UK VoIP telco receives 'colossal ransom demand', reveals REvil cybercrooks suspected of 'organised' DDoS attacks on UK VoIP companies
- Reference: 1630578732
- News link: https://www.theregister.co.uk/2021/09/02/uk_voip_telcos_revil_ransom/
- Source link:
South Coast-based [1]Voip Unlimited has confirmed it has been slapped with a "colossal ransom demand" after being hit by a sustained and large-scale DDoS attack it believes originated from the Russian cybercriminal gang REvil.
This morning, it [2]confirmed that "services are operational ... however the attacks are still ongoing."
[3]
Separately, [4]London-based Voipfone (see status page here) said it is still suffering outages on voice, inbound and outbound calls, and SMS services. It told customers on Tuesday in a status update that it had been hit by "a further DDoS attack" after the initial attack, revealed to customers via email as having taken place over the Monday bank holiday.
[5]
[6]
At this stage it's not clear if any other UK Internet Telephony Service Providers (ITSP) have been affected. However, [7]UK Comms Council – the industry body that represents ITSPs – has informed members of the industry group about the attacks and issued a reminder to adopt "appropriate DDoS mitigation strategies."
Mark Pillow, MD of Voip Unlimited, told us the company takes "full responsibility of the availability of our services to our clients" and that he is "extremely sorry for all inconvenience caused."
[8]
In a statement, he explained: "At 2pm 31st August, Voip Unlimited's network was the victim of an alarmingly large and sophisticated DDoS attack attached to a colossal ransom demand."
As a result of the attack some of VoIP Unlimited's network experienced "intermittent or total loss of internet connectivity services" although customers using its Voip Unlimited Ethernet and Broadband services are understood to have remained largely unaffected.
[9]Dissected: A dropper-as-a-service miscreants pay to push their malware onto potentially 1,000s of victims
[10]In Microsoft's world, cloud email still often requires on-premises Exchange. Why?
[11]Mirai-style IoT botnet is now scanning for router-pwning critical vuln in Realtek kit
[12]Blackbaud – firm that paid off crooks after 2020 ransomware attack – fails to get California privacy law claim dropped
Pillow went on to say the incident was not isolated and that other companies had also been hit.
"UK Comms Council have communicated to us that other UK SIP (Session Initiation Protocol) providers are affected and identified them as a criminal hacking organisation called REvil who appear to be undertaking planned and organised DDoS attacks against VoIP companies in the UK," he said.
The full extent of the attack is not yet known, but in an email sent by Voipfone on Tuesday and seen by El Reg the company told customers that its services had been "intermittently disrupted by a DDoS attack" over the Bank Holiday weekend that flooded its network with bogus traffic from tens of thousands compromised devices.
[13]
Although it had managed to regain some control - biz broadband services are again live after the problem was resolved late yesterday afternoon - it did warn that the attack may return at some point. The status page is [14]here .
Sources close to Voipfone told us that they "do believe it is the same attack as the other VoIP provider" but went on to add that they have nothing official to say at the moment other than they are working to resolve the issue as quickly as possible.
It goes without saying that customers have become increasingly frustrated at being unable to access key digital communications services following a return to work after the August Bank Holiday weekend.
In a statement, chair of Comms Council UK Eli Katz told us: "Comms Council UK is aware of the Denial of Service attacks currently targeting IP-based communications service providers in the UK and that a small number of our members have been impacted. We have communicated the issue to our membership and are continuing to liaise closely with them to share further information and support as the situation develops."
UK law enforcement agencies have been informed of the attack. ®
Get our [15]Tech Resources
[1] https://www.voip-unlimited.net/
[2] https://status.voip-unlimited.net/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YTD1QJ4u-tpNtzOyZnfvXgAAABc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.voipfonestatus.co.uk/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YTD1QJ4u-tpNtzOyZnfvXgAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YTD1QJ4u-tpNtzOyZnfvXgAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://commscouncil.uk/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YTD1QJ4u-tpNtzOyZnfvXgAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2021/09/02/malware_droppers_sophos/
[10] https://www.theregister.com/2021/08/31/microsoft_on_prem_exchange/
[11] https://www.theregister.com/2021/08/25/mirai_botnet_critical_vuln_realtek_radware/
[12] https://www.theregister.com/2021/08/17/ccpa_blackbaud/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YTD1QJ4u-tpNtzOyZnfvXgAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://www.voipfonestatus.co.uk/
[15] https://whitepapers.theregister.com/
Re: Calling OfCom and Openreach...
Until a muppet puts a digger through a trunk cable. Enjoy a week of no service.
Re: Calling OfCom and Openreach...
It is a bit more difficult to do that from the comfort of a Russian basement.
This has been a known threat...
.. for close on 2 decades. Larger Compnaies will (should) have private connections into their VoIP provider, but for the smaller ones, they will not have a choice.
Re: This has been a known threat...
A 'private connection' (unless you're talking about a dedicated physical line, which for all but the very largest is utterly impractical) will not save you from a DDoS attack that swamps your provider's bandwidth.
Especially not when the underlying POTS network is gone and everything is IP based.
Much more work is needed before we start transitioning potentially life-critical systems such as telephony exclusively to the internet.
The transition has already started, my friend. It's largely on its way to be completed as well.
Fingers in their ears
This whole mess has been predicted for something like 20 years, and as far as I can see has been totally ignored by world+dog. I don't see it improving until there are mountains of dead bodies.
Re: Fingers in their ears
If you take care of a problem proactively, how are you going to make money in the future on clearing the mess?
Abandon Copper At Your Own Risk....
Be warned BT/Openreach et al.
"All that glitters is not gold" (Credit Mr. Wm. Shakespeare)
Glitter includes in this context fibre and VOIP - act in haste, repent at leisure.
Toodle Pip.
Re: Abandon Copper At Your Own Risk....
The likes of BT offering VoIP over it's own fiber is much less problematic (although not entirely without risk) as it controls the infrastructure end to end in that situation. It could, if it so desired, keep telephony traffic entirely separate from data, thus mitigating at least some of the risk of DDoS.
The chances of them actually doing that without a very firm regulatory imperative however are so small that I suspect I have a greater chance of riding in an electric flying car!
Waiting
for someone to claim the 1 mill bounty for REvil. Someone must be getting close to them by now.
Calling OfCom and Openreach...
Please can you change your mind about switching off my POTS line in 2025?