ANNOUNCEMENT : ALL OF ROYAL MAIL'S EMPLOYMENT POLICIES (AGREEMENTS) AT A GLANCE (Updated 2021)... HERE

ANNOUNCEMENT : PLEASE BE AWARE WE ARE NOT ON FACEBOOK AT ALL!

The Royal Mail boss takes on MPs' questions about a Russian ransomware attack and Strikes

Latest Royal Mail and CWU news.This is an open forum.
TrueBlueTerrier
FORUM ADMINISTRATOR
Posts: 72657
Joined: 30 Dec 2006, 10:29
Gender: Male
Location: On my couch

The Royal Mail boss takes on MPs' questions about a Russian ransomware attack and Strikes

Post by TrueBlueTerrier »

https://canadatoday.news/ca/the-royal-m ... ck-226645/

The Chief Executive of Royal Mail faces questions from MPs over the Russia-linked ransomware attack that has halted international deliveries this week.

Royal Mail chief executive Simon Thompson will be questioned about Tuesday’s cyberattack when he appears before the Commons’ Business Select Committee.

Committee members are understood to be discussing Royal Mail’s response to the cyberattack at the evidence hearing on Tuesday 17 January.

A Royal Mail spokesman said: “Royal Mail has been the subject of a cyber incident affecting our international export service. We are focused on restoring this service as soon as possible.”

MPs are due to question Mr Thompson on his company’s handling of CWU union strikes, as well as CWU general secretary Dave Ward and Post chief Nick Read.

Last week Royal Mail was forced to suspend all outbound international mail after machines used to print customs slips were disabled by Russia-linked cybercriminal gang Lockbit.

Lockbit’s attackers used ransomware, malicious software that encrypts important computer files before the gang demands payment to unlock them again.

The software also reportedly took over printers at Royal Mail’s international sorting offices and “squirted” ransom notes out of them.

Cybersecurity industry sources warned that while Lockbit is known to be of Russian origin, it is unknown if a stolen copy of the gang’s ransomware was deployed by competing hackers.

Peter McKenzie, Director of Incident Response at cybersecurity firm Sophos, said: “In this attack, it appears that the information on the ransom note that the attacker provides to the victim directs them to the genuine Lockbit site and communication method.

“This would suggest it was done by Lockbit, but for now it appears Lockbit has denied it was them.”

Royal Mail is classified by the government as Critical National Infrastructure (CNI). The criminals behind Lockbit have previously said they avoid attacking CNI, in what experts say is an attempt to avoid the attention of western cybersecurity agencies.

The National Cyber ​​Security Centre, a division of GCHQ, is helping Royal Mail repair the damage caused by the hackers.

Lockbit has threatened to release data stolen from Royal Mail, although at the time of writing it is unclear what information the criminals obtained.
All post by me in Green are Admin Posts.
Any post in any other colour is my own responsibility.
If you like a news story I posted please click the link to show support Any news stories you can't post - PM me with a link
My sharing of news articles should not be interpreted as an endorsement or condemnation of any particular viewpoint or the issues presented. I share them solely for informational purposes.
olilew
Posts: 594
Joined: 19 May 2010, 22:04
Gender: Male

Re: The Royal Mail boss takes on MPs' questions about a Russian ransomware attack

Post by olilew »

Now who do we know with strong Russian links......?
"Just take it out and see how you go......."
derricksmyth
Posts: 353
Joined: 13 Sep 2012, 17:58
Gender: Male

Re: The Royal Mail boss takes on MPs' questions about a Russian ransomware attack

Post by derricksmyth »

olilew wrote:
14 Jan 2023, 18:54
Now who do we know with strong Russian links......?
A certain Sphinx ???
Eduardo
Posts: 182
Joined: 14 Sep 2016, 08:27
Gender: Male

Re: The Royal Mail boss takes on MPs' questions about a Russian ransomware attack

Post by Eduardo »

Maybe some of that £550 million pounds paid out to the boys club should have been spent on beefing up security of critical IT systems.

Security is more than just checking people's pockets when they leave site. Heads should roll over this one. 😠
Under Siege
ConeHater
MAIL CENTRES/PROCESSING
Posts: 1184
Joined: 25 Sep 2020, 12:37
Gender: Male

Re: The Royal Mail boss takes on MPs' questions about a Russian ransomware attack

Post by ConeHater »

Just spent several thousand on new printers for gatehouses at NDC, despite them being able to cope without a printed bay card being given to every driver passing through for the last 2+ years. They aren’t compatible with the system, if they can’t get that right what hope is there for everything else ! ? !
Eduardo
Posts: 182
Joined: 14 Sep 2016, 08:27
Gender: Male

Re: The Royal Mail boss takes on MPs' questions about a Russian ransomware attack

Post by Eduardo »

There must be some proper incompetent people at higher levels within RM and instead of rooting out these major fvckups all they seem to do is attack us worker Bees, all the time.
Under Siege
guardianangel
Posts: 1828
Joined: 21 Feb 2020, 19:40
Gender: Male

Re: The Royal Mail boss takes on MPs' questions about a Russian ransomware attack

Post by guardianangel »

Important national infrastructure ,dont make me laugh if Thompson gets his way it will all be gone anyway,or is that his plan,the government need to step in and nationalise it now or face a country without any communication with its people,lets be honest no one trusts that the media tells any truth.
pieoftheday
Posts: 1834
Joined: 11 Mar 2010, 16:43
Gender: Male

Re: The Royal Mail boss takes on MPs' questions about a Russian ransomware attack

Post by pieoftheday »

Eduardo wrote:
14 Jan 2023, 20:23
Maybe some of that £550 million pounds paid out to the boys club should have been spent on beefing up security of critical IT systems.

