Jump to content

Recommended Posts

Posted

Happened on 13th, noticed on 15th. Email to customers on the 19th (likely in the finance mailbox - I didn't get it directly)

 

Potential for customer data to be compromised - keep an eye out for phishing pretending to be Millgate.

 

https://millgate.co.uk/data-breach-incident/

 

Overall, fairly impressed with their response so far. A few Kent councils could learn a thing or two.

  • Thanks 1
Posted

Looks like Millgate has had a data breech. Unknown type of data from unknown number of customers currently.

 

"We are reaching out to inform you of a recent security incident at Millgate. On 15th January 2024, we discovered that some of our internal systems were impacted by a cyber incident. We understand the seriousness of this situation and have taken steps to address it."

  • Thanks 2
Posted
... and TES given the current issue with Classcharts.

 

TES are sufficiently clown car that I have no expectations of competence. Everything they buy becomes awful.

  • Thanks 1
  • 5 months later...
Posted

Hi Everyone - We only started sponsoring Edugeek after this breach and I`ve only just seen this thread about it so please don`t think we were avoiding the issue.

 

Yeah, it happened - I don`t have the exact details but I know it relates to an old data server that was being commissioned. At some point during that process it was vulnerable and the info was stolen, it was predominantly internal data from about 8 years ago.

 

We put our money where our mouth is though, got everyone notified and followed all procedures as well as taking many optional measures we weren`t obliged to and have ridden it out.

 

if anyone wants to discuss in more detail or has any concerns please reach out to me privately and I can refer you to the internal team at Millgate who handled it.

 

Thanks

 

Jon.

Posted
taking many optional measures we weren`t obliged to and have ridden it out.

 

You shouldn’t have bothered replying. This type of response does not come across well.

Posted

Apologies - would it have been better to lie and say we got breached and didn`t do anything about it?

 

Maybe you shouldn`t have bothered replying as that type of response does not come across well.

 

If you were affected by the breach, are, or were a client of Millgates and have concerns by all means drop me a line and I`ll be happy to help.

 

Thanks

 

Jon.

  • Thanks 3
Posted
Apologies - would it have been better to lie and say we got breached and didn`t do anything about it?

 

.

 

On the contrary. This is a technical forum, and we like technical answers. I'd personally like to see a technical breakdown, how the systems were compromised, with what? How did the attackers escalate their privileges? What did they encrypt? How did you get alerted? What could you have done to mitigate the problem, what have you done? I'm sure there are many more questions.

 

Answering these points would go a long way to help others mitigate attacks. saying we rode out the problem and it's all ok now doesn't really help anyone.

Posted

That makes more sense thank you DMJ

 

I`m not the man to answer those things though and I`m afraid unless you are a Millgate client I`m not sure management would be happy about me putting that info out there, not there is anything to hide, more that it`s essentially between us and our clients.

 

I`m not being obtuse in saying that, it`s just how it is.

 

From my personal point of view, Millgate were great to all employee`s - We were offered 121 sessions with the contractor brought in, all employees gifted Experian memberships with monitoring tools and alerts for our credit files - we now use Password1 to manage those across the board - these are the "extra" things that Millgate aren`t obliged to do but did - because it matters.

 

As far as clients are concerned, none of the 60-ish accounts I look after expressed any concern after reading the report and were very happy with how things were communicated and dealt from the very start.

 

All in all - we`ve actually come out of this in a really good place - As for the technical answers........apologies "We got hacked" is about as much am allowed/capable of offering!

 

Cheers

 

Jon.

  • Thanks 1
Posted
Sorry you're under orders not to divulge anything useful for the community. It sounds like Millgate either never actually understood the exploit, or it was so trivial they won't admit to it publicly. Personally I'd just have kept quiet if you're not able to offer any details that don't sound like PR, but hey thanks for telling us what you were allowed to say.
Posted

I thought what I said was useful to the community - if anyone here had any concerns, assuming they are clients of Millgates they are more than welcome to message me and I can point them in the direction of our team who can help.

 

Please don`t assume I`m "under orders", thats not the case but I do understand boundaries and the kind of technical info referred to above is reserved for those affected.

 

Millgate as a company have absolutely understood the exploit, neither was it so trivial we wouldn`t admit to it - We have been very open about it.

 

We don`t want it to turn into entertainment though and it`s not our responsibility to use this experience as a training tool for others.

 

My original statement stands - anyone with legitimate concerns, please contact me and I`ll help you get the info you need.

 

I`m not one to keep quiet - it happened, not shying away from that however I`m also not one to shout unnecessarily thats all.

 

Help is here for those that need it - Thats all I was trying to get across.

 

Thanks

 

Jon.

  • Thanks 2
Posted
Millgate are under no obligation to post specific details of the exploit to the public. Indeed, it maybe that IT specialists and legal teams specifically advised them not to.

 

Just because you want to know, doesn’t mean you can or should.

 

The post was honest and helpful and if you think you could have been affected, it’s seems millgate are open to discussing with you.

 

 

I somewhat agree, they are under no obligation whatsoever. Jon said that they won't help others on the forum for free unless we pay for their consultancy services. I guess that's fair enough, they are an MSP/consultancy and sell their services. I can understand why they don't want the geeks here knowing their innermost secrets - they don't want to turn it into 'entertainment'. I can imagine the backlash here if it tuned out to be something that we (collectively) had been mitigating against already, and if it isn't then it would certainly benefit us. Personally I prefer a more open approach like in the links I supplied earlier.

 

Do any customers actually know what happened or is it under NDA?

  • Thanks 1
Posted
I think Millgate dealt with this well - they found out about it, told their customers about it and fixed it. And were happy to talk/discuss in public about it. Most companies could learn a thing or two from this best practice.
  • Thanks 1
Posted

:mod: Please keep this civil everyone. If it continues as it is, we may have to close the thread :mod:

 

If you want to see just how determined cyber-criminals are to wreak havoc on systems these days then please watch the webinar Sophos did with us recently. It's quite an eye opener how much effort goes into their activities these days.

 

Posted
:mod: Please keep this civil everyone. If it continues as it is, we may have to close the thread :mod:

 

If you want to see just how determined cyber-criminals are to wreak havoc on systems these days then please watch the webinar Sophos did with us recently. It's quite an eye opener how much effort goes into their activities these days.

 

 

No system is safe.

 

If even the big companies that spend millions can get a breach.... not sure we can go too mad at a supplier.

In fact, I'm surprised it doesn't happen more often.

 

Schools are getting hit. Health sector getting hit. Is there any safe areas anymore?.......

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...