It has been听reported听that听tens of thousands of British Airways, BBC and Boots staff may have had their personal details stolen following a听suspected Russia-linked cyber attack.听BA has written to many of its 34,000-strong workforce warning them of a 鈥渃yber security incident which has led to the disclosure of personal information about colleagues paid through British Airways鈥 payroll in the UK and Ireland鈥.
An email to BA staff 鈥 seen by the Telegraph 鈥 warns that the compromised information includes names, addresses, national insurance numbers, banking details and other information. The hack is linked to BA鈥檚 payroll provider, Zellis, and other companies that work with the company have also had their information stolen.
Boots has emailed employees saying that staff鈥檚 names, surnames, employee numbers, dates of birth, email addresses, the first lines of their home address and national insurance numbers have been affected. It said a 鈥渧ery small number鈥 of employees may have had other data compromised.
A BBC spokesman confirmed they were also affected by the hack. The spokesman said: 鈥淲e are aware of a data breach at our third party supplier, Zellis, and are working closely with them as they urgently investigate the extent of the breach.
听
More from News
- Russia鈥檚 Latest Move Against Pavel Durov Shows That Telegram Is No Longer Just A Messaging App
- Experts React To The UK鈥檚 Decision To Make Tech Subjects Compulsory In Schools
- Microsoft Has Confirmed Copilot鈥檚 Super App Will Launch Soon 鈥 But What Is It For?
- G2A.COM鈥檚 Autonomous AI Agent Dave Helps Sellers Resolve 14,400 Support Tickets In 63 Days
- Why One MedTech Company Chose a Computer Graphics Conference To Launch Its Next AI Platform
- 75% Of CEOs Don鈥檛 Think Marketing Drives Growth 鈥 What Are They Missing?
- OpenAI Will Soon Release Its First Tech Gadgets 鈥 Here鈥檚 What To Expect
- Can Elon Musk鈥檚 New X Money Platform Rival PayPal?
Expert comments
听
Israel Barak, chief information security officer at Cybereason:
鈥If this was in fact a ransomware attack on payroll management provider Zellis鈥 third party suppliers, MOVEit, transparency is important for everyone that has been impacted, most importantly the tens of thousands of British Airways, BBC and Boots employees that have had their personal data stolen. In the days ahead, we need to shift focus from dealing with the aftereffects of the attack, to educating organisations on deploying tools that disrupt the earliest stages of attacks through behavioural detections 鈥 this is the operation centric approach to cybersecurity.
鈥淪topping the attackers in their tracks before they can gain access to an organisation鈥檚 data is extremely important. The good news is that tools exist today to stop material breaches. We can鈥檛 just focus on the attack itself 鈥 by then it is too late. Look at the earlier stages of the attack when criminals are inserting malicious code into the supply chain for instance.鈥
听
Javvad Malik, lead security awareness advocate at KnowBe4:
鈥淭he recent news, involving the theft of sensitive data from BA and Boots highlights the importance of tightening up cybersecurity controls and the challenges of securing the supply chain. It鈥檚 also a reminder of how the exploitation of zero-day vulnerabilities represents one of the most significant threats to any IT team.
鈥淚n this particular case, the issue appears to be an SQL injection vulnerability within the MOVEit software, which enables unauthorised remote attackers to exploit the system and subsequently, gain access to sensitive information via the database. Unfortunately, the exploitation of such a vulnerability can lead to the theft of valuable data, and in this case, BA鈥檚 UK employees鈥 data has been exposed.
鈥淚t鈥檚 unfortunate to see so many people affected by this cyberattack. This news demonstrates that the challenges of keeping systems secure go beyond mere firewalls and antivirus software. Securing the supply chain depends on implementing robust cybersecurity measures, such as constant monitoring, insider threat detection, and ongoing education and awareness among users and all staff members. The theft of data from BA and Boots illustrates how organisations depend on software solutions like MOVEit, which underpin their infrastructure and provide an attractive target to cybercriminals, even when they鈥檙e not household names.
鈥淚n the end, proactive cybersecurity measures can help guard against cyberattacks, but organizations must also prepare for scenarios where a system vulnerability is exploited and no patch is available yet, such as is the case with zero-day vulnerabilities. This breach serves as a dire reminder that organisations need to remain vigilant and work constantly to identify and mitigate these risks to protect their data and their stakeholders.鈥
听
Erfan Shadabi, cybersecurity expert at听comforte AG:
鈥淭he recent cybersecurity incident involving Zellis and their third-party supplier, MOVEit, underscores the critical security risks that organizations face through their supply chain. Third-party supply chain relationships have become a prime target for malicious actors seeking to exploit vulnerabilities in interconnected systems. This incident serves as a reminder that the security of an organization鈥檚 data is only as strong as its weakest link. By relying on external suppliers, organizations expose themselves to potential breaches and data compromises if proper security measures are not in place.
鈥淭o mitigate these risks, organizations must prioritize securing the data itself. While traditional perimeter-based security measures are important, they may not be sufficient in preventing advanced threats originating from third-party suppliers. Organizations, instead, should adopt a data-centric security approach. Also, when selecting business partners, organizations should conduct thorough due diligence to ensure that potential partners have appropriate data security measures in place. Evaluating the partner鈥檚 security practices, certifications, and adherence to industry standards can provide crucial insights into their commitment to data protection.鈥
听
Brad Freeman, Director of technology at听SenseOn:听
鈥淭his kind of incident is nothing new unfortunately. MOVEit, the enterprise software involved which is used to transfer sensitive files, should never have been exposed to the听Internet听in the first place. But, mistakes happen, and听attackers can also gain access to these kinds of systems if they are already present on a victims network.The SQL injection vulnerability in MOVEit could allow an attacker to remotely gain access to highly sensitive data or further their access, and as we can see it is being actively exploited by threat groups.鈥澨
听
Jamie Akhtar, CEO and co-founder, CyberSmart:
鈥淭his incident is the perfect illustration of how a single vulnerability in a supply chain can cause widespread damage. The zero-day vulnerability hackers discovered MOVEit鈥檚 software has exposed thousands of companies to听attack.听
It鈥檚 a stark reminder (if businesses needed one) of the risks posed by third-party suppliers and the supply chain. And, that even having your own cybersecurity in order is no guarantee of complete protection from breaches.听
With this in mind, we urge all businesses to map their supply-chain dependencies.听The goal is to have an understanding of your network of suppliers so that听cyber听risks can be managed and responded to effectively. If you鈥檙e unsure of where to start, the听is a great jumping-off point.鈥澨
听
A MOVEit spokesperson commented on the incident:
鈥淥ur customers have been, and will always be, our top priority. When we discovered the vulnerability, we promptly launched an investigation, alerted MOVEit customers about the issue and provided immediate mitigation steps. We disabled web access to MOVEit Cloud to protect our Cloud customers, developed a security patch to address the vulnerability, made it available to our MOVEit Transfer customers, and patched and re-enabled MOVEit Cloud, all within 48 hours. We have also implemented a series of third-party validations to ensure the patch has corrected the exploit.
鈥淲e are continuing to work with industry-leading cybersecurity experts to investigate the issue and ensure we take all appropriate response measures. We have engaged with federal law enforcement and other agencies with respect to the vulnerability. We are also committed to playing a leading and collaborative role in the industry-wide effort to combat increasingly sophisticated and persistent cybercriminals intent on maliciously exploiting vulnerabilities in widely used software products.鈥
