News: 1626784384

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Northern Train's ticketing system out to lunch as ransomware attack shuts down servers

(2021/07/20)


Publicly owned rail operator Northern Trains has an excuse somewhat more technical than "leaves on the line" for its latest service disruption: a ransomware attack that has left its self-service ticketing booths out for the count.

"Last week we experienced technical difficulties with our self-service ticket machines, which meant all have had to be taken offline," a spokesperson for Northern Trains confirmed to the The Register .

[1]

April 12th 2021: Leeds Railway Station on the day non essential shops reopened in the area

"This is the subject of an ongoing investigation with our supplier, but indications are that the ticket machine service has been subject to a ransomware cyberattack. Working with the supplier, we took swift action and the incident has only affected the servers which operate the ticket machines. Customer and payment data has not been compromised."

A representative for Northern Trains referred further questions on to Flowbird Transport, which provides the ticketing system in question, telling us "it's their system that's been affected."

Northern Trains partnered with Flowbird in a £17m-and-counting scheme to update its self-service ticketing facilities in 2016. Through that partnership the pair reported installing 621 of Flowbird's machines at 420 stations as of [2]May this year.

[3]

"We are working to restore normal operation to our ticket machines as soon as possible," Northern Trains' spokesperson continued. "We are sorry for any inconvenience this incident causes and, in the meantime, are advising customers to either use Northern's mobile app or website to purchase tickets in advance and, where necessary, to collect those from one of our ticket offices. Of course, those offices can also be used to buy tickets.

[4]Upside down, you turn me, you're giving bork instinctively: Firefox flips as a train connection is missed

[5]Yes, TfL asked people to write down their Oyster passwords – but don't worry, they didn't inhale

[6]What made a super high-tech home in Victorian England? Hydroelectric witchery, for starters

[7]Free WiFi coming to UK trains ... in two years

"Customers who have already bought tickets to be collected at a machine, or who would normally use 'promise to pay' slips, should board their booked service and either speak to the conductor or to Northern staff at their destination station."

The publicly owned Northern Trains took over the operation of the Northern rail franchise from Arriva Rail North in [8]March last year , after poor performance from the previous franchise holder gave the government cause to step in.

[9]

[10]

Northern Trains' public-facing news page failed to mention any ransomware attack but blamed the ongoing outage on unspecified [11]"technical difficulties."

"An issue was recently identified which impacted our TVM services for one customer (Northern)," a Flowbird spokesperson confirmed in a statement on the ransomware attack. "The issue was first identified through cyber monitoring systems and our initial investigations indicated that the service may have been subject to a cyber-attack.

[12]

"We immediately instigated our major incident procedure in order to protect other parts of the network and our checks have shown there has been no compromise to any personal data. The TVM [Ticket Vending Machine] network has been taken offline as a precautionary measure and we are working with our customer in order to restore services as soon as possible."

Flowbird did not confirm whether it had alerted authorities to the breach.

Charlie Smith, consulting solutions engineer at Barracuda Networks said the latest incident is a "stark reminder" that businesses of all shapes and sizes can fall under the watchful eye of infosec criminals.

[13]

"[R]egularly reviewing and testing your data regulation practices is essential to ensure all IT staff are comfortable in running a full system recovery for software and data that is critical to a business functioning, especially during the summer months when many people are taking holiday.

“The only way to recover quickly and easily from a ransomware attack is to remove all infected data and run full system and virtual machine level recoveries of the web servers and IT systems which have been exploited." ®

Get our [14]Tech Resources



[1] https://regmedia.co.uk/2021/07/20/shutterstock_leeds_rail_concourse.jpg

[2] https://www.railway-technology.com/news/northern-deploys-ticket-machines/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YPbzJt7gYRG9X8oLis0HwQAAAMc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.theregister.com/2020/09/08/bork/

[5] https://www.theregister.com/2019/08/27/tfl_oyster_cards_plain_text_password_form/

