Security Stop-Press: Cyber Insurance Payouts Triple

Association of British Insurers (ABI) figures show that cyber insurance payouts in the UK have tripled, reaching £197 million in 2024 as businesses face increasingly costly cyber-attacks, particularly from ransomware and malware.

The number of cyber insurance policies has also risen, with 17 per cent more businesses taking out coverage in 2024. However, experts warn that not all claims are guaranteed to be paid. Insurers are tightening requirements, and failure to meet security standards or maintain effective recovery plans may limit payouts.

Businesses must ensure they implement robust cybersecurity measures, including secure backups and effective recovery plans. Cybersecurity should be a core business priority, with regular risk assessments and a proactive security culture to mitigate risks and safeguard against costly attacks.

Security Stop-Press: Ransoms Double as Credential Theft Surges

Average ransomware payments have more than doubled in the past quarter, while stolen credentials are driving a sharp rise in breaches.

Coveware by Veeam reported the average ransom payout in Q2 2025 hit $1.13 million, up 104 per cent on the previous quarter. The median payment also doubled to $400,000, with larger organisations paying out in data exfiltration-only incidents, where files are stolen rather than systems encrypted. Data theft was a factor in 74 per cent of cases.

Criminal groups such as ‘Scattered Spider’, ‘Silent Ransom’ and ‘Shiny Hunters’ are using targeted social engineering to impersonate staff, trick helpdesks, and exploit third-party providers. “Attackers aren’t just after your backups – they’re after your people, your processes, and your data’s reputation,” warned Coveware CEO Bill Siegel.

At the same time, Check Point found credential theft has surged 160 per cent in 2025, now causing one in five breaches. Many businesses take months to revoke exposed logins, giving attackers time to exploit them.

Security experts advise organisations to enforce multi-factor authentication, tighten password policies, and train staff to spot social engineering. Treating stolen credentials and data theft as primary risks is now seen as essential.

Tech Insight : 45% Of MSPs Keep Cash To Pay Off Hackers

A new survey reveals 45 per cent of managed service providers (MSPs) are setting aside cash to pay ransomware demands, as fears over AI-fuelled cybercrime continue to mount.

MSPs Under Pressure as Ransomware Attacks Surge

The finding comes from the CyberSmart MSP Survey 2025, which examined the security posture of 900 MSPs across the UK, Europe, Australia, and New Zealand. According to the report, nearly half of those surveyed now maintain a dedicated pot of money in case they are hit by a ransomware attack, a tactic where cybercriminals encrypt a victim’s data and demand a payment for its return.

Counter To Guidance

This approach appears to run counter to guidance from insurers, governments, and law enforcement agencies, which consistently urge organisations not to pay. However, the growing scale and frequency of attacks, often powered by artificial intelligence, appear to be forcing MSPs to adopt a more pragmatic (if controversial) strategy.

“Organisations shouldn’t rely on ransomware payments; rather, they should partner with organisations that can help proactively secure them,” said Jamie Akhtar, CEO and co-founder of CyberSmart.

Be Prepared

The report’s findings highlight a deepening sense of vulnerability among MSPs, many of which provide outsourced IT and cyber-security services to small and medium-sized enterprises (SMEs). With AI-generated phishing emails, malware, and deepfakes becoming increasingly sophisticated, the pressure to be prepared for the worst has never been higher.

More Breaches, More Budgets, More Confusion

CyberSmart’s research revealed that 69 per cent of MSPs had suffered two or more cyber breaches in the last 12 months, while 47 per cent reported being hit three times or more. These incidents are not just one-off events. For example, many are the result of supply chain vulnerabilities, such as the May 2025 breach where the Dragonforce ransomware group exploited a remote monitoring and management (RMM) tool to compromise multiple MSP clients.

Faced with mounting threats, MSPs are reacting in different ways. For example, 36 per cent now rely on cyber insurance as their primary defence, while 11 per cent (worryingly) have neither cyber insurance nor a ransomware fund in place, leaving them financially and operationally exposed if attacked.

