a previous customer data leak in November 2022 that forced Royal Mail to <a href=\"https:\/\/www.theregister.com\/2022\/11\/03\/royal_mail_customer_data_leak\/\">temporarily suspend its Click and Drop online service<\/a>, the organisation may have been better able to respond to the current attack.<\/p>\n<p>\u201cThis earlier breach means it has had recent \u2018practice\u2019 of the UK Information Commissioner\u2019s Office (ICO) mandatory breach notification process. Nonetheless, Royal Mail will have been well prepared for this type of incident, and it has clearly made the necessary authorities aware in a timely manner to limit the potential damage,\u201d said Trott.<\/p>\n<p>\u201cSpecifically, it has already publicised that it is working with the UK\u2019s National Cyber Security Centre and the ICO to investigate the incident. But further, as a component of the UK\u2019s critical national infrastructure as determined within UK law by the Network and Information Systems Directive, it must adhere to higher standards of operational resilience \u2013 including from a cyber resilience perspective \u2013 than most organisations.\u201d<\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>The infamous LockBit ransomware cartel is suspected of being behind an ongoing cyber security incident at the UK\u2019s Royal Mail, which has crippled IT systems and left the postal service unable to dispatch letters and parcels overseas. Leaked copies of the ransomware note appear to identify the prolific Russia-based gang as the culprits. As is [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":84254,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-84253","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/84253","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=84253"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/84253\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/84254"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=84253"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=84253"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=84253"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}