Ransomware gang did steal residents' confidential data, UK city council admits
- Reference: 1712227780
- News link: https://www.theregister.co.uk/2024/04/04/ransomware_gang_did_in_fact/
- Source link:
The attack began nearly a month ago on March 7 and since then, the council has continually refused to say whether ransomware was involved or if data was compromised.
That all changed yesterday when INC Ransom, which [1]mentioned the council attack earlier in the week, hinting at its role in the incident, leaked a cache of documents that appeared to be sourced from council servers.
[2]
"We have downloaded about 3 TB of private information," the gang's website claims, alongside what it calls a "proof pack" – a 32-file snippet of the data it claims to have stolen.
[3]
[4]
The leaked files include scans of residents' identification documents such as passports and driving licenses, bank statements, and various official council forms for matters regarding rent, social housing, and more.
Within hours of the leak, Richard Sword, Leicester City Council's strategic director of city developments and neighborhoods, released an updated statement acknowledging that fact.
[5]
"We have today been made aware that a small number of documents held on our servers have been published by a known ransomware group," said Sword.
"This group is known to have attacked a number of government, education, and healthcare organizations.
"The breach of confidential information is a very serious matter and its publication is a criminal act. We are in the process of trying to contact all of those affected by this breach, and have also notified the [6]Information Commissioner .
[7]
"We realize this will cause anxiety for those affected, and want to apologize for any distress caused."
Sword went on to say that the council, at this current stage, couldn't say if any other files had been stolen, but "it is very possible" that the criminals do indeed have more.
The UK's National Cyber Security Centre (NCSC) and the cybercrime team at Leicestershire Police are working together on the criminal case, the nature of which was cited as the reason for so few details coming to light thus far.
Residents have been urged to remain vigilant about any attempts to access their accounts, and of people claiming to have data relating to them. They've also been reassured that engaging with the council and carrying out normal functions like paying council tax bills is safe.
The council has largely recovered from the incident, it confirmed last week, with most of its systems, email access, and phone lines back up, running as normal. Council-run services such as recreation centers and public internet at libraries are also now operational once again.
The attack on Leicester City Council was carried out by the same criminals at INC Ransom who were behind the recent [8]attack at NHS Dumfries and Galloway , a regional healthcare organization in Scotland.
[9]Nearly 1M medical records feared stolen from City of Hope cancer centers
[10]Cyberattack hits Omni Hotels systems, taking out bookings, payments, door locks
[11]INC Ransom claims to be behind 'cyber incident' at UK city council
[12]JetBrains keeps mum on 26 'security problems' fixed after Rapid7 spat
INC Ransom is believed to be one of the beneficiaries of the recent law enforcement efforts to disrupt [13]LockBit and [14]ALPHV/BlackCat , which were until recently the two heavy hitters of the ransomware industry.
Cybersecurity analyst and researcher Dominic Alvieri [15]said three ransomware groups appear to have benefited the most, picking up the affiliates who left LockBit and ALPHV after law enforcement's intervention efforts.
INC Ransom registered 23 new victims in the past month, whereas the other beneficiaries – [16]Medusa and [17]Hunters International – have registered 24 and 18 respectively.
For INC and Medusa, these numbers aren't far off LockBit's when it was arguably at its peak last year. According to the US authorities, LockBit carried out at least 340 attacks in 2023 – an average of around 28 per month. ®
Get our [18]Tech Resources
[1] https://www.theregister.com/2024/04/02/inc_ransom_leicester_council/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zg7OnK7PW82K8pazhEpASQAAAJQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zg7OnK7PW82K8pazhEpASQAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zg7OnK7PW82K8pazhEpASQAAAJQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zg7OnK7PW82K8pazhEpASQAAAJQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2024/03/11/ico_pay_or_ads/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zg7OnK7PW82K8pazhEpASQAAAJQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2024/03/28/nhs_scotland_cyberattack/
[9] https://www.theregister.com/2024/04/03/city_of_hope_data_theft/
[10] https://www.theregister.com/2024/04/03/omni_hotels_it_outage/
[11] https://www.theregister.com/2024/04/02/inc_ransom_leicester_council/
[12] https://www.theregister.com/2024/03/28/jetbrains_fixes_26_security_problems/
[13] https://www.theregister.com/2024/02/20/nca_lockbit_takedown/
[14] https://www.theregister.com/2023/12/19/blackcat_domain_seizure/
[15] https://twitter.com/AlvieriD/status/1775601934738600019
[16] https://www.theregister.com/2023/04/19/medusa_microsoft_data_dump/
[17] https://www.theregister.com/2023/10/25/rebuilt_hive_ransomware_gang_stings/
[18] https://whitepapers.theregister.com/
I am beginning to think . . .
that the Internet is _entirely unfit_ for the purpose of storing _any_ personal information, full stop.
Re: I am beginning to think . . .
It's about time that these people start to understand that air-gapping confidential data might be a good idea.
Re: I am beginning to think . . .
I’ve long ago reached that conclusion … I won’t even apply for my bus pass entitlement on the basis I don't trust the council idiots to safely secure my identification data and photograph.
Now if I could just get the DVLA. to delete my driving licence photo … Oh forgot about the idiots at HMRC & NHS and the Electoral Commission (but as to the latter, I seem to recall its already all gone to some foreign entity with them having been hacked)
My personal data is very important to me, but only post hacking, does security become top priority to these numpties (or was that posterior/bonus covering?)
Horse, door, stable, bolts, shut, me thinks
God help us all if they introduce a mandatory biometric national ID card
Storage
That's why we need government to store all the data about us they possibly can. This way when the foxy data thieves enter the hen house they will be overwhelmed by sheer amount of data, they won't be able to download anything meaningful before the coppers read a headline in a local newspaper that there is an ongoing data thievery, try to ignore it and then under pressure from the public reluctantly come assess the situation. At which point thieves realise they ran out of space and only managed to download 20 years worth of heartbeat rate at 0.001s resolution of one citizen.
Sword, meet Damocles
In the [1]original article , El Reg quoted Eerke Boiten, professor of cybersecurity at De Montfort University Leicester as saying, relating to "anything where personal circumstances get dealt with", that:
...you would expect that such data has extra protection on it so that an attack that hits the main systems doesn't automatically get into the sensitive databases that have extra levels of protection , adding ...Leicester City Council has a good reputation for information governance, so I have some faith that the damage done in terms of sensitive data will be quite limited.
In retrospect, that statement seems quite a hostage to fortune and not entirely the help to the council that was apparently intended.
[1] https://www.theregister.com/2024/03/12/leicester_city_council_stays_shtum/
One has to wonder why they are storing scans of documents they only need to use for verification of identity, once seen and confirmed why the hell are they stored?
The leaked files include scans of residents' identification documents such as passports and driving licenses, bank statements, and various official council forms for matters regarding rent, social housing, and more.
Once the documents have been used to prove identification why are the kept. If they must be kept why are they kept online?
Well, they might be able to get away with burying a king under a car park for a few hundred years, but this was always going to come out in the open fairly quickly.....