Guidance Not Clear

It seems that part of the problem is that official guidance around ransomware payments remains fragmented and unclear. While governments generally discourage paying ransoms, enforcement is inconsistent outside the public sector. “What your business is advised to do will largely depend on where you’re based and who’s advising you,” CyberSmart noted in its commentary.

This has led to a patchwork of interpretations, with some MSPs feeling they have little choice but to maintain a reserve, despite the moral and strategic risks involved.

UK Government Moves to Ban Ransomware Payments for Critical Services

In July 2025, the UK government announced proposals to ban ransomware payments for public sector bodies and operators of critical national infrastructure (CNI). The measures, introduced by the Home Office following a public consultation, would apply to organisations such as hospitals, councils, schools, and water providers, sectors where operational downtime can endanger lives.

“Ransomware is a predatory crime that puts the public at risk, wrecks livelihoods and threatens the services we depend on,” said Security Minister Dan Jarvis. “We’re determined to smash the cyber criminal business model and protect the services we all rely on.”

Private Businesses Would Need To Notify Government Before Paying

Under the proposals, private businesses would not be banned outright from paying, but would be required to notify the government before doing so. This would enable authorities to offer advice, check for potential sanctions breaches (such as paying Russian-linked gangs), and gather intelligence to disrupt criminal networks.

Cybercrime’s Business Model Under Scrutiny

The rationale behind the payment ban is to undermine the business model of ransomware gangs, which rely on victims caving in quickly to avoid reputational damage, data leaks, or prolonged disruption. However, experts have warned that banning payments, especially only for certain sectors, may not have the desired effect.

“Ransomware is largely an opportunistic crime, and most cyber criminals are not discerning,” said Jamie MacColl, a senior research fellow at the Royal United Services Institute (RUSI). “They’re unlikely to develop a rigorous understanding of UK legislation or how we designate critical infrastructure.”

Others suggest the ban could increase the stakes for victims. “If the best solution is to just turn around and say to the hackers, ‘We’re not giving in to your demands anymore,’ don’t be surprised if they double down,” said Rob Jardin, chief digital officer at NymVPN.

The British Library, one of the most high-profile public victims of ransomware in recent years, chose not to pay after an attack in October 2023 devastated its systems. “We are committed to sharing our experiences to help protect other institutions and build collective resilience,” said Chief Executive Rebecca Lawrence.

AI Attacks Are Changing the Game

Perhaps the most striking shift in this year’s CyberSmart survey is the rise of artificial intelligence as the top concern for MSPs in 2025. AI overtook ransomware itself, with 44 per cent of respondents citing it as their biggest worry, compared to 40 per cent for traditional malware and ransomware threats.

This change reflects a growing trend in how attackers operate. For example, AI tools are now being used to write convincing phishing emails, build more evasive malware, and even create deepfake audio and video to impersonate executives or support social engineering attacks.

In 2024, 67 per cent of MSPs reported falling victim to AI-enabled attacks, a figure expected to rise in 2025 as generative and agent-based AI tools become more widely available to threat actors.

However, many MSPs feel ill-equipped to counter these evolving threats, with a lack of user-friendly, AI-specific defence tools still a key issue. “MSPs are being asked to do more, with fewer tools at their disposal,” the report concludes.

Customer Expectations Are Rising, But So Is Investment

The research also showed that 84 per cent of MSPs now manage their clients’ cybersecurity infrastructure, or both their cybersecurity and broader IT estate. This shift reflects growing client expectations for MSPs to provide end-to-end protection which are the kind of expectations that often come with greater scrutiny.

According to the CyberSmart research, 77 per cent of MSPs said potential customers are now evaluating their cyber credentials more carefully, especially in the procurement stage.

To meet demand, it seems that MSPs are now investing heavily. For example, 81 per cent have increased spend on hiring security specialists, and 78 per cent have upped budgets for cyber defence tools, training, and client services. Compliance is also high on the agenda, with 60 per cent hiring regulatory specialists and 64 per cent enhancing capabilities to align with frameworks such as NIS2 in the EU and the UK’s upcoming Cyber Security and Resilience Bill.

