News: 1622794510

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Brit retailer Furniture Village confirms 'cyber-attack' as systems outage rolls into Day 7

(2021/06/04)


Furniture Village – the UK's largest independent furniture retailer with 54 stores nationwide – has been hit by a "cyber-attack", the company confirmed to The Register .

Details are still sketchy, but it emerged late last week that some of the retailer’s internal systems had been taken offline.

Although its website remains up and running, this is not the case for the back end. The problems emerged last weekend on 29 May when Furniture Village admitted it was experiencing "technical issues" and it was unable to answer calls. This is still the case at the time of publication, 6 days later.

[1]

By Wednesday, Furniture Village revealed it was “still experiencing technical issues with [its] internal systems” and that the team was working to resolve them as quickly as possible. These included delivery systems, phone systems, and according to customers, payment mechanisms.

So frustrated that not only is there a phone line glitch for [2]@OfficialFV but also their payment system has a glitch which doesn't have a time frame to be fixed by.was asked to call them back and now in some voicemail loop. Voicemail prob has a glitch too!💆🏽‍♀️🤦🏽‍♀️ — Brash A (@Brashtastic) [3]June 3, 2021

[4]@OfficialFV YOU called ME last week to arrange delivery of my new sofa for today. I got rid of my sofa yesterday and called you today to be told it won’t just not be arriving today, but it hasn’t even been made yet. I’ve just given BIRTH and now have nothing to sit on. CHEERS 👍 — KAIYA (@KaiyaMusicUK) [5]June 3, 2021

The Reg asked the furniture retailer what has caused the multi-day troubles and the company admitted that it had been the victim of a cyber-attack but stressed no data had been leaked and it was continuing to restore all "system-related functions".

In a statement, Furniture Village told The Register :

[6]

[7]

"Frustratingly, Furniture Village was recently the target of a cyber-attack, however, by immediately implementing security protocols, including shutting down the affected systems, we were able to restrict the scope of the attack.

"Thankfully, to the best of our knowledge, no personal data has been lost or compromised.

[8]

"We're working around the clock to restore all system-related functions of the business as soon as it’s safe to do so. The business remains healthy, and our teams are focused on supporting our customers, resorting to manual processes where necessary."

At this stage, the true nature of the attack remains unclear, but some industry experts believe the retailer could be the victim of a ransomware flingers. There has been no formal confirmation as to whether law enforcement agencies have been notified.

[9]JBS Foods ransomware gang: White House 'engaging directly' with Russia about attack on massive meat producer

[10]Oh SITA: Airline IT provider confirms passenger data leaked after major 'cyber-attack'

[11]Sodinokibi/REvil ransomware gang pwns British housing biz via suspected phishing attack

[12]EU Medicines Agency hacked, BioNTech-Pfizer coronavirus vaccine paperwork stolen, probe launched

Last week, the UK’s National Crime Agency published its 2021 National Strategic Assessment in which it said that criminals are exploiting advances in technology to drive "serious and organised crime."

It singled out ransomware attacks stating that they have "increased in frequency and impact."

"It is estimated 50 per cent of all ransomware attacks included a threat to publish stolen data and over the last year there were £3bn of estimated fraud losses for UK individuals and businesses, but an accurate figure is constrained by significant under-reporting," it said.

[13]

Furniture Village declined to comment further beyond the statement issued. You can [14]tip us off securely here . ®

Get our [15]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YLn5v2AYieiRxuthNHlTpgAAANg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://twitter.com/OfficialFV?ref_src=twsrc%5Etfw

[3] https://twitter.com/Brashtastic/status/1400454259351511044?ref_src=twsrc%5Etfw

[4] https://twitter.com/OfficialFV?ref_src=twsrc%5Etfw

[5] https://twitter.com/KaiyaMusicUK/status/1400442022226505731?ref_src=twsrc%5Etfw

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YLn5v2AYieiRxuthNHlTpgAAANg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YLn5v2AYieiRxuthNHlTpgAAANg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YLn5v2AYieiRxuthNHlTpgAAANg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2021/06/02/jbs_fodds_ransomware/

[10] https://www.theregister.com/2021/03/05/oh_sita_airline_it_provider/

[11] https://www.theregister.com/2020/11/06/revil_sodinokibi_ransomware_gang_flagship_group_housing/

[12] https://www.theregister.com/2020/12/09/european_medicines_agency_cyberattack/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YLn5v2AYieiRxuthNHlTpgAAANg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.theregister.com/Profile/contact/

[15] https://whitepapers.theregister.com/

A cyber-attack and no data had been leaked

Pascal Monett

That sounds a lot like they got hit by encryption malware, locked it down and are in the process of restoring their servers and possibly some of their PCs as well.

Good on them for not paying. Too bad somebody clicked the wrong link.

Re: A cyber-attack and no data had been leaked

Anonymous Coward

Clicked on a link? That's not how this stuff is happening, you do know that?

The current wave of attacks utilise nation-state style network intrusion, only instead of just being content to rumage through your network looking for data to steal, after they have something juicy to expose to the world, they sh1t bomb every machine they can with the encryption code.

This isn't like firing an artillery piece at a remote area target, this is hand delivered explosives stuck onto your most vital assets.

Its a bit of a shock to anyone who has never played in the world of APT before....more battle experienced orgs know exactly what happens, the only problem is that this looks like an APT low and slow intrusion that maybe you have time to deal with then suddenly it turns into mass destruction - something your usual foes would never do.

Re: A cyber-attack and no data had been leaked

PM from Hell

That's quite informative but what does the Advanced Passenger Train have to do with this

I hope Furniture Village

Andy Non

aren't taking this sitting down.

Re: I hope Furniture Village

alain williams

Whoever let the malware in will be carpeted.

Have they double-checked...

Ken Moorhouse

...that it's not slipped down the back of the sofa?

Necessity has no law.
-- St. Augustine