BBC, BA and Boots issued with ultimatum by cyber gang Clopon June 7, 2023 at 12:19 am

- Advertisement -
- Advertisement -
- Advertisement -
- Advertisement -

They say personal details of 100,000 staff at the BBC, British Airways and Boots will be published if employers do not get in touch.

BBC Broadcasting HouseImage source, Reuters

A prolific cyber crime gang thought to be based in Russia has issued an ultimatum to victims of a hack that has hit organisations around the world.

The Clop group posted a notice on the dark web warning those affected by the MOVEit hack to email them before 14 June or stolen data will be published.

More than 100,000 staff at the BBC, British Airways and Boots have been told payroll data may have been taken.

Employers are being urged not to pay up if the hackers demand a ransom.

Cyber security research previously suggested Clop could be responsible for the hack which was first announced last week.

The criminals found a way to break into a piece of popular business software called MOVEit and were then able to use that access to get into the databases of potentially hundreds of other companies.

Analysts at Microsoft said on Monday they believed Clop was to blame, based on the techniques used in the hack.

It has now been confirmed in a long blog post written in broken English.

The post, seen by the BBC, reads: “This is announcement to educate companies who use Progress MOVEit product that chance is that we download a lot of your data as part of exceptional exploit.”

The post goes on to urge victim organisations to send an email to the gang to begin a negotiation on the crew’s darknet portal.

This is an unusual tactic as normally ransom demands are emailed to victim organisations by the hackers, but here they are demanding that victims get in touch. This could be because Clop itself can’t keep up with the scale of the hack which is still being processed around the world.

MOVEit is supplied by Progress Software in the US for many businesses to securely move files around company systems. Payroll services provider Zellis, which is based in the UK, was one of its users.

Zellis has confirmed that eight organisations have had data stolen as a result – including home addresses, national insurance numbers and, in some cases, bank details.

So far the following have all said that they may have had data stolen:

  • BBC
  • British Airways
  • Aer Lingus
  • Boots
  • Nova Scotia Government
  • The University of Rochester

Advice from experts is for individuals not to panic, and for organisations to carry out security checks issued by authorities like the Cyber Security and Infrastructure Authority in the US.

Clop claims on its leak site that it has deleted any data from government, city or police services.

“Do not worry, we erased your data you do not need to contact us. We have no interest to expose such information,” it reads.

However, researchers say the criminals are not to be trusted.

“Clop’s claim to have deleted information relating to public sector organisations should be taken with a pinch of salt. If the information has monetary value or could be used for phishing, it’s unlikely that they will simply have disposed it,” said Brett Callow, threat researcher from Emsisoft.

Cyber security experts have long tracked the exploits of Clop, which is thought to be based in Russia as it mainly operates on Russian speaking forums.

Russia has long been accused of being a safe haven to ransomware gangs – which it denies.

However, Clop runs as a “ransomware as a service” group, which means hackers can rent their tools to carry out attacks from anywhere.

In 2021, alleged Clop hackers were arrested in Ukraine in a joint operation between Ukraine, US and South Korea.

At the time, authorities claimed to have taken down the group which they said was responsible for extorting $500m from victims around the world.

But Clop has continued to be a persistent threat.

- Advertisement -

Discover

Sponsor

Latest

Andrew Bridgen threatens to sue Matt Hancock in Covid vaccine rowon January 26, 2023 at 4:39 pm

MP Andrew Bridgen claims he was libelled, but the former health secretary is standing by his comments.Image source, ReutersAndrew Bridgen is threatening to sue...

Woman attacked by Babes in Wood killer wants to be heardon December 1, 2022 at 4:40 pm

Rachael Watts was attacked as a girl and left for dead by Babes in the Wood killer Russell Bishop.A woman who at age seven...

Covid-19: World’s first human trials given green light in UKon February 17, 2021 at 10:22 am

Healthy, young volunteers are being recruited for the approved study, which will start shortly.image copyrightGetty ImagesHealthy, young volunteers will be infected with coronavirus to...

Myanmar coup: ‘Dozens killed’ in military crackdown in Bagoon April 10, 2021 at 10:12 pm

Activists say more than 80 people were killed in the city of Bago in protests against the military coup.image copyrightReutersMore than 80 people have...

Manston migrant’s death may have been caused by diphtheria – Home Officeon November 26, 2022 at 11:38 am

The centre was cleared of people last week after reports of overcrowding and disease.Image source, PA MediaBy Chris GilesBBC NewsThe death of a migrant...