According to NCSC Director of National Resilience Jonathon Ellison, such steps are critical: “Ransomware remains a serious and evolving threat, and organisations must not become complacent. All businesses should strengthen their defences using proven frameworks such as Cyber Essentials.”

MSPs Prepared Yet Vulnerable

Despite the high rate of breaches, MSPs remain surprisingly confident in their security posture. For example, CyberSmart found that 76 per cent rate their cyber confidence as above average or higher. That said, only 20 per cent described their confidence as complete, suggesting that many know there’s room for improvement.

Looking at this research, for businesses relying on MSPs to manage their security, the message appears to be that while many providers are stepping up their game, others are still reacting to threats in ways that may not align with long-term best practice.

Co-op CEO Shirine Khoury-Haq, who oversaw the retailer’s response to a Scattered Spider ransomware attack, captured the sentiment well, saying: “What matters most is learning, building resilience, and supporting each other to prevent future harm. This is a step in the right direction for building a safer digital future.”

What Does This Mean For Your Organisation?

For MSPs and their clients, the emergence of ransomware funds could be seen as a move from aspirational resilience to operational realism. Despite official advice against paying cybercriminals, it seems that many MSPs clearly believe they cannot afford to be unprepared. With 69 per cent already breached multiple times in a single year and AI accelerating the scale and complexity of attacks, the temptation to hold a contingency reserve is understandable. However, this pragmatic stance may also entrench the very business model that governments and law enforcement are working hard to dismantle.

The UK’s proposed ransomware payment ban for public bodies and CNI highlights just how far official thinking has moved towards systemic deterrence. However, the exclusion of private businesses from that ban, and the option for them to pay under notification, risks creating an uneven response that may ultimately frustrate enforcement and dilute its impact. As Jamie MacColl pointed out, most ransomware gangs operate opportunistically and will not necessarily distinguish between regulated and unregulated targets. This raises questions about whether partial bans can realistically alter attacker behaviour.

For UK businesses, especially SMEs dependent on MSPs for protection, the findings raise difficult questions. For example, while many providers are making serious investments in tools, people, and compliance, others are still relying on reactive strategies that may offer short-term cover but little long-term assurance. The increasing scrutiny on MSPs is likely to intensify, particularly as clients seek partners who are both cyber confident and operationally transparent. Businesses must now evaluate not only whether their MSP has a ransomware plan, but also whether that plan reflects best practice or a compromise born of confusion.

For regulators, the lack of clarity and consistency around ransomware responses remains a core problem. Guidance alone is proving insufficient. A broader and more unified framework, alongside mandatory reporting, may be needed to help ensure MSPs, their clients, and their insurers are working from the same playbook. For now, the reliance on private ransomware funds points to a cyber landscape still dominated by tactical survival rather than strategic coordination.

Security Stop-Press: Ingram Micro Hit by SafePay Ransomware Attack

IT giant Ingram Micro, a major global distributor of technology products and services, has confirmed it suffered a ransomware attack that forced key systems offline and disrupted global operations.

The incident, which began early on 4 July, was carried out by the SafePay ransomware group. Employees discovered ransom notes on their devices, and systems including Ingram’s Xvantage distribution platform and Impulse licensing tool were shut down. Microsoft 365 and Teams remain unaffected.

Ingram Micro confirmed the attack in a brief statement on 6 July, saying it had “identified ransomware on certain of its internal systems” and was working with cybersecurity experts while restoring services.

The SafePay group, active since late 2024, has hit over 220 organisations and is known for exploiting VPN vulnerabilities using stolen or weak credentials. In this case, the company’s GlobalProtect VPN is thought to be the entry point.

This attack highlights the importance of securing remote access with multi-factor authentication, regular updates, and strong password policies to prevent ransomware intrusions.

Tech Insight : How Marks & Spencer Was Brought To A Standstill

In this Tech Insight, we look at how a major ransomware attack on M&S could happen, who was behind it, how it caused such widespread disruption, and what it means for the company, its customers, and the wider UK retail sector.

What Happened and When?

To help understand how the cyber attack on Marks & Spencer unfolded, here’s a timeline of events from early disruption to the continuing impact on customers, stores, and services:

– 29–31 March. Customers across the UK reported issues with contactless payments and Click & Collect services in M&S stores. At the time, the problems appeared to be routine glitches.