Security is more than just checking people's pockets when they leave site. Heads should roll over this one. 😠
Do you have your pockets checked when leaving at your office? Iv not heard of that happening in RM
WalkerX
Posts: 422
Joined: 20 Feb 2021, 22:31
Gender: Male

Re: The Royal Mail boss takes on MPs' questions about a Russian ransomware attack

Post by WalkerX »

guardianangel wrote:
15 Jan 2023, 08:29
Important national infrastructure ,dont make me laugh if Thompson gets his way it will all be gone anyway,or is that his plan,the government need to step in and nationalise it now or face a country without any communication with its people,lets be honest no one trusts that the media tells any truth.
:Applause :Applause :Applause
pinstripe
Posts: 2472
Joined: 25 May 2007, 16:42
Gender: Male
Location: 2 left turns from reality

Re: The Royal Mail boss takes on MPs' questions about a Russian ransomware attack

Post by pinstripe »

pieoftheday wrote:
15 Jan 2023, 11:11
Eduardo wrote:
14 Jan 2023, 20:23
Maybe some of that £550 million pounds paid out to the boys club should have been spent on beefing up security of critical IT systems.

Security is more than just checking people's pockets when they leave site. Heads should roll over this one. 😠
Do you have your pockets checked when leaving at your office? Iv not heard of that happening in RM
Isn’t that how they catch the thieves? I’m sure I read that the IB, when concluding an investigation would ‘plant a target package’ and wait for the suspect to steal it. What about the bag and locker checks from years gone by?
Eduardo
Posts: 182
Joined: 14 Sep 2016, 08:27
Gender: Male

Re: The Royal Mail boss takes on MPs' questions about a Russian ransomware attack

Post by Eduardo »

We have from time to time been subject to the randomiser, or sodomiser as we like to call it.

It's a little box with a button and management backed up by one security guard will ask staff to press the button on our way out the building.
If your lucky enough to get the random light come on you are then asked to go into a small room and empty your pockets.

This happened for a while until people realised they didn't have to press the button and so now if we are approached by the sodomiser we simply walk the other way and nothing seems to get done about it.

As far as IB goes I guess they're still in action but I haven't heard about anybody being ensnared lately.
As far as locker checks I've not heard of that happening for ages.
Under Siege
NPC00030300
Posts: 10
Joined: 08 Sep 2022, 02:47
Gender: Male

Re: The Royal Mail boss takes on MPs' questions about a Russian ransomware attack

Post by NPC00030300 »

The system is called PCS (Production control system) it was built by Siemens in or around the year 2001 so it’s old and probably working on Windows 2000 so subject to cyber threats and vulnerabilities. The ransom note was printed out on all PCS printers at HWDC and other sites which have PCS installed . The backup was also infected with the lockbit 3.0 ransomware so it looks like export international will be down for a minimum of at least 4 weeks whilst Siemens rebuild the whole system , in the meantime not a dickie bird from Simon Thompson whilst RM lose customers to the competition . Something is afoot .
Lewis123
Posts: 10
Joined: 27 Apr 2015, 17:24
Gender: Male

Re: The Royal Mail boss takes on MPs' questions about a Russian ransomware attack

Post by Lewis123 »

Regarding the original post, you can watch live as Simon Thompson, David Ward & Andy Furey give their oral evidence this morning to the Business, Energy and Industrial Strategy Committee, starts at 9:15:-

https://committees.parliament.uk/event/ ... e-session/
SpacePhoenix
MAIL CENTRES/PROCESSING
Posts: 12134
Joined: 12 Nov 2008, 17:03
Gender: Male

Re: The Royal Mail boss takes on MPs' questions about a Russian ransomware attack

Post by SpacePhoenix »

NPC00030300 wrote:
17 Jan 2023, 02:25
The backup was also infected with the lockbit 3.0 ransomware
That's a major screw up in itself. There should have been a backup copy of the software stored on a medium that's strictly read-only
toucan
MDEC
Posts: 4
Joined: 07 Dec 2014, 08:05
Gender: Male

Re: The Royal Mail boss takes on MPs' questions about a Russian ransomware attack

Post by toucan »

NPC00030300 wrote:
17 Jan 2023, 02:25
The system is called PCS (Production control system) it was built by Siemens in or around the year 2001 so it’s old and probably working on Windows 2000 so subject to cyber threats and vulnerabilities. The ransom note was printed out on all PCS printers at HWDC and other sites which have PCS installed . The backup was also infected with the lockbit 3.0 ransomware so it looks like export international will be down for a minimum of at least 4 weeks whilst Siemens rebuild the whole system , in the meantime not a dickie bird from Simon Thompson whilst RM lose customers to the competition . Something is afoot .
I thought there was a newer system for CN22/CN23 data capture or is that only for import items.