[6] https://www.theregister.com/2019/03/18/geeks_guide_to_britain_cragside/

[7] https://www.theregister.com/2015/02/12/free_wifi_coming_to_uk_trains_in_two_years/

[8] https://www.bbc.com/news/uk-england-51298820

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPbzJt7gYRG9X8oLis0HwQAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YPbzJt7gYRG9X8oLis0HwQAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://www.northernrailway.co.uk/updates/travel-alerts/2945-self-service-ticket-machines-fault

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YPbzJt7gYRG9X8oLis0HwQAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YPbzJt7gYRG9X8oLis0HwQAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



A quick fix

Version 1.0

We see ransomware and related attacks everywhere - but before the internet existed they were completely non-existent. We can fix this by returning to the original systems that were very reliable ... e.g. a station-master and a couple of employees who sell you a ticket and check them when people get off the train. All the changes that have been made to the way the world works were claimed to improve service and save money but they have resulted in more people unemployed, ransomware becoming very efficient, and insecure systems everywhere.

Re: A quick fix

AMBxx

I remember them well. Queuing to buy a ticket. If you wanted to buy in advance, you had to go to the station. Planning a route involved going to the station, queuing and asking for help.

PS Unemployment is much lower these days.

Re: a station-master and a couple of employees

Anonymous Coward

ah, but what about the executives' BONUSES?!

Ransomware

Warm Braw

As someone who used to travel regularly on Northern Trains, I'm not sure I'd notice much difference either in my pocket or in the quality of service.

One Needs To Ask

wolfetone

How important are Northern Trains to the UK's infrastructure to be targeted like this?

Re: One Needs To Ask

Sandtitz

How important are Northern Trains to the UK's infrastructure to be targeted like this?

It doesn't have to be targeted at all. Could be a fully or semi-automated process, such as:

- Malware such as Cryptolocker is mass mailed to millions and someone at Flowbird/NT managed to execute the malware.

- All the public IP's are constantly scanned and a vulnerability in a (web)server / router / firewall has allowed the malware installation. Due to poor security practices the vulnerable machine has managed to infect other systems, the backend servers or even those ticket vending machines.

The railway infrastructure is not affected at all, NT just couldn't sell tickets.

devin3782

Chaos reigns within, reflect, restore, reboot.

Makes a change

Steve Kerr

Normally it's their passengers, sorry "customers" that are normally held to ransom

Conductors?

MJI

Wow on train orchestras.

BR never had those!

Re: Conductors?

katrinab

The buses had conductors. The trains I think had guards.

Re: Conductors?

Steve K

They certainly have my symphony here

Re: Conductors?

Dabooka

I believe nowadays we have 'Train Managers'

Still no catering on the Trans Pennine routes (at least last time I had the pleasure of using one), but we have a manager.

Re: Managers?

DJV

But what do the managers manage?

Apart from passenger customer disappointment, though I suspect they don't manage to manage that either, but only manage to magnify it.

poor performance from the previous franchise holder gave the government cause to step in

Anonymous Coward

from here on, it can only get better! Oh, wait!

Re: poor performance from the previous franchise holder gave the government cause to step in

Anonymous Coward

The flowbird ticket machine “upgrade” was a project inherited by the government from the failed franchisee when they took over Northern last year.

They should leave them switched off.

Anonymous Coward

Nothing much of value was lost. The flowbird machines are absolutely useless in direct sunlight as their giant screens become completely illegible. Many have been placed out in the open with no shade so are unusable for large parts of the day, especially in summer.

If you overcome that barrier you have to deal with the software, which is slow, crashes often, and is generally a huge downgrade from the previous system. I no longer attempt to buy a ticket from them if my train is arriving within the next 10 minutes as the risk of me missing it because I’m waiting for the machine is too high. Faults in the machines are so common I’ve never been challenged when I buy a ticket from a conductor or from a staffed kiosk at the other end.

Are they not selling tickets?

yetanotheraoc

"Customer and payment data has not been compromised."

I don't think they know how ransomware works. Usually it's two attacks in one.

With all the fancy scientists in the world, why can't they just once
build a nuclear balm?