– Early April. M&S confirmed it was dealing with a “cyber incident” and took key internal systems offline to contain the disruption.

– Friday 26 April. M&S suspended all online orders via its website and mobile apps as the situation escalated. Some stores began to report empty shelves. Food halls displayed signs blaming “technical issues” for limited product availability.

– End of April. Further disruption affected in-store services. Gift cards could not be used, food store returns were unavailable, and job applications were taken offline. Speculation grew over the cause and scale of the incident.

– By 2 May. Online shopping remained unavailable with no clear restoration timeline. In-store issues continued, and M&S had yet to confirm when normal operations would resume.

What Kind of Attack, and by Whom?

Cybersecurity researchers and law enforcement sources have since confirmed the incident was a ransomware attack, i.e. a form of cybercrime where attackers encrypt a company’s systems and demand a ransom in exchange for a decryption key.

The group thought to be behind the attack are a loose, English-speaking collective known as Scattered Spider (also known in some circles as Octo Tempest). The group of hackers has gained notoriety for previous high-profile hits, including on MGM Resorts and Caesars Entertainment in the US.

Different

It seems, however, that Scattered Spider operates differently from many of the more traditional ransomware gangs linked to Russia or Eastern Europe. For example, their tactics are sophisticated and often rely on “social engineering”, i.e. impersonating staff over the phone or via email, bypassing security by tricking help desks and IT teams into granting access. In some cases, they’ve used phishing, SIM-swapping, or multi-factor authentication fatigue techniques to break in.

Gained Access In February?

In M&S’s case, some reports suggest the attackers may have gained access as early as February, exfiltrating data before deploying the ransomware payload using malware linked to another group known as DragonForce. The malware encrypted access to vital servers, triggering the cascade of outages that followed.

Was It a Direct Hit, Or Through a Supplier?

One mystery that remains unresolved, however, is how the attackers actually gained entry in the first place. While M&S has not disclosed technical details, some industry insiders have suggested the compromise may have originated through a third-party supplier, a growing concern in the age of interconnected cloud platforms and shared vendor infrastructure.

This approach would make sense in terms of it being the same tactic used in previous Scattered Spider campaigns, where attackers exploited weaknesses in identity management systems like Okta or Microsoft Entra, or leveraged supplier access to leapfrog into target systems.

What’s the Damage So Far?

The fallout from the attack has been both operational and financial. Estimates of the damage caused include:

– £3.8 million in daily online sales lost. M&S’s e-commerce arm reportedly takes in nearly £4 million a day, all of which has ground to a halt.

– Over £500 million wiped from its stock market value. Uncertainty over the scale and duration of the attack spooked investors.

– Empty shelves and store disruption. Particularly in food halls, where logistics and supply chain systems were knocked offline.

– Job ads pulled and staff sent home. Over 200 vacancies vanished from the M&S careers page, and some warehouse workers were told not to come in due to low volume.

Beyond the financial hit, the reputational cost could, of course, be much worse. For example, customers expecting digital convenience, seamless returns, and reliable stock levels have been met with error messages and handwritten signs. For a retailer that prides itself on trust and quality, the breach has struck at the heart of the brand.

Harrods and Co-op Too

Worryingly for the retail sector, M&S isn’t alone. For example, within days, Harrods confirmed it too had been targeted by a cyberattack. While the impact appeared more contained (involving restricted internet access across its stores) it marked another breach of a high-profile UK retailer.

Meanwhile, the Co-op has confirmed that it was also the victim of a cyber attack affecting one of its IT systems. Although the company initially said the disruption had been contained by proactively shutting down affected systems, further investigation revealed that attackers were able to access and extract personal data. This is reported to have included names, contact details, and dates of birth linked to a significant number of current and former members.

However, the Co-op has stated that no passwords, payment data, or transaction history was compromised and that its loyalty and payment systems remain secure. That said, clearly the breach prompted a wider response involving the National Cyber Security Centre and the National Crime Agency. Customers have been urged to stay alert for suspicious activity, and the company has apologised while confirming that it is working closely with data protection authorities to manage the incident.

