Security News > 2023 > September > Greater Manchester Police ransomware attack another classic demo of supply chain challenges
The UK's Greater Manchester Police has admitted that crooks have got their mitts on some of its data after a third-party supplier responsible for ID badges was attacked.
Assistant Chief Constable Colin McFarlane of Greater Manchester Police said: "We are aware of a ransomware attack affecting a third-party supplier of various UK organizations, including GMP, which holds some information on those employed by GMP.".
Supply chain attacks are becoming increasingly prevalent, and this latest incident is a reminder to organizations that their security posture can often depend on that of their suppliers.
Caleb Mills, Professional Services director at Doherty Associates, said: "The attack exposing Greater Manchester Police Officers' personal details highlights the importance of holistically assessing an organization's cybersecurity posture - no stone must be left unturned. This is especially true because security controls, no matter how robust, can be rendered ineffective if there are vulnerabilities within the supply chain. Your security is only as strong as its weakest link."
Raj Samani, SVP and chief scientist at Rapid7, said: "The ransomware attack on Greater Manchester Police is another kick in the teeth for public services. An organization is only as secure as its weakest third-party network, and security protocols are only effective if all of their third-party providers are equally secure."
He added: "Cybercriminals are aware of this and will attempt to breach the weakest link in the chain to gain access to systems and steal highly sensitive data. The exposure of sensitive information such as the identities of undercover officers can jeopardise criminal cases, and at worse, endanger officers' lives. Therefore, it is even more important that supply chains are secured." .
News URL
Related news
- Microsoft Identifies Storm-0501 as Major Threat in Hybrid Cloud Ransomware Attacks (source)
- Embargo ransomware escalates attacks to cloud environments (source)
- JPCERT shares Windows Event Log tips to detect ransomware attacks (source)
- Police arrest four suspects linked to LockBit ransomware gang (source)
- Ransomware attack forces UMC Health System to divert some patients (source)
- Underground ransomware claims attack on Casio, leaks stolen data (source)
- Casio confirms customer data stolen in a ransomware attack (source)
- Schools bombarded by nation-state attacks, ransomware gangs, and everyone in between (source)
- Supply Chain Attacks Can Exploit Entry Points in Python, npm, and Open-Source Ecosystems (source)
- Brazilian police claim they've cuffed serial cybercrook behind FBI and Airbus attacks (source)