Security News > 2023 > September > Greater Manchester Police ransomware attack another classic demo of supply chain challenges

The UK's Greater Manchester Police has admitted that crooks have got their mitts on some of its data after a third-party supplier responsible for ID badges was attacked.
Assistant Chief Constable Colin McFarlane of Greater Manchester Police said: "We are aware of a ransomware attack affecting a third-party supplier of various UK organizations, including GMP, which holds some information on those employed by GMP.".
Supply chain attacks are becoming increasingly prevalent, and this latest incident is a reminder to organizations that their security posture can often depend on that of their suppliers.
Caleb Mills, Professional Services director at Doherty Associates, said: "The attack exposing Greater Manchester Police Officers' personal details highlights the importance of holistically assessing an organization's cybersecurity posture - no stone must be left unturned. This is especially true because security controls, no matter how robust, can be rendered ineffective if there are vulnerabilities within the supply chain. Your security is only as strong as its weakest link."
Raj Samani, SVP and chief scientist at Rapid7, said: "The ransomware attack on Greater Manchester Police is another kick in the teeth for public services. An organization is only as secure as its weakest third-party network, and security protocols are only effective if all of their third-party providers are equally secure."
He added: "Cybercriminals are aware of this and will attempt to breach the weakest link in the chain to gain access to systems and steal highly sensitive data. The exposure of sensitive information such as the identities of undercover officers can jeopardise criminal cases, and at worse, endanger officers' lives. Therefore, it is even more important that supply chains are secured." .
News URL
Related news
- Police arrests 4 Phobos ransomware suspects, seizes 8Base sites (source)
- Police arrests 2 Phobos ransomware suspects, seizes 8Base sites (source)
- US indicts 8Base ransomware operators for Phobos encryption attacks (source)
- RA World Ransomware Attack in South Asia Links to Chinese Espionage Toolset (source)
- North Korea targets crypto developers via NPM supply chain attack (source)
- Chinese espionage tools deployed in RA World ransomware attack (source)
- Lee Enterprises newspaper disruptions caused by ransomware attack (source)
- Southern Water says Black Basta ransomware attack cost £4.5M in expenses (source)
- Bybit Hack Traced to Safe{Wallet} Supply Chain Attack Exploited by North Korean Hackers (source)
- Qilin ransomware claims attack at Lee Enterprises, leaks stolen data (source)