Although there has been no interruption to food supplies or store operations, the breach has exposed how even a relatively contained cyber event can present serious privacy and reputational risks. In a sector that depends so heavily on trust and repeat custom, this kind of incident can have lasting implications.

These incidents appear to follow an alarming pattern, i.e. it looks as though UK retailers are becoming increasingly attractive targets for cybercriminals looking to cause widespread disruption, and score a quick payday.

Why The Food Sector Is Now a National Cyber Target

While banks and energy firms have long been classed as “critical infrastructure”, attacks like the one on M&S have raised fresh questions about whether food supply chains should be treated with similar urgency.

For example, Dr Harjinder Singh Lallie of the University of Warwick has described the incident as a “red flag” for the food industry’s cyber readiness, and has warned that “attacks like these can seriously disrupt access to basic necessities.” The relevance of this point was all too clear as M&S shoppers saw bare shelves and delayed orders first-hand.

Also, cybersecurity experts have called attention to the knock-on effects of this kind of attack, i.e. a single ransomware attack can ripple across supply chains, logistics providers, warehouse networks, and even government services that depend on consistent delivery.

It seems that the interconnectedness of these systems makes them simultaneously efficient and dangerously vulnerable.

Lessons

Cybersecurity specialists have suggested that the attack on M&S highlights how modern hackers are no longer just exploiting technical flaws. For example, they are now increasingly targeting the trust between companies and their suppliers, employees, and service partners. Analysts have, therefore, stressed the need for stronger identity verification, tighter control over third-party access, and better training for frontline staff such as IT helpdesks. Many are also pointing to the importance of adopting “zero trust” models, where access to systems is never assumed and must be continually verified.

The Motivation for the Attack?

In the case of Scattered Spider, experts have noted the group’s unusual profile. For example, unlike many ransomware gangs based in Eastern Europe, this network appears to involve mostly English-speaking members, including individuals believed to be in their late teens. Their motivation appears to be a mix of financial gain with a desire for recognition, making them both capable and difficult to predict.

Gives a Playbook to Other Cybercriminals

It seems that while most experts agree that this was a criminal act rather than a state-sponsored one, some are warning that the response (or lack thereof) could embolden hostile states watching from the sidelines. As Ciaran Martin, former head of the UK’s National Cyber Security Centre, put it: “My national-level worry is that this gives other bad actors a playbook on how to disrupt Britain at scale.”

What Does This Mean For Your Business?

While the immediate concern for M&S remains restoring full operations and reassuring customers, the wider implications of these attacks are hard to ignore. The scale and severity of the disruption (coupled with the prolonged recovery timelines) have highlighted vulnerabilities not only in retail infrastructure but also in the broader digital supply chain that supports it. These were not just one-off disruptions. They were demonstrations of how a well-organised cyber attack can ripple across departments, damage customer trust, and expose operational dependencies that were previously taken for granted.

For UK businesses, particularly those in retail, food supply, and logistics, the M&S and Co-op incidents offer a sharp reminder that cyber risk is now an operational risk. Being online and interconnected brings enormous efficiency but also opens the door to increasingly sophisticated and persistent threats. The attacks have shown how a breach of one supplier or system can impact everything from stock levels to staff recruitment, and how quickly customer-facing services can grind to a halt.

There are clear lessons here for organisations of all sizes. For example, while investment in technology is essential, so too is investment in people, training, and crisis planning. Basic resilience, i.e. the ability to function when systems go offline, is becoming just as important as innovation. For shareholders, customers and employees alike, the expectation is not perfection but preparedness.

The incidents also raise important questions for regulators and policymakers. If food retail is now so central to daily life that a single ransomware attack can cause national disruption, then its classification as part of the UK’s critical infrastructure may need to be reconsidered. In that context, the M&S and Co-op breaches could act as a turning point and one that prompts a broader shift in how businesses and government work together to anticipate, contain, and recover from this kind of attack.

While M&S works to bring its systems back online and the Co-op continues its investigation, the broader industry is already watching, and hopefully, learning. The hope is that attacks like this don’t become the new normal. If they do, resilience needs to become the new standard.

