News: 1644320712

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Vice Society said to be behind digital break-in at UK umbrella and accounting group

(2022/02/08)


Optionis, the group that includes umbrella and accountancy companies providing services to tech contractors, has confirmed that following last month's digital break-in customer data is being leaked online.

As we revealed mid-January, Parasol Group, which provides payroll services to freelancers, [1]shut down its IT systems for an extended period to deal with a serious attack, thought by some to be ransomware. Parent Optionis Group later said that divisions [2]SJD Accountancy and Nixon Williams were also hit .

In an email seen by us, Doug Crawford, CEO at Optionis, today thanked contractors for their "patience over the past few weeks." "The incident has now been contained and we have notified the police and relevant authorities," he continued.

[3]

"Our security team has now detected that some data belonging to Optionis was copied from our system and we believe some of that has been leaked online," he added.

[4]

[5]

The company claimed to have [6]upwards of 13,000 contractors on its books as of last October.

Crawford confirmed that the group has yet to determine the "precise nature of this information."

[7]

"We felt that it was important to let you know about this development and we can assure you that we will inform you as a matter of urgency should we uncover that personal data which is likely to result in a high risk to you has been leaked."

[8]Court of Appeal ruling offers hope for UK umbrella firm workers chasing holiday pay

[9]More contractor pain: Parasol's sister firms, SJD Accountancy and Nixon Williams, confirm cyberattack

[10]Umbrella company Parasol Group confirms cyber attack as 'root cause' of prolonged network outage

[11]Multi-day IT systems outage whacks umbrella biz Parasol Group amid fears of a cyber attack

So what is Optinois doing for contractors as it continues to investigate the security incident? It is partnering with Experian, which has set up a dedicated helpline to field any questions from concerned freelancers.

This is the same credit reference agency that in 2020 sent the [12]details of 24 million South Africans to one individual who purported to be a client.

According to infosec experts, Vice Society – the same gang that [13]snared retail chain Spar last year – is behind the attack on Optionis. The gang's leak site includes thousands of documents including spreadsheets, database files, and folders that it claims were taken from Optionis.

Brett Callow, a threat researcher at Emsisoft, told The Register : "Vice Society emerged in the middle of last year and has been observed to deploy multiple ransomware families, including HelloKitty and Zeppelin. They do, however, appear to have some form of connection with the threat group behind HelloKitty, FiveHands and DeathRansom but the nature of the relationship isn't clear." ®

Get our [14]Tech Resources



[1] https://www.theregister.com/2022/01/14/multiday_it_systems_outage_whacks/

[2] https://www.theregister.com/2022/01/18/sjd_accountancy_ransomware_attack/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YgKhu9ccr4Enq1XtVJrHrwAAANc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YgKhu9ccr4Enq1XtVJrHrwAAANc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YgKhu9ccr4Enq1XtVJrHrwAAANc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://parasolgroup.co.uk/blog/parasol-group-celebrates-trustpilot-milestone-with-1000-reviews-15399/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YgKhu9ccr4Enq1XtVJrHrwAAANc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/02/02/court_of_appeal_ruling_offers_hope/

[9] https://www.theregister.com/2022/01/18/sjd_accountancy_ransomware_attack/

[10] https://www.theregister.com/2022/01/17/umbrella_company_parasol_group_confirms/

[11] https://www.theregister.com/2022/01/14/multiday_it_systems_outage_whacks/

[12] https://www.theregister.com/2020/08/20/experian_24m_south_africans_data_breach/

[13] https://www.theregister.com/2021/12/06/spar_cyber_attack/

[14] https://whitepapers.theregister.com/



Eh?

Aristotles slow and dimwitted horse

What on Earth do they expect Experian to be able to provide in terms of services in this instance, that they themselves shouldn't be providing their customers?

Experian are probably the last company I would want advising me or answering questions about any leaked personal and business data.

Re: Eh?

Cederic

Following a data breach it's useful to put in place automated measures to mitigate and prevent identity theft and its ensuing complications.

Experian are one of several companies that offer a service providing that type of support.

Cynically I suspect that market's primary customers are the companies suffering breaches and paying for those services on consumers' behalf to offset their own exposure and risks.

Re: Eh?

Velv

Following a data breach it's useful to put in place automated measures to mitigate and prevent identity theft and its ensuing complications.

So have those measures been put in place? Am I expected to phone Experian and put them in place?

Re: Eh?

Anonymous Coward

I am a contractor working through Parasol. I also happen to pay for Experian's Identity Protection service, although I meant to stop it a while back.

Yesterday Experian notified me that my full name, date of birth, address and email address were on lists being sold on the underground market. This is a new alert, and I presume it's part of the Parasol data breach.

This in itself is useful, because it confirmed the data breach (the only previous alerts were from credit searches done by insurance brokers when setting up car insurance). Parasol are being deliberately vague about what has been leaked.

But looking through what Experian offer, you can lodge with them pretty much anything, such as credit or debit card numbers, bank account details etc. and they will check against information being sold whether your data appears in the lists.

I'm a little uncertain about doing this, because then I have to worry about someone else who has information about me to lose.

There are only really two pieces of information Parasol have about me which I'm a llttle worried about. One is my banking details (which they need to pay me), and the other is my NI number, which they need for PAYE. Fortunately, the password they have for their portal is not used for any other account, so I'm not panicking, and they have asked me to change that twice in the last three weeks.

None of the information Parasol has is of a super-secret nature, and much of it is available from other sources, but together, it is a risk. But there's not much anybody can do about it other than to carefully watch over the next few weeks and months for events suggesting ID theft.

What Experian offer

Mike 137

" you can lodge with them pretty much anything, such as credit or debit card numbers, bank account details etc "

I believe one could do the same with Equifax, and we know what happened there in 2017.

global warming