Royal Mail Cyber at...
 

  You don't need to be an 'investor' to invest in Singletrack: 6 days left: 95% of target - Find out more

Royal Mail Cyber attack

10 Posts
10 Users
0 Reactions
59 Views
Posts: 7121
Free Member
Topic starter
 

Just tried to price up a parcel to send to the US.. but RM aren't accepting any international parcels.
Looks like RM got hacked last week and still having a major issue.

Anyone know whats going on? Is it being held hostage by the Russians?


 
Posted : 16/01/2023 8:53 am
Posts: 22922
Full Member
 

Is it being held hostage by the Russians?

"Russian based' criminals. Nobody goes so far as to say the Russian state - but these criminals don't target businesses / victims within Russia or in countries Russia considers to be an ally.


 
Posted : 16/01/2023 8:57 am
Posts: 5055
Free Member
 

Bet they said it was a "sophisticated hack", or words to that effect?

AKA it's not that we've poor and/or badly managed controls, just that they're 'World Class' criminals.

FWIW I work in controls assurance in the FS industry...


 
Posted : 16/01/2023 9:05 am
Posts: 22922
Full Member
 

Bet they said it was a “sophisticated hack”,

They've been quite open and said - 'someone opened a dodgy attachment'. Most important thing in all this is to make sure we blame the victim.


 
Posted : 16/01/2023 9:12 am
Posts: 8819
Full Member
 

If they got a system pwned by a dodgy attachment, something was seriously lacking in how they work or how their systems are set up. It would lso not necessarily mean that it was a sophisticated attacker either.

Mind you, it might make it a lot easier fr them to garner sympathy if they say it is a sophisticated attacker and, as attribution is difficult, no one is going to disprove them. Unless they release the IOCs and someone independent knows for sure who it is.


 
Posted : 16/01/2023 9:19 am
Posts: 4656
Full Member
 

“Russian based’ criminals. Nobody goes so far as to say the Russian state – but these criminals don’t target businesses / victims within Russia or in countries Russia considers to be an ally.

to be fair if I was an independent Russian superhacker, I wouldn't poo in my own back yard either. Less liable to be prosecuted or fall out of a window if caught.


 
Posted : 16/01/2023 10:51 am
Posts: 6829
Full Member
 

I saw somewhere that it was down to RM still using Windows 7 which doesn’t surprise me at all - too busy paying out dividends to shareholders than worry about things like investment in business-critical software


 
Posted : 16/01/2023 11:10 am
 mc
Posts: 1190
Free Member
 

It's a major failure on RM's part, that we're now on to day 5, and they've seemingly not managed to restore any international services.


 
Posted : 16/01/2023 3:02 pm
Posts: 5382
Free Member
 

From what I've heard it requires a complete wipe and reinstall of the system.....

Parcelforce is unaffected and you can still send international post through postoffice's using this with a discount they should provide on site.


 
Posted : 16/01/2023 3:11 pm
Posts: 9135
Full Member
 

Given China has also apparently been attacked by this same group, i doubt its anything state sponsored.

More likely criminal gang.

Prior to the war, the Ukraine was known for being a base for these type of criminals.


 
Posted : 16/01/2023 3:45 pm
Posts: 8613
Full Member
 

Without knowing the specifics of the attack I'm not going to criticise the IT security side of things. Absolutely it could turn out to be negligence or poorly implemented security controls or massive under-funding and management not listening to IT about systems they need to put in place etc. But also it could have used a zero day (once they'd got a foot in the door via the phishing attack) and truly immutable backups for your core IT is difficult. If a lot of their core IT systems are now ransomware encrypted that's a painful recovery process in itself, if their backups are encrypted to they're in a whole world of hurt.


 
Posted : 17/01/2023 7:54 am

6 DAYS LEFT
We are currently at 95% of our target!