Intruder alert: UK retailer WH Smith hit by another cyber attack
- Reference: 1677763620
- News link: https://www.theregister.co.uk/2023/03/02/wh_smith_breach/
- Source link:
In a typically passive statement, the magazines, paperbacks and sweeties retailer posted a [1]London Stock Exchange notice to investors this morning explaining it had been the "target of a cyber security incident."
Public companies like WH Smith – which is is a constituent of the FTSE 250 Index – have to disclose these things under financial regulator rules, lest shareholders sue them at a later date for not coughing up the information in a timely manner.
[2]
WH Smith said the attack had "resulted" in illegal access to some company data, including on current and former employees.
[3]
[4]
However, its website, customer accounts and "underlying customer databases" were on separate systems that were not accessed, it said. As for the staffers whose data was snaffled, it is "notifying all affected colleagues and have put measures in place to support them."
It added: "Upon becoming aware of the incident, we immediately launched an investigation, engaged specialist support services and implemented our incident response plans, which included notifying the relevant authorities."
[5]
The group, which is just weeks away from reporting its results for the half year to February 28, added that it had seen "strong trading performance" and that its commercial activities were not affected.
[6]DNA testing biz vows to improve infosec after criminals break into database it forgot it had
[7]What Mary, Queen of Scots, can teach today's cybersec royalty
[8]Airbus in talks to buy 30% chunk of Atos's breakaway cybersecurity biz
[9]LockBit's Royal Mail ransom deadline flies by. No data released
In [10]April last year , someone illegally accessed systems of WH Smith's subsidiary Funky Pigeon. The online greetings card and gifts business had to stop taking orders during the attack, but said that payment data was not affected. Just days before, the company's social media feeds had been telling customers that [11]"technical issues" were delaying new business being processed. It did not clarify which data was accessed.
The latest developments at WH Smith come a week after the Royal Mail resumed international shipments as it recovers from an attack by individuals who said they weren't, and then that they were, part of Russia-linked group LockBit. The malware slingers appear to have given up on getting the [12]ransom they asked from Royal Mail and published some files it claimed were from the stolen loot.
The Royal Mail told [13]Reuters that its investigation didn't find any financial or sensitive customer information among the data the thieves stole. ®
Get our [14]Tech Resources
[1] https://www.londonstockexchange.com/news-article/SMWH/notice-of-cyber-security-incident/15859335
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZADWNT7TL@XHhX-dUiUFkgAAABE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZADWNT7TL@XHhX-dUiUFkgAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZADWNT7TL@XHhX-dUiUFkgAAABE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZADWNT7TL@XHhX-dUiUFkgAAABE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2023/02/20/dna_testing_firm_pays_200k/
[7] https://www.theregister.com/2023/02/20/opinion_column_mary_queen_of_scots/
[8] https://www.theregister.com/2023/02/16/airbus_evidian_stake/
[9] https://www.theregister.com/2023/02/13/lockbits_royal_mail_ransom_deadline/
[10] https://www.theregister.com/2022/04/19/funky_pigeon_security_incident/
[11] https://twitter.com/Thefunkypigeon/status/1514939709553889288?s=20&t=rGPCW544Fh1MCmuiQoaaog
[12] https://www.theregister.com/2023/02/13/lockbits_royal_mail_ransom_deadline/
[13] https://www.reuters.com/technology/lockbit-ransomware-group-threatens-publish-stolen-royal-mail-data-techcrunch-2023-02-07/
[14] https://whitepapers.theregister.com/
Re: As someone married to an Ex-WH Smith Employee
I'm more surprised they have a computer.
I assumed it was run on a Speccy that was left in a store cupboard
Re: As someone married to an Ex-WH Smith Employee
If they were using Tasword 2, Vu-File, and Vu-Calc the data would be more secure.
Re: As someone married to an Ex-WH Smith Employee
I'm more surprised they have a computer.
That seems to be a common reaction across social media. Certainly one I had.
Offers
If the attackers managed to get away with their haul without being hassled to buy a large bar of chocolate then I'd be interested in their methods.
Re: Offers
They still are on about that? It's been years, decades even, since I last set foot in a WH Smith's, mostly because it's been a Very Long Time since I've been in the UK. I always felt lucky if I managed to escape a Smith's without chocolate or some such. One would think that they were a confectioners or something of the sort.
Re: Offers
Even their self-serve checkouts do it. As I'm developing a sort of tunnel vision I often don't notice the pop-up offering me some extra as I start paying for the Weekend Guardian. Luckily an employee was nearby last Saturday and cleared the notice for me as I stood there wondering why my coins were just rolling through the machine and into the output tray.
Re: Offers
What are these"coins" that you speak of?
Are they another annoyance that Smiths try to foist on you?
Re: Offers
I'm sure there must be a witty observation about many newspaper readers being completely unable to observe and react to the real-world events around them. But I wouldn't be so cruel ...
Intruder alert yawning
Before the COVID days I used to see a blocked malware delivery on the corporate mail server from the spawn of Satan every six months - these days we get a dozen every day so I guess that entities getting data theft is a constant risk everywhere now. We're blocking them but they arrive continuously - safely blocking them isn't easy, it needs a lot of work and I have a corporate backup setup too because I can't be certain that malware blocking is 100% effective although it's currently working for us; fingers crossed, touch wood.
As someone married to an Ex-WH Smith Employee
In many ways, a data-breach of employee's data really is just another drop in the sea of contempt that WH Smith's head office seem to have for their staff.
They're an utter shit-show.