The notorious LockBit ransomware gang has leaked the sensitive personal information of hundreds of Royal Mail employees on the dark web following Royal Mail’s refusal to pay a ransom.
Last month, Royal Mail suffered a massive
cyber attack that disrupted its international shipping services. The infamous LockBit ransomware group later published the contents of a long-drawn-out negotiation with Royal Mail wherein the group demanded a whopping $80 million as ransom.
In response, Royal Mail’s negotiator was seen clarifying to LockBit that they have mistaken Royal Mail International with Royal Mail and that the organisation won’t pay the demanded ransom.
“Under no circumstances will we pay you the absurd amount of money you have demanded. We have repeatedly tried to explain to you we are not the large entity you have assumed we are, but rather a smaller subsidiary without the resources you think we have. But you continue to refuse to listen to us. This is an amount that could never be taken seriously by our board,” said Royal Mail’s negotiator.
According to inews, a Twitter user named FaclonFeedsio on Tuesday posted a conversation log between LockBit and the postal company. The logs
revealed that the ransomware gang was willing to reduce its ransom demand by half.
“Last chance to prevent leaks or Royal Information. We are ready to make a discount, remove the stolen information and provide a decryptor for 40 million dollars. There will be more delays, after the timer expires all the data will be released,” LockBit told Royal Mail.
It appears that the reduced demand did not make any impact on Royal Mail’s negotiators. Earlier today, the ransomware gang published a screenshot that contained samples of the stolen information with one folder containing “personel” details. It is suspected that almost 200 Royal Mail employees’ personal data is in the possession of the LockBit gang.
While the postal company downplayed the cyber attack and initially said “no sensitive customer information” was compromised, the possibility of the same cannot be ruled out.
In a service update, Royal Mail
said it has finally reinstated international shipping service to all destinations, almost two months after it was attacked. Customers can purchase postage online, through shipping solutions, and over the counter at Post Office branches.
“Delivery of International items may take slightly longer than usual. Customers using International Tracked services may notice different tracking information as items leave the UK. We are seeing delays to some tracking events in a small number of destinations. As we continue to work with our partners to resolve this, if you cannot see tracking information for your items it is likely to be available on the overseas’ posts tracking websites,” the postal service added.
Commenting on the news, Terry Greer-King, VP of EMEA at SonicWall, said, “Lockbit’s decision to release technical data of Royal Mail on the dark web serves as a stark reminder of the grave threat that ransomware poses to UK organisations. The magnitude of this attack is uniquely critical as personal information is at stake: people’s home addresses, full names, and postal codes are all at risk of going public.
“The criminals are reportedly holding on to this sensitive data, demanding £33 million from its coffer. Understanding these threats and how the cybercriminals act, what motivates them, and who they consider a target is a vital intelligence in the fight against cybercrime.”