News: 1710243910

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK council yanks IT systems and phone lines offline following cyber ambush

(2024/03/12)


Leicester City Council says IT systems and a number of its critical service phone lines will remain down until later this week at the earliest following a "cyber incident".

The governing body of the midlands city in England first reported issues across its services on March 7 and announced via its X channel that it had yanked a number of systems offline. A day later, it attributed the outages to a "cyber incident."

Nowadays, when organizations are as vague as this, it can mean things are worse than they're letting on.

[1]

"Cyber incident" and "encryption event" are two of the most commonly preferred phrases by public relations teams to delicately communicate a ransomware attack, although this hasn't been officially confirmed to be the case with Leicester City Council.

[2]

[3]

The Reg asked the council for clarity on the matter, including whether the digital break-in involved ransomware, and for an up-to-date statement, but it had not responded at the time of publication.

Some security experts [4]suspect ransomware is involved, and have noticed services at the council's network border pulled offline, including Citrix Netscaler and Cisco AnyConnect VPN appliances.

[5]

A cursory scan of the major ransomware groups' leak blogs shows none of the big names are yet claiming responsibility for the attack on Leicester City Council.

Senior officials said the council is still working to fully understand the nature of the incident and that services will hopefully be restored before the end of the week.

"Over the weekend we have continued to work with our cybersecurity and law enforcement partners, as well as learning from other councils who have had attacks, to identify the nature of the incident and the steps we need to take to get our systems back online," said Richard Sword, strategic director of city developments and neighborhoods at Leicester City Council.

[6]

"We expect that it will take until at least the middle of the week before we will be able to start the recovery process, beginning with our most critical services.

"We apologize for the inconvenience this is causing. Council officers are working hard to ensure that our frontline services continue to operate with the minimum of disruption."

Emergency phone numbers have been established in lieu of full access to key council services such as adult safeguarding, child protection, homelessness, housing, and others.

Online forms for functions such as reporting child protection concerns or accessing housing services are down, leaving the emergency phone number as the only contact method.

[7]Swiss cheese security? Play ransomware gang milks government of 65,000 files

[8]IT suppliers hacked off with Uncle Sam's demands in aftermath of cyberattacks

[9]Brit borough council apologizes for telling website users to disable HTTPS

[10]Capita says 2023 cyberattack costs a factor as it reports staggering £100M+ loss

"Cyberattacks happen a lot, they happen to councils a lot," said Eerke Boiten, professor of cybersecurity at De Montfort University Leicester, to [11]BBC Radio Leicester . "I think the biggest damage is the day-to-day functioning of the council which is hampered until, they say, the middle of this week before they start recovery.

"We don't know how serious it is, they're not giving everything away, but it sounds serious enough that it will probably stop normal functioning in many areas for weeks."

The council concluded its brief statement about the incident by reminding the world it's not the only UK councils tthat have suffered a cyberattack in the past year.

The reason behind making the point can be debated – trying to make the situation seem more palatable perhaps – but it's correct in saying it.

Three Kent local authorities were attacked simultaneously at the start of the year and some council services reamin disrupted. And St Helens Council also reported a suspected ransomware attack in August 2023, an incident that took the authorities months to fully restore services.

A handful of regional British councils were affected by [12]Capita exposing an unsecured AWS bucket to the web last year too, with some seeing residents' social financial benefits information exposed.

Asked about what the attack means for Leicester city residents who handed personal data over to the council, Boiten said: "I mentioned the [13]British Library , they've just come out with a detailed report on what actually happened in [its attack] and I think that's quite possibly representative for this type of attack. It pointed out, for example, that although people have been paying the British Library with credit cards, the credit card data doesn't live on their system and they're not allowed to keep it on their system because there are special regulations for payment data which make sure they don't, and they even actively look for it to delete it.

"So, those are fairly standard protections in that area. Similarly, the sensitive data that Leicester City Council has – not so much the data around payments – the way more sensitive data might be in the social work corner of the council, or anything where personal circumstances get dealt with. But then again, you would expect that such data has extra protection on it so that an attack that hits the main systems doesn't automatically get into the sensitive databases that have extra levels of protection.

He added: "Leicester City Council has a good reputation for information governance, so I have some faith that the damage done in terms of sensitive data will be quite limited." ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZfCKK3@9QQDde10zCjwvygAAAFc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfCKK3@9QQDde10zCjwvygAAAFc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfCKK3@9QQDde10zCjwvygAAAFc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://cyberplace.social/@GossiTheDog/112062381448129142

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfCKK3@9QQDde10zCjwvygAAAFc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfCKK3@9QQDde10zCjwvygAAAFc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2024/03/08/swiss_government_files_ransomware/

[8] https://www.theregister.com/2024/02/08/us_tech_industry_changes/

[9] https://www.theregister.com/2023/11/29/reading_borough_council_https/

[10] https://www.theregister.com/2024/03/06/capita_says_2023_cyberattack_recovery/

