Published on PublicTechnology.net (https://publictechnology.net)

Home > Regulator vows it ‘will not engage with criminals’ as ransomware response continues

Regulator vows it ‘will not engage with criminals’ as ransomware response continues

Written by Jenni Davidson on 25 January 2021 in News
News

Attack on Scottish environment watchdog happened on Christmas Eve

The Scottish Environment Protection Agency has said it “will not engage with criminals intent on disrupting public services and extorting public funds”, as it continues to deal with a ransomware attack that has been ongoing since Christmas Eve.

Some of the information stolen from the environmental regulator has now been published online, but Police Scotland is warning individuals and organisations not to search for it, as accessing the host site may place their computer infrastructure at risk.

SEPA previously confirmed the theft of around 1.2GB of data, which the agency points out is the equivalent to a fraction of the contents of an average laptop hard drive, but it still means that at least 4,000 files may have been stolen by criminals.

This includes business and staff information, some of it already publicly available and some of it internal. But although work is under way to analyse the data set, the agency says it does not yet know, and may never know, the full details of the information stolen.   

It confirmed that staff had been contacted based on the information available, and were being supported, and that a dedicated data loss support website, Police Scotland guidance, enquiry form and support line was available for regulated business and supply chain partners.


Related content

  • ‘Cyberattackers are doing the same things over and over – and too often getting through’ [1]
  • How secure is government and should we have a right to know? [2]
  • DHSC signs £2m six-month deal to improve ability to ‘respond to recover from a cyberattack’ [1]

SEPA chief executive, Terry A’Hearn said: “Supported by Scottish Government, Police Scotland and the National Cyber Security Centre, we continue to respond to what remains a significant and sophisticated cyberattack and a serious crime against SEPA. We’ve been clear that we won’t use public finance to pay serious and organised criminals intent on disrupting public services and extorting public funds. 

He added: “We have made our legal obligations and duty of care on the sensitive handling of data a high priority and, following Police Scotland advice, are confirming that data stolen has been illegally published online. We’re working quickly with multi-agency partners to recover and analyse data then, as identifications are confirmed, contact and support affected organisations and individuals.”

SEPA’s priority regulatory, monitoring, flood forecasting and warning services are continuing to operate and it will give a broader update on service delivery and recovery this week.

Detective Inspector Michael McCullagh of Police Scotland’s Cybercrime Investigations Unit said: “This remains an ongoing investigation. Police Scotland are working closely with SEPA and our partners at Scottish Government and the wider UK law enforcement community to investigate and provide support in response to this incident. Enquiries remain at an early stage and continue to progress including deployment of specialist cybercrime resources to support this response. It would be inappropriate to provide more specific detail of investigations at this time."

Jude McCorry, chief executive of the Scottish Business Resilience Centre, said: “There are many ways including ransomware a business can experience a cyber security incident, with varying levels of complexity and disruption. Cyber incidents can occur through deliberate targeting like we have seen with SEPA, or even human error, the end result is the same, a disruptive effect on business operations.  At SBRC we are working in partnership with Police Scotland and Scottish government running the UK’s first collaborative cyber incident response helpline for organisations in Scotland.

 

About the author

Jenni Davidson is a journalist at PublicTechnology sister publication Holyrood [3], where a version of this story first appeared. She tweets as @HolyroodJenni [4].

Tags
Cybersecurity [5]
Categories
Business and industry [6]
Public order, justice and rights [7]
#block-views-events-popup-block{ position: fixed; bottom: -30px; padding: 25px 22px; width: 360px; max-width: calc(100% - 30px); text-align: center; border-radius: 0 4px 0 0; color: #fff; background: rgb(0, 170, 200) none repeat scroll 0% 0%; -ms-transform: translateY(100%); -webkit-transform: translateY(100%); transform: translateY(100%); -webkit-transition: all .35s ease-in-out; transition: all .35s ease-in-out; z-index: 2; } #block-views-events-popup-block.show{ bottom:10px; transform:none; -webkit-transform:none; } #block-views-events-popup-block a.btn.btn--outlineWhite { border-color: #fff; color: #fff; background: transparent; } #block-views-events-popup-block .events-popup-close{ position: absolute; cursor: pointer; top: -30px; left: 0; height: 32px; padding: 7px 20px; border-radius: 4px 4px 0 0; color: #fff; background: rgb(0, 170, 200) none repeat scroll 0% 0%; font-size: 13px; } #block-views-events-popup-block .events-popup-close .icon--events-popupClose{ padding-left: 10px; font-family: inherit !important; } #block-views-events-popup-block .icon--events-popupClose:before { content: ''; width: 12px; height: 12px; margin: -1px 7px 0 0; background: url(https://www.publictechnology.net/sites/www.publictechnology.net/themes/pubtech_override/img/close-thin.svg) center no-repeat; background-size: 10px; vertical-align: middle; position: absolute; left: 10px; top: 10px; } #block-views-events-popup-block .views-field.views-field-nid .field-content{ display:none; }

