MOVEit & Zellis data security attack puts thousands of employees at risk

ramsac cybercovid 1 e1585644078953

In case you missed it, last week the news headlines once again featured a serious data breach, with the revelation that the personal information of thousands of employees’ personal data had been breached in planned attack on the data of Zellis, an outsourced payroll company.

In brief, Zellis are a payroll company that provide an outsourced service to some pretty large organisations, including the BBC, British Airways and Boots. They use a piece of software called MOVEit, for transferring files between themselves and their clients.

It has been reported that Cybercriminals are exploiting a zero-day vulnerability in MOVEit, to perform a mass download of data. Data stolen includes staff ID numbers, dates of birth, home addresses, national insurance numbers and banks details.

A zero-day vulnerability is a flaw in a system or application that there is no defense against because the system or application maker is unaware it exists.

Zellis have confirmed that data was stolen from 8 of its client firms. The BBC have informed employees that their personal data was stolen, while staff of British Airways were informed their bank details may have been stolen. Many other organisations have been impacted by this attack and the numbers are expected to rise. It is not confirmed who is behind this attack, but there is speculation that notorious Cl0p ransomware group, thought to be based in Russia, may be behind it according to Microsoft.

An updated version of the MOVEit software has been released and the National Cyber Security Centre has urged organisations using this software to carry out security updates as soon as possible. However, an internet scan revealed that thousands of company databases are still vulnerable because they haven’t been updated according to reports.

Attacks like these are a reminder that all of us need to have strong security resilience in place. It is essential that you

  1. Have an understanding of your supply chain. Your company data doesn’t just reside in your own system, you likely share data via your supply chain, be that professional advisors, outsourced service providers, or even your IT suppliers. Our recent blog gives more information on how to audit your supply chain
  2. Ensure that someone in your business is receiving daily alerts about zero day threats and is ascertaining if you need to take immediate action. Our secure+ service provides this service on your behalf.
  3. Have a plan for emergency patching when new vulnerabilities are released
  4. Have a plan for ongoing patching and software updates which should happen across all platforms at least once a month
  5. It is important that organisations have Cyber Incident Response Plans (CIRP) in place that outlines procedures and guidelines for responding to any potential cyber incidents that may occur within an organization such as this MOVEit cyber breach. This plan should not only highlight steps to recover from cyber-attacks but should also detail how to communicate with internal and external stakeholders

If you believe your data may have been impacted by this breach, the National Cyber Security Centre have issued guidance, available at https://www.ncsc.gov.uk/guidance/data-breaches

Brochure: secure+ from ramsac

secure+ is a proactive cybersecurity monitoring service designed to hunt for signs of malicious activity or potential cyberbreach, ramsac then takes action to prevent damage from being done.

Related Posts

  • Social Engineering: The 7 most common tricks cybercriminals use (and how to stop them)

    Social Engineering: The 7 most common tricks cybercriminals use (and how to stop them)

    Cybersecurity

    Discover the top 7 social engineering tricks cybercriminals use to manipulate people into giving away sensitive information, and learn practical steps to protect yourself and your organisation from these [...]

    Read article

  • Protect your organisation with secure+ from ramsac

    Protect your organisation with secure+ from ramsac

    Cybersecurity

    Protect your organisation from evolving cyber threats with ramsac's secure+ A proactive monitoring solution designed to safeguard your systems, data, and reputation. [...]

    Read article

  • All you need to know about software vulnerabilities

    All you need to know about software vulnerabilities

    CybersecurityTechnical Blog

    Understanding software vulnerabilities is crucial for staying protected in an ever-evolving cyber landscape, where unpatched weaknesses can open the door to serious security threats for individuals and organisations alike. [...]

    Read article

  • Why your printer might be the biggest security risk in your office

    Why your printer might be the biggest security risk in your office

    Cybersecurity

    Think your office printer is harmless? Think again. Printers store data, connect to networks, and often have default passwords that cyber criminals love. Don't let your weakest link be the [...]

    Read article

  • The importance of cybersecurity contingency planning for businesses

    The importance of cybersecurity contingency planning for businesses

    Cybersecurity

    Protect your data from cybercriminals and minimise downtime with an effective cybersecurity contingency plan. Read on. [...]

    Read article

  • How to Spot a Scam HMRC Letter 

    How to Spot a Scam HMRC Letter 

    Cybersecurity

    Learn how to spot fraudulent communications, like fake HMRC letters, and take steps to protect your personal information and finances from scammers. [...]

    Read article

Quiz yourself

Are you more cyber savvy than an 11 year old?

11-14 year olds get asked these questions in school. Could you get these right?