Company Check – NHS Supplier Fined £3m Over 2022 Ransomware Failures

A software provider to the NHS has been fined £3.07 million after serious security lapses allowed hackers to steal sensitive personal data in a 2022 ransomware attack.

A Breach With Real-World Impact

The penalty, issued by the Information Commissioner’s Office (ICO), follows a detailed investigation into Advanced Computer Software Group Ltd. In August 2022, the company’s health and care subsidiary was targeted by cybercriminals linked to the LockBit ransomware group. The attackers exploited a customer account that lacked multi-factor authentication (MFA), gaining access to systems used across NHS services.

In total, the personal data of 79,404 individuals was compromised. This included extremely sensitive information such as care plans and (in 890 cases) detailed instructions for entering the homes of vulnerable patients receiving in-home care.

Examples of the seriousness of the effects of the attack include:

– The NHS 111 helpline was forced to revert to manual operations.

– Health professionals across the country were locked out of patient records for extended periods.

– Routine services were thrown into disarray, with some systems offline for weeks.

ICO Says “Fell Seriously Short”

The ICO concluded that Advanced Computer Software Group Ltd had failed to implement basic cybersecurity hygiene expected of an organisation handling high-risk data. While some systems were protected by MFA, coverage was patchy, leaving major entry points exposed. Investigators also found gaps in vulnerability scanning and weaknesses in the company’s patch management processes.

Information Commissioner John Edwards said Advanced’s security “fell seriously short of what we would expect from an organisation processing such a large volume of sensitive information.” He added: “People should never have to think twice about whether their medical records are in safe hands.”

Fine Halved From £6m to £3m

The ICO originally proposed a fine of £6.09 million but ultimately reduced the figure by half. The discount followed a voluntary settlement in which Advanced accepted the findings, agreed not to appeal, and worked closely with the National Cyber Security Centre (NCSC), the National Crime Agency (NCA), and NHS partners in the wake of the breach.

The regulator also acknowledged the company’s efforts to limit the damage and mitigate risks to affected individuals, which contributed to the final penalty being set at £3,076,320.

A Data Processor Under Pressure

As a data processor acting on behalf of healthcare providers, Advanced Computer Software Group Ltd was responsible for protecting information it handled but did not own. That legal duty, the ICO stressed, does not allow for shortcuts. The ICO highlighted how it was not enough to have security measures “in progress” but that they needed to be fully implemented, especially given the volume and sensitivity of the data involved.

This attack, enabled by a single unsecured login, revealed how thinly spread protections can lead to catastrophic consequences when threat actors find a gap.

More Than Just a Cyber Incident

It seems that the fallout in this case extended far beyond IT systems. For example, the data accessed by attackers contained private information used daily by carers, clinicians, and emergency staff. In some cases, the stolen data may have revealed access instructions to individuals’ homes, which is an unprecedented breach of trust and safety for those affected.

For many observers, this incident demonstrated how a breakdown in basic cyber hygiene can translate directly into disruption on the front lines of public health services.

One of the Largest Fines in Years

Advanced’s fine is the highest handed down by the ICO since TikTok was penalised in April 2023 and ranks among the regulator’s top six ever. It places the company alongside British Airways, Marriott, and Interserve in a growing list of high-profile data security failures.

What sets this case apart is the nature of the data compromised, i.e. health and care information linked to some of the most vulnerable people in society. It also highlights how private contractors embedded in public services now face the same scrutiny and accountability as frontline NHS bodies.

What Does This Mean For Your Business?

The clear message from the ICO, illustrated by this case, is that partial protections are not enough. If you’re handling sensitive data, especially as a supplier to critical sectors, every point of access must be secured, monitored, and updated. Incomplete MFA rollout, unpatched vulnerabilities, and weak incident response planning all count as regulatory failures.

This case also highlights how regulators are now expecting more from third-party vendors, and public sector clients are unlikely to forgive repeat offenders. For procurement teams, cyber due diligence is no longer optional. It must include not only accreditations and policies, but proof that systems are fully hardened and actively monitored.