jQuery(window).load(function() { if(jQuery('#event-popup-nid').length){ var eventId = jQuery('#event-popup-nid').text(); jQuery.cookie('eventPageId',eventId); var countCurrentValue = parseInt(jQuery.cookie('countCurrentName')) || 1; var combinedValueValue = eventId+'-'+countCurrentValue; var countCurrentValue = parseInt(jQuery.cookie('countCurrentName')) || 1; jQuery.cookie('combinedValueName',combinedValueValue); const result = combinedValueValue.split('-'); if( result[1] <= 3 ) { jQuery('section#block-views-events-popup-block').addClass('show'); countCurrentValue = parseInt(result[1]) + 1; jQuery.cookie('countCurrentName',countCurrentValue); combinedValueValue = eventId+'-'+countCurrentValue; jQuery.cookie('combinedValueName',combinedValueValue); } jQuery('.events-popup-close').click(function(){ jQuery('section#block-views-events-popup-block').removeClass('show'); }); } });

(function(e,t,o,n,p,r,i){e.visitorGlobalObjectAlias=n;e[e.visitorGlobalObjectAlias]=e[e.visitorGlobalObjectAlias]||function(){(e[e.visitorGlobalObjectAlias].q=e[e.visitorGlobalObjectAlias].q||[]).push(arguments)};e[e.visitorGlobalObjectAlias].l=(new Date).getTime();r=t.createElement("script");r.src=o;r.async=true;i=t.getElementsByTagName("script")[0];i.parentNode.insertBefore(r,i)})(window,document,"https://diffuser-cdn.app-us1.com/diffuser/diffuser.js","vgo"); vgo('setAccount', '253344499'); vgo('setTrackByDefault', true); vgo('process');
Close
Sign up for our free daily newsletter
Register here
6472
Dods PublicTechnology.net is a Merit Group plc title

Quick Links

  • Home
  • News
  • Opinion
  • Features
  • Private Sector Insight
  • Cyber Week
  • White Papers
  • Events
  • On Demand Webinars
  • Partner Directory
  • About
  • Contact

Services

Dods People Dods Political Intelligence Dods ResearchDods EventsDods Training

Media & Publishing

PoliticsHome Parliament MagazineHolyroodThe House MagazineCivil Service WorldTraining Journal

About Dods

Dods Group Part of Merit Group Privacy Policy Terms & Conditions Advertising Sponsorship
Privacy PolicyTerms & ConditionsAdvertisingSponsorship Subscriptions
  • Registered office: 11th Floor
  • The Shard
  • 32 London Bridge Street
  • London SE1 9SG
  • Company number: 04267888
  • © Merit Group plc 2021

Source URL: https://publictechnology.net/articles/news/regulator-vows-it-%E2%80%98will-not-engage-criminals%E2%80%99-ransomware-response-continues

Links
[1] https://www.publictechnology.net/articles/news/%E2%80%98cyberattackers-are-doing-same-things-over-and-over-%E2%80%93-and-too-often-getting-through%E2%80%99
[2] https://www.publictechnology.net/articles/features/how-secure-government-and-should-we-have-right-know
[3] https://www.holyrood.com/
[4] https://twitter.com/holyroodjenni?lang=en
[5] https://publictechnology.net/tags/cybersecurity
[6] https://publictechnology.net/categories/business-and-industry
[7] https://publictechnology.net/categories/public-order-justice-and-rights