News: 1711021072

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK council won't say whether two-week 'cyber incident' impacted resident data

(2024/03/21)


Leicester City Council continues to battle a suspected ransomware attack while keeping schtum about the key details.

Progress updates posted to its website are still referring to the widespread outage as a "cyber incident," failing to even confirm whether data has been compromised or whether ransomware is involved, which some experts [1]insist to be the case .

The Register has repeatedly asked for a confirmation or denial of ransomware's involvement from the council, but after ignoring us for ten days it finally replied today, only to say it still couldn't share anything beyond official statements.

[2]

The UK's National Cyber Security Centre (NCSC), which has been informed of the situation at the council, told us it continues to work with local officials.

[3]

[4]

Leicester says in its statement a criminal investigation into the "cyber incident" remains ongoing, and as such the key details surrounding it all can't be revealed.

"The UK government really needs a radical rethink on [5]ransomware [in my honest opinion]," said security expert Kevin Beaumont at the time the incident was first disclosed.

[6]

"If you can't even say the word, you can't manage the problem."

Eerke Boiten, professor of cybersecurity at De Montfort University Leicester, [7]said following the initial disclosure of the incident that the council has a good reputation when it comes to information governance and that he had "some faith" that any damage to sensitive data would be limited.

Earlier this week, the council extended its estimated time to recovery from the few short days at the time of disclosure, to "at least two weeks."

[8]

Richard Sword, strategic director of city development and neighborhood services at the council, said this week that "a good majority of staff are also back on the network," but its phone lines still require some work before they're back online.

[9]Crypto scams more costly to the US than ransomware, Feds say

[10]More than 133,000 Fortinet appliances still vulnerable to month-old critical bug

[11]Cyberattack gifts esports pros with cheats, forcing Apex Legends to postpone tournament

[12]As if working at Helldesk weren't bad enough, IT helpers now targeted by cybercrims

Libraries and community centers remain open, and waste services continue to operate as normal, but access to public computers, [13]Wi-Fi , and printing is down.

Some residents have had issues with the council being unable to collect their direct debits. The council will be writing to the affected individuals to inform them of the new date of collection.

Standing orders aren't affected and residents can still pay fixed penalty notices, which are issued for low-level crimes such as littering and not paying for car parking.

Emergency telephone lines have been established for critical services such as child protection services, homelessness, and housing repairs while the recovery efforts continue.

"We are making good progress with the recovery of our systems and are now in the process of switching them back online, with housing, adult and children's social care, and revenues and benefits being prioritized for this week," said Sword.

Residents were urged to only contact the council in the event of an emergency. They've also been assured that its website is still safe to use, and that they may trust emails coming from council sources, including any [14]attachments that come with them.

"Many people in Leicester will be frustrated by these ongoing issues, but I'd like to reassure them that we're working as quickly as possible to get things back to normal," said Sword earlier this week.

"I'd also like to apologise for the disruption and thank people for their continued patience and understanding as we work to resolve these outstanding issues." ®

Get our [15]Tech Resources



[1] https://cyberplace.social/@GossiTheDog/112127226601378456

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zfxnpn@9QQDde10zCjzz6wAAAE4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zfxnpn@9QQDde10zCjzz6wAAAE4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zfxnpn@9QQDde10zCjzz6wAAAE4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2024/01/18/ransomware_attacks_hospitalize_security_pros/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zfxnpn@9QQDde10zCjzz6wAAAE4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2024/03/12/leicester_city_council_stays_shtum/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zfxnpn@9QQDde10zCjzz6wAAAE4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2024/03/19/crypto_scams_cost/

[10] https://www.theregister.com/2024/03/18/more_than_133000_fortinet_appliances/

[11] https://www.theregister.com/2024/03/18/cyberattack_gifts_esports_pros_with/

[12] https://www.theregister.com/2024/03/15/it_helpdeskers_under_increased_threat/

[13] https://www.theregister.com/2023/09/25/wifi_7_ee_qualcomm/

[14] https://forums.theregister.com/forum/all/2023/04/06/microsoft_outlook_onedrive_storage/

[15] https://whitepapers.theregister.com/



Doctor Syntax

If they're saying nothing things must be really so bad that they've even lost the scripts to "Your security is important to us, only a small number of people etc".

Ah, trust...

Flak

So hard to gain, so easy to lose:

"[the council's] website is still safe to use, and that they [users] may trust emails coming from council sources, including any attachments that come with them."

Right...

Pilots have an axiom for emergencies:

JimC

Aviate, Navigate, Communicate.

Where do you suppose talking to the press comes on that list?

Re: Pilots have an axiom for emergencies:

Anonymous Coward

That'll be in the communicate section, comes after the first two. I suspect they're struggling to fly the plane, and won't pull the recovery chute as that removes all other options

Navigating a "cyber incident" (let's be honest, it's proably ransomware and they're probably fucked) is hard, I know, I've done it.

I suspect those on the ground haven't told those at the top how fucked they are yet...

Re: Pilots have an axiom for emergencies:

Doctor Syntax

"I suspect those on the ground haven't told those at the top how fucked they are yet."

They must have tried. But there's none so deaf as those who won't listen.

Re: Pilots have an axiom for emergencies:

Anonymous Coward

I've done a full - take half the servers in the company down - Ransomware attack.

Now my company doesn't have the finest IT dept on the planet but there's nothing like a crisis to bring everyone together. Had our core back within 3 days and the long tail of random shizzle back within 2 weeks.

Helped by paying the ransom - which I'd tend to advise unless your running active-active or hot backups and have some way of firewalling the secondary/backup from the ransomware.

Thing about ransomware its clever and insidious and can be running for a significant period of time encrypting random files until it hits a critical one. So your backups get "corrupted" to.

As does your OS.

So you are looking at server wiping, Data Loss and probably manual recovery -- if you are lucky. Much cleaner to decrypt in place with the key - if the ransom folks are remotely trustworthy. And they generally are on this. Because they want to get paid every time.

We were able to crash push Jenkins + a Ransomware killer + a decrypter out to every machine in the estate and essentially run massively parallel decryption. Hardest bit was getting Jenkins on the 10% of awkward servers who refused the push or were too full of encrypted files to receive anything.

BZZZTTT FAIL

Gordon 10

BOFH Cattle prod of doom for you.

IT Estate is not a plane.

ITIL (or any other framework worth its name) has an Incident Management process that includes a role for Incident Comms, that should cover all your user stakeholders including the general public .... and for which the press is a valid comms channel.

Your ERP goes down and you're not giving the CFO hourly updates on the expected recovery time and process - your IT dept is a clown car.

Its been 20 years since I've done IM. This is basic stuff.

ffRewind

"...residents can still pay fixed penalty notices, which are issued for low-level crimes such as littering and not paying for car parking."

Great news as this sounds like the perfect time to be handing over credit card information.

Graham Cobb

I'd be less worried about that (credit card data gets stolen all the time - I presume the CC companies are used to dealing with it) than that the payment you've just made disappears when someone finds a more recent backup tape to load during the process of trying to restore services.

Handlebars

You probably put your card details into a separate page run by the payment processor. That's how it works where I live.

Fifteen men on a dead man's chest,
Yo-ho-ho and a bottle of rum!
Drink and the devil had done for the rest,
Yo-ho-ho and a bottle of rum!
-- Stevenson, "Treasure Island"