That said, Advanced’s experience shows that cooperation can actually reduce fines, but it doesn’t undo the reputational and operational damage. For suppliers across healthcare, education, and government services, the priority now is clear, i.e. secure the basics or risk losing everything.

Security Stop-Press: UK Government Proposes Ransomware Payment Ban

The UK government is consulting on plans to ban ransomware payments by public sector bodies and critical national infrastructure (CNI) to disrupt the financial model underpinning cybercrime.

The proposals also include mandatory reporting of ransomware attacks and measures to block payments to criminal groups, aiming to reduce the threat and support law enforcement investigations.

Ransomware is the most serious cybercrime threat to the UK, with attacks on organisations like the NHS and Royal Mail causing widespread disruption and recovery costs. Security Minister Dan Jarvis highlighted the urgency of action, noting $1 billion was paid globally to ransomware groups in 2023.

Banning payments would make public organisations less attractive targets, while mandatory reporting would provide intelligence to help disrupt criminal networks. Penalties for non-compliance, such as fines or leadership bans, are also being considered to ensure adherence.

This initiative is part of a wider strategy to strengthen the UK’s cyber resilience, complementing global efforts like the disruption of the LockBit network and sanctions against major ransomware groups.

Businesses are advised to adopt strong cybersecurity measures, including frameworks like Cyber Essentials, regular data backups, and tested incident response plans, to mitigate the risk and impact of ransomware attacks.

Security Stop Press : Warning About RansomHub

The FBI, MS-ISAC, and the Department of Health and Human Services (HHS) in the US have issued a released a joint advisory to businesses about the ransomware-as-a-service collective ‘RansomHub’.

The joint advisory highlights how RansomHub (formerly known as Cyclops and Knight) has as established itself as an efficient and successful service model. The advisory highlights how, since its inception in February 2024, RansomHub has encrypted and stolen data from at least 210 victims across various critical infrastructure sectors, including water and wastewater systems.

RansomHub affiliates have been stealing data using a double-extortion strategy, encrypting systems, and stealing data to coerce victims into compliance. The data exfiltration methods vary by affiliate, and the ransom note usually omits initial payment demands or instructions although it typically gives victims between three and 90 days to pay. Instead, it provides a client ID and directs victims to contact the ransomware group via a specific .onion URL, accessible through the Tor browser.

The advice to defenders is to implement the recommendations in the Mitigations section of the advisory, which include installing updates for operating systems, software, and firmware as soon as they are released, using phishing-resistant multi-factor authentication (MFA), such as non-SMS text-based methods, for as many services as possible, and training users to recognise and report phishing attempts.

Security Stop Press : Insurance Industry and Security Coalition To Tackle Ransomware

Three major UK insurance associations have united in a coalition with GCHQ’s National Cyber Security Centre (NCSC) to help reduce ransom payments made by victims of cybercrime.

The Unprecedented cross-sector coalition is comprised of the NCSC and the Association of British Insurers (ABI), British Insurance Brokers’ Association (BIBA) and the International Underwriting Association (IUA).

With Ransomware being the biggest day-to-day cyber security threat to UK organisations, the coalition, working closely with the NCSC, has developed a set of guidelines and a frameworks for a broad range of stakeholders including insurance providers, businesses, and cyber security professionals, aimed at reducing the frequency and impact of ransomware attacks.

NCSC CEO Felicity Oswald said: “It’s really encouraging to see all corners of the insurance industry unite to support victim organisations with guidance that will help them to better understand their options and reduce harm and disruption to their businesses.”

Security Stop Press : ConnectWise LockBit Alert

Just days after it was announced that the UK’s National Crime Agency (NCA), the FBI, and Europol had taken down the Russian LockBit ransomware gang’s website, it’s been reported that LockBit ransomware is still being deployed via flaws in a popular remote access tool.

Researchers at cybersecurity companies Huntress and Sophos have highlighted how two bugs in the ConnectWise ScreenConnect remote access IT support tool, usually used by IT technicians, are being exploited to launch LockBit attacks.

ConnectWise has issued an alert urging IT administrators to take quick action to patch the two critical vulnerabilities. Details are available here.