[11] https://www.bbc.co.uk/sounds/play/live:bbc_radio_leicester

[12] https://www.theregister.com/2023/05/22/capita_security_pensions_aws_bucket_city_councils/

[13] https://www.theregister.com/2024/03/11/british_library_slaps_the_cloud/

[14] https://whitepapers.theregister.com/



"Cyberattacks happen a lot, they happen to councils a lot,"

Mike 137

' "Cyberattacks happen a lot, they happen to councils a lot," said Eerke Boiten, professor of cybersecurity at De Montfort University Leicester '

One has to ask whether councils are specifically targeted in advance, or whether they're simply in general so vulnerable that they fall victim by chance. Neither the victims nor the perps will ever disclose this or they'd lose face, but a combination of the recognised poverty of most UK councils (making them a poor target of choice) and my experience of local authority IT suggests that these are mostly opportunistic successes (just as the UK NHS wasn't specifically targeted by NotPetya -- it was just wide open and so fell victim).

Simple scumbag target priority formula

cyberdemon

(number_of_customers x vulnerability_of_customers) / competence_of_it_staff

Attacks are becoming about increasing the search space for further victims of scams, and councils will be a prime target because so many people depend on them.

I am unfortunately a southern water hostag^Wcustomer and since their cyber-leak i have started getting many scam calls e.g. [1]"calling about your housing problem"

These appear to be automated with an AI voice calling itself Sarah. I haven't been far enough down the scam but I assume it wants to collect info about any issues you do have which it will use to sell you a discount home improvement survey which doesn't exist

I dread to think how much misery they could cause if they obtained a list of phone numbers of vulnerable people who are in debt to their council / housing association / etc. It's pretty worrying

[1] https://www.unknownphone.com/phone/03301748875

Re: One has to ask whether councils are specifically targeted in advance

Captain Hogwash

Possibly. It depends who's behind the attack. If I was a criminal opportunist then I'd sneak in wherever I saw an opening. If I was the kind of aggressive nation state who liked to try and interfere in another country's elections then I'd definitely be targeting councils in order to disrupt services, cost money and sow much dissatisfaction among the populace. I understand it's known as hybrid warfare.

We're stuffed

tmTM

but we're not sure how badly.

Check back later for more bad news.

Managed Service Success Story stabalising the home Office's digital applications

t245t

> .. officials still trying to 'identify the nature of the incident'

[1]Open Leicester - IT Services - Information

[2]Managed Service Success Story | stabalising the Home Office's digital applications

[1] https://data.leicester.gov.uk/explore/dataset/it-services-information/table/

[2] https://www.bjss.com/our-work/stabilising-the-home-offices-digital-applications

Ah, the good old UK public sector!

Anonymous Coward

The natural home of incompetent IT staff who can't get a proper job in IT and senior council manglers on huge salaries who couldnt organise a day out for alcoholics in brewery where the bottles are already open.

Re: Ah, the good old UK public sector!

Anonymous Coward

I was contacted about a job at a London council recently doing M365 migration. I have 25 years of AD and Exchange, 10 of 365 and many successful migrations under the belt, but at the salary on offer of £45-50k they're not going to get the best.

Re: Ah, the good old UK public sector!

Little Mouse

re " incompetent IT staff ", etc.

Been there - done that. It's far more nuanced than just Idiots-work-for-the-council. It's basically a Kafka-nightmare in miniature, played out by the characters from Gormenghast.

The staffers are not typically incompetent at all. Not necessarily the top 10%, but certainly more than capable of keeping the IT lights on.

It's the layers and layers of middle management who bog everything down. That's where the "couldn't get a proper job in the real world" individuals are to be found. Too many decisions made at that level are self-serving and fly in the interests of the tax-payer.

Add to that the senior management, who, like CEOs everywhere, spunk too much money on their pet vanity project, but then leave before it gets finished, only to get replaced by a looky-likey clone with another totally different vision that requires a complete U-turn.

And then you have the tendering and procurement processes that effectively guarantee that all promising and well-intentioned initiatives get compromised to the point of being unrecognisable.

Anonymous Coward

When I worked at a council one of the staffers trying to set up a website for their service wanted to skip the security reviews - "after all, we're just a little council, who'd want to attack us". I reminded them that very recently a council had had their web server hacked and someone had started their own site with unsavoury illegal images being served from a council domain. I was in the middle of repainting our hallway and the colour reminded me of one of the lighter shades on the Dulux colour chart.

Oh, all is well, then

Pascal Monett

" Leicester City Council has a good reputation for information governance, so I have some faith that the damage done in terms of sensitive data will be quite limited "

Yeah, well we're going to find out just how "limited" the damage was. Not that I wish them to languish for weeks, it's just that I doubt that their reputation is enough to get them back on their feet next week.

I don't think 'It's better than hurling yourself into a meat grinder'
is a good rationale for doing something.
-- Andrew Suffield in
<20030905221055.GA22354@doc.ic.ac.uk> on debian-devel