News: 1647351006

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK criminal defense lawyer hadn't patched when ransomware hit

(2022/03/15)


Criminal defense law firm Tuckers Solicitors is facing a fine from the UK's data watchdog for failing to properly secure data that included information on case proceedings which was scooped up in a ransomware attack in 2020.

The London-based business was handed a £98,000 penalty notice by the Information Commissioner's Office under Article 83 of the EU's General Data Protection Regulation 2018*.

The breach was first noted by Tuckers on August 23 2020 when part of its IT system became unavailable. On closer inspection, resident techies found a note from the attackers confirming they had compromised part of the infrastructure. The Microsoft Exchange server was out of action and two days' worth of emails were lost, as detailed by the [1]company blog at the time .

[2]

The breach was reported to the ICO by Tuckers on August 25 2020, the ICO says.

[3]

[4]

According to the watchdog's [5]monetary penalty notice [PDF], "neither" the solicitor or the third party specialist hired to investigate the break-in were able to confirm the exact location of unauthorized entry but "found evidence of a known system vulnerability."

Tuckers told the ICO it patched the unnamed vuln in June 2020, but admitted the patch has been released in January that year, and the lawyer "accepted that the attacker could have exploited it" in that five-month period, the ICO report states. The CVE scored a CVSS of 9.8 or "critical", it adds.

[6]

Once the attacker was inside the network, they created their own account and used this to launch the wider assault, encrypting a "significant volume of personal data contained in case bundles held on the archive server within the Tuckers network," the report adds.

Data held on the archive server had not been encrypted, Tuckers admitted to the ICO. This wouldn't have prevented the attack but may have mitigated the risk to data subjects.

The criminals then encrypted 972,191 individual files, of which 24,712 related to court bundles. Of the encrypted bundles, 60 were "exfiltrated by the attacker and released in underground data marketplaces," says the ICO.

[7]

Tuckers said in its company blog the data dumped on the dark web pertained to 60 clients out of a potential haul of 60,000, so this wasn't the worst result for the lawyer. Neither was this its finest hour.

"The 60 exfiltrated court bundles included 15 relating to criminal court proceedings and 45 civil proceedings. Of the 60 exfiltrated court bundles, the personal data was not related to just one living individual, it was likely to have included multiple individuals," the ICO states in its report.

The criminals' cases had concluded, with just one at the Proceeds of Crime Act stage. The civil cases were a mix of archived and live cases. Tuckers told the ICO that to the best of its understanding the security breach "had not had any impact… on the conduct or outcome of the relevant proceedings."

[8]New US law: Cyberattacks to be reported within 72 hours

[9]Microsoft squashes OneDrive bug that caused files to linger after PC wipe

[10]Linux distros patch 'Dirty Pipe' make-me-root kernel bug

[11]Enterprise open-source is on the up and proprietary software on the way down

The ICO says the personal data in the bundles included special category data that related to vulnerable individuals such as children or those involved in significant crimes, which increased the "severity of this infringement."

Tuckers refused to pay the ransom, saying in its August 2020 blog: "Unfortunately for our attackers, targeting a criminal defence firm, with income predominantly from the legal aid sector, with a view to extorting money, is something of a fool's errand."

As such, the business moved its server to a new environment by September 2020 "albeit without the restoration of the data that had been compromised by the attacker" which it said were "permanently lost", although the material in the bundles was still available in the case management system it added.

The conclusion from the ICO was that the primary cause of the incident obviously rests with the ransomware criminal or criminals.

Yet an unpatched vulnerability "gave the attacker a weakness to exploit," and the serious nature of the personal data was such that it justified enforcement action.

"Taking into consideration the highly sensitive nature of the personal data that Tuckers were processing, as well as the state of the security updates, and the costs of implementation for them, Tuckers should not have been processing personal data on an infrastructure containing known critical vulnerabilities without appropriately addressing the risk," the report says. ®

*The applicable legislation at the time of the incident, which occurred before the [12]official Brexit date of January 31, 2020 .

Get our [13]Tech Resources



[1] https://www.tuckerssolicitors.com/tuckers-cyber-ransomware-attack/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YjDGO1ItC6kgWsDp2tfLQwAAAAM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjDGO1ItC6kgWsDp2tfLQwAAAAM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YjDGO1ItC6kgWsDp2tfLQwAAAAM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://ico.org.uk/media/action-weve-taken/mpns/4019746/tuckers-mpn-20220228.pdf

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YjDGO1ItC6kgWsDp2tfLQwAAAAM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YjDGO1ItC6kgWsDp2tfLQwAAAAM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/03/14/in_brief_security/

[9] https://www.theregister.com/2022/03/09/windows_reset_fix_onedrive/

[10] https://www.theregister.com/2022/03/08/in_brief_security/

[11] https://www.theregister.com/2022/03/02/red_hat_open_source/

[12] https://www.theregister.com/2020/01/30/uk_government_free_eu_roaming_will_end/

[13] https://whitepapers.theregister.com/



Defense

Dr Scrum Master

Defense!?

Re: Defense

Anonymous Coward

My dog ran away because of a hole in defence.

msobkow

Gee, now if only we could fine all the general public that are using insecure and infected computers and FORCE their systems offline so they can't be used as bots.

Anonymous Coward

So, everyone running Windows 10 or 11 then? =-)p

Doctor Syntax

It seems tht once they were aware of the situation they acted appropriately. But it always seems to be the case that although there's no time and/or budget to fix things before the disaster strikes there's always time and budget to fix things after - including budget to pay a fine.

Neil Barnes

See this stable door?

Using it before the horse leaves would be good.

Flywheel

They were probably trying to work out if they could bill someone for the time and software costs...

Stamp out organized crime!! Abolish the IRS.