News: 1712056514

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

INC Ransom claims to be behind 'cyber incident' at UK city council

(2024/04/02)


The cyber skids at INC Ransom are claiming responsbility for the ongoing cybersecurity incident at Leicester City Council, according to a post caught by eagle-eyed infosec watchers.

A post made to INC Ransom's leak blog in the late hours of April 1 mentioned Leicester City Council as a victim of the ransomware group – the first indication that the local authority's IT incident involves an established cybercrime gang.

The note also mentioned that the attackers claimed to have stolen 3 TB worth of council data, before it was deleted soon after going live.

[1]

Posting a victim to a leak site and swiftly removing it is a process known as "flashing," and is commonly used to get a response out of leadership teams that may have gone silent during the ransom negotiation phase.

[2]

[3]

Leicester City Council's most recent incident update came on March 28, the last working day before the UK's long bank holiday weekend. Based on how its recovery efforts are going, it's likely that it won't have paid a ransom, and the [4]latest flashing by INC Ransom is a last-gasp attempt to extort the council.

The Register approached the local authority and INC Ransom for more details but neither immediately responded.

[5]

Nearly a month after the [6]council's widespread system shutdown on March 7, which was only supposed to last for a few days, it said most systems and service portals are back online.

Residents' online services for waste and recycling, schooling, birth registrations, social housing, planning, and parking were reinstated late last week.

Council-run recreation centers are now back open as usual, and computer and Wi-Fi services at public libraries were also brought back online. Council staff have regained access to emails and phone lines too.

[7]

"We're pleased that most of our online service portals and customer service lines are now up and running again," said Andrew Shilliam, director of corporate services at Leicester City Council.

"Next week, I hope to report that the remaining phone lines have been restored and that we're making progress on dealing with a backlog of emails and requests.

"We're very sorry for the inconvenience caused by the cyber incident and want to thank people for their patience while we restore our systems. I'd also like to thank all of our partners in the city who have supported us as we deal with this incident."

The council still refuses to comment on whether any data was compromised during the epsiode due to ongoing criminal investigations.

[8]AT&T admits massive 70M+ mid-March customer data dump is real though old

[9]Malicious SSH backdoor sneaks into xz, Linux world's data compression library

[10]INC Ransom claims responsibility for attack on NHS Scotland

[11]Miscreants are exploiting enterprise tech zero days more and more, Google warns

INC Ransom is known for operating on a [12]double extortion model, so if it was indeed behind the attack, it's likely that at least some data was stolen before affiliates deployed the locker.

Looking at recent attacks claimed by the group, the nature of the data it targets can be highly sensitive.

INC stain on the UK

INC Ransom also recently claimed responsibility for an attack on NHS Dumfries and Galloway, one of 14 regional National Health Service branches of Scotland.

After posting "NHS Scotland" last week, El Reg [13]confirmed the attack was actually contained to just the Dumfries and Galloway branch, which had reported a cybersecurity incident weeks prior.

The criminals also allegedly stole 3 TB worth of data from the healthcare organization. A quick browse of the taster data dump it posted revealed sensitive data throughout, including medical test results tied to patients' real names and home addresses.

If the attackers had access to information typically assumed to be held only by official sources, such as Leicester City Council itself, the potential for attackers to use that data in convincing phishing attacks is high.

Most UK residents would assume that their unique council tax number, for example, is only known by the council. Most constituencies usually include the number in official correspondence to show the communication was meant for the intended recipient.

If attackers had access to this information, as well as full names, email addresses, and other data types, they could feasibly target residents with convincing campaigns that fraudulently request urgent "council tax" payments. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZgwrnLg61A0WmtQzJFNbWAAAAEo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgwrnLg61A0WmtQzJFNbWAAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZgwrnLg61A0WmtQzJFNbWAAAAEo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://cyberplace.social/@GossiTheDog/112198087610896156

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgwrnLg61A0WmtQzJFNbWAAAAEo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2024/03/21/shock_uk_councils_recovery_from/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZgwrnLg61A0WmtQzJFNbWAAAAEo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2024/04/01/att_admits_massive_70m_midmarch/

[9] https://www.theregister.com/2024/03/29/malicious_backdoor_xz/

[10] https://www.theregister.com/2024/03/28/nhs_scotland_cyberattack/

[11] https://www.theregister.com/2024/03/27/surge_in_enterprise_zero_days/

[12] https://www.theregister.com/2023/10/02/feds_ransomware_report/

[13] https://www.theregister.com/2024/03/28/nhs_scotland_cyberattack/

[14] https://whitepapers.theregister.com/



Interesting

Will Godfrey

If they did refuse to pay, good for them.

Hope they are also looking at ways to secure against future attacks. Those bastards are likely to try a revenge attack.

cyber skids

Neil Barnes

You misspelled 'shits'.

Council centers

Jan 0

If you're going to mangle the spelling, do it properly:

"Kownsill-run wreckreayshun senters", surely?

The real question

Mike 137

What isn't clear (and probably never will be) is whether the council was actively targeted or merely feel victim of a scatter gun attack because its "security" wasn't adequate. I strongly suspect the latter, as was the case when the UK NHS fell foul of NotPetya. The biggest mistake we currently make is to assume that security is a technology problem. Almost all the big breaches that have been sufficiently reported to judge have been fundamentally down to sloppy management and poor decision-making. Out of interest, that's also been the root cause of the large number of near misses (and indeed some accidents) involving Western nuclear weaponry 1 , so it's not an IT problem -- it's a cultural one.

1: Eric Schlosser, Command and Control, USA, the Penguin Press 2013 [ISBN 987-1-59420-227-8]

.

The boy stood on the burning deck,
Eating peanuts by the peck.
His father called him, but he could not go,
For he loved those peanuts so.