The Guardian ransomware attack hits week two as staff told to work from home
(2023/01/04)
- Reference: 1672862411
- News link: https://www.theregister.co.uk/2023/01/04/guardian_ransomware_attack/
- Source link:
Long-standing British broadsheet The Guardian has told staff to continue working from home and notified the UK's data privacy watchdog about the security breach following a suspected ransomware attack before Christmas.
The publication broke the news about the "serious IT incident" on its systems on December 21, and said the attack affected parts of the company's technology infrastructure. At the time, it told staff to work from home.
"We believe this to be a ransomware attack but are continuing to consider all possibilities," The Guardian Media Group Chief Executive Anna Bateson and Editor-in-Chief Katharine Viner [1]told staff last month.
[2]
Since then, the newspaper has notified Britain's Information Commissioner's Office (ICO) about the breach. "Guardian News and Media has made us aware of an incident and we are making enquiries," an ICO spokesperson told The Register .
[3]
[4]
According to the ICO's rules, organizations must notify the government agency [5]within 72 hours of discovering a ransomware attack.
Also this week, The Guardian confirmed that most of its staff in the UK, US and Australia will continue working from home until at least January 23.
[6]
"As we previously announced, the Guardian's systems have been subject to a serious network disruption," a spokesperson told The Register . "We have been able to keep publishing our journalism digitally and in print, but a number of key IT systems have been affected. The work to restore our systems fully is ongoing and will take some weeks. We have asked most staff to work from home for the next three weeks to allow our technical teams to focus on essential technical work."
The spokesperson declined to answer any additional questions about the security incident.
[7]UK's Guardian newspaper breaks news of ransomware attack on itself
[8]This ransomware gang is a right Royal pain in the AES for healthcare orgs
[9]Rackspace confirms ransomware attack behind days-long email meltdown
[10]LockBit: Sorry about the SickKids ransomware, not sorry about the rest
So far, none of the usual suspects have claimed responsibility for the purported ransomware attack.
However, ransomware gangs including [11]LockBit have been especially busy over the past month, with that group of criminals attacking (and then apologizing for attacking) Canada's largest children's hospital and Los Angeles' public housing authority, among others.
At least 219 local governments, health-care providers, colleges, universities and school districts in the US alone were victims of ransomware attacks last year, according to numbers published this week by Emsisoft Malware Lab.
[12]
The security firm has reportedly similarly high stats in its earlier reports since 2019. "The fact that there seems not to have been any decrease in the number of incidents is concerning," report authors [13]said .
Additionally, a report
Get our [15]Tech Resources
[1] https://www.theregister.com/2022/12/21/the_guardian_hit_by_ransomware/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y7YFDpoZdBHvCy1utPtysQAAAFM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y7YFDpoZdBHvCy1utPtysQAAAFM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y7YFDpoZdBHvCy1utPtysQAAAFM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/security/ransomware-and-data-protection-compliance/#scenario-3
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y7YFDpoZdBHvCy1utPtysQAAAFM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/12/21/the_guardian_hit_by_ransomware/
[8] https://www.theregister.com/2022/12/09/royal_ransomware_hhs_warning/
[9] https://www.theregister.com/2022/12/06/rackspace_confirms_ransomware/
[10] https://www.theregister.com/2023/01/04/lockbit_sickkids_ransomware/
[11] https://www.theregister.com/2023/01/04/lockbit_sickkids_ransomware/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y7YFDpoZdBHvCy1utPtysQAAAFM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://www.emsisoft.com/en/blog/43258/the-state-of-ransomware-in-the-us-report-and-statistics-2022/
[14] https://www.fincen.gov/sites/default/files/2022-11/Financial%20Trend%20Analysis_Ransomware%20FTA%202_508%20FINAL.pdf
[15] https://whitepapers.theregister.com/
The publication broke the news about the "serious IT incident" on its systems on December 21, and said the attack affected parts of the company's technology infrastructure. At the time, it told staff to work from home.
"We believe this to be a ransomware attack but are continuing to consider all possibilities," The Guardian Media Group Chief Executive Anna Bateson and Editor-in-Chief Katharine Viner [1]told staff last month.
[2]
Since then, the newspaper has notified Britain's Information Commissioner's Office (ICO) about the breach. "Guardian News and Media has made us aware of an incident and we are making enquiries," an ICO spokesperson told The Register .
[3]
[4]
According to the ICO's rules, organizations must notify the government agency [5]within 72 hours of discovering a ransomware attack.
Also this week, The Guardian confirmed that most of its staff in the UK, US and Australia will continue working from home until at least January 23.
[6]
"As we previously announced, the Guardian's systems have been subject to a serious network disruption," a spokesperson told The Register . "We have been able to keep publishing our journalism digitally and in print, but a number of key IT systems have been affected. The work to restore our systems fully is ongoing and will take some weeks. We have asked most staff to work from home for the next three weeks to allow our technical teams to focus on essential technical work."
The spokesperson declined to answer any additional questions about the security incident.
[7]UK's Guardian newspaper breaks news of ransomware attack on itself
[8]This ransomware gang is a right Royal pain in the AES for healthcare orgs
[9]Rackspace confirms ransomware attack behind days-long email meltdown
[10]LockBit: Sorry about the SickKids ransomware, not sorry about the rest
So far, none of the usual suspects have claimed responsibility for the purported ransomware attack.
However, ransomware gangs including [11]LockBit have been especially busy over the past month, with that group of criminals attacking (and then apologizing for attacking) Canada's largest children's hospital and Los Angeles' public housing authority, among others.
At least 219 local governments, health-care providers, colleges, universities and school districts in the US alone were victims of ransomware attacks last year, according to numbers published this week by Emsisoft Malware Lab.
[12]
The security firm has reportedly similarly high stats in its earlier reports since 2019. "The fact that there seems not to have been any decrease in the number of incidents is concerning," report authors [13]said .
Additionally, a report
[14]PDF
by the Financial Crimes Enforcement Network (FinCEN), part of the US Treasury, found that the impact of ransomware attacks — measured in Bank Secrecy Act filings — hit $1.2 billion 2021, up 188 percent compared with 2020. ®Get our [15]Tech Resources
[1] https://www.theregister.com/2022/12/21/the_guardian_hit_by_ransomware/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y7YFDpoZdBHvCy1utPtysQAAAFM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y7YFDpoZdBHvCy1utPtysQAAAFM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y7YFDpoZdBHvCy1utPtysQAAAFM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/security/ransomware-and-data-protection-compliance/#scenario-3
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y7YFDpoZdBHvCy1utPtysQAAAFM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/12/21/the_guardian_hit_by_ransomware/
[8] https://www.theregister.com/2022/12/09/royal_ransomware_hhs_warning/
[9] https://www.theregister.com/2022/12/06/rackspace_confirms_ransomware/
[10] https://www.theregister.com/2023/01/04/lockbit_sickkids_ransomware/
[11] https://www.theregister.com/2023/01/04/lockbit_sickkids_ransomware/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y7YFDpoZdBHvCy1utPtysQAAAFM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://www.emsisoft.com/en/blog/43258/the-state-of-ransomware-in-the-us-report-and-statistics-2022/
[14] https://www.fincen.gov/sites/default/files/2022-11/Financial%20Trend%20Analysis_Ransomware%20FTA%202_508%20FINAL.pdf
[15] https://whitepapers.theregister.com/
Continuity?
"We have been able to keep publishing our journalism..."
..and all of your clients' email services are restored, along with legacy data? Oh! Wait, you don't do that! Could you spare some time for a little outfit in San Antonio? I'm sure they have the space, and you could rack up some column inches too!