Royal Mail ransomware attackers threaten to publish stolen data

Postal service has been unable to send letters and parcels overseas since Wednesday due to hacking

Royal Mail has been hit by a ransomware attack by a criminal group, which has threatened to publish the stolen information online.

The postal service has received a ransom note purporting to be from LockBit, a hacker group widely thought to have close links to Russia.

Royal Mail revealed that it had been hit by a “cyber incident” on Wednesday, and said it was unable to send parcels or letters abroad. The company asked customers to refrain from submitting new items for international delivery, although domestic services and imports were unaffected.

Ransomware attackers exploit gaps in organisations’ security to install their own software and encrypt files so they are unusable. They then ask for a ransom, often in cryptocurrency, which can be harder to trace because it is not reliant on the banking system.

Printers at a Royal Mail distribution site near Belfast in Northern Ireland started printing ransom notes, according to the Telegraph. The note said: “Lockbit Black Ransomware. Your data are stolen and encrypted.”

Online security researchers posted photographs purporting to show the ransom note on social media.

Royal Mail has reported the incident to the UK’s government-run National Cyber Security Centre, the National Crime Agency and the Information Commissioner’s Office. It has not publicly revealed any details regarding the nature of the incident.

Organisations that have been hit by ransomware range from the National Health Service to businesses of almost every size. The Guardian was hit by a ransomware attack last month.

Andrew Brandt, a principal researcher at Sophos, a cyber security company, said the Lockbit ransomware software is thought to have been developed by criminals mainly from Russia and other former Soviet republics. It gives criminal affiliates access to the software in exchange for a cut of any ransoms.

Ransom demands against organisations listed on a publicly available website ranged from around $200,000 (£165,000) to almost $1.5m, Brandt said.

“Something Royal Mail is going to have to consider is whether or not they are going to pay a ransom,” Brandt said. “I’m a bit of a purist and [say] they should never pay these people anything.”

However, it can be a “delicate balance” for organisations depending on the severity of the attack and what data has been taken, he said.

Royal Mail has not indicated when it expects to be able to resume international deliveries. The company has already been heavily affected by workers’ recent strike action, and a new ballot is planned this month to approve further industrial action in the dispute over pay and changes to working conditions.

Smaller exporting companies are thought to be the most affected by the delays. Tina McKenzie, policy chair of the Federation of Small Businesses, said companies had already been through “a tumultuous Christmas period after postal strikes, and this latest cyber incident is the last thing they need”.

It is “an already challenging time” for smaller exporters, she said. “In the context of global supply chain disruption, rising shipping costs and more paperwork, this creates a very worrying picture.”

Royal Mail declined to comment further.

Contributor

Jasper Jolly

The GuardianTramp

Related Content

Article image
Royal Mail overseas post badly disrupted after cyber incident
Company asks customers not to send international parcels and letters as it informs security authorities

Jasper Jolly

11, Jan, 2023 @3:53 PM

Article image
Post Office strikes to overlap with Royal Mail and BT industrial action
CWU’s Andy Furey says issues at stake ‘are all remarkably similar’ across separate trade disputes

Joe Middleton

12, Aug, 2022 @3:48 PM

Article image
Royal Mail pay offer is ‘declaration of war on posties’, says union
CWU says firm’s offer of below-inflation pay rise and changes to work practices are unacceptable

Joanna Partridge

31, Oct, 2022 @4:17 PM

Article image
Currys drops Royal Mail ‘for now’ as strikes threaten deliveries
Retailer says its responsibility is to ensure customers ‘get hold of their technology’ for Christmas

Rupert Jones

04, Dec, 2022 @12:25 PM

Article image
What is LockBit ransomware and how does it operate?
Name of malware and criminal group behind it, LockBit has been blamed for attack on Royal Mail

Dan Milmo Global technology editor

13, Jan, 2023 @3:13 PM

Article image
Royal Mail bosses threaten to declare insolvency as pay talks near collapse
Talks with union over pay and working practices are on brink of collapse and special administration has been explored

Nils Pratley

27, Mar, 2023 @6:10 PM

Article image
How the growing Russian ransomware threat is costing companies dear
With KP Snacks the latest cyber-attack victim, firms must learn to defend themselves against a mounting menace

Rob Davies and Dan Milmo

05, Feb, 2022 @10:00 AM

Article image
British Airways data breach: what to do if you have been affected
From which payments have been compromised to future bookings and compensation

Staff and agencies

07, Sep, 2018 @7:55 AM

Article image
JD Sports hit by cyber-attack that leaked 10m customers’ data
Retail group says incident affected shoppers at JD, Size?, Millets, Blacks, Scotts and Millets Sport brands

Mark Sweney

30, Jan, 2023 @11:06 AM

Article image
Unions threaten battle with Royal Mail over pension scheme change
Communication Workers Union says they will explore every avenue to defend postal workers’ current pension plan

Patrick Collinson and Sarah Butler

11, Aug, 2016 @6:00 PM