An ancient Windows 7 PC is being blamed for cyberattack against UK armed forces supplier

Ransomware attack on a computer
(Image credit: Kaspersky)

Zaun, a UK company that supplies military bases with high-security fencing, suffered a partially successful ransomware attack, with the hackers’ apparent point of entry a PC endpoint running the obsolete Windows 7 software. 

In a statement, Zaun admitted the LockBit threat actor managed to compromise the company's infrastructure and steal roughly 10GB of data. 

It did not manage to deploy the ransomware encryptor, and the company also said that the attackers didn’t take any sensitive information.

Staying safe

"We do not believe that any classified documents were stored on the system or have been compromised," the announcement reads, adding that LockBit appears to have published the stolen data on the dark web.

The National Cyber Security Centre (NCSC) and the UK's Information Commissioner's Office (ICO) were both notified of the incident.

Ransomware is a relatively novel method of cybercrime that’s only been around for a couple of years, but since hackers can extort the victims for millions of dollars, it quickly rose to fame. The wider cybersecurity community, as well as law enforcement, have since been urging organizations to keep their endpoints secure, not just by enforcing strong password policies and multi-factor authentication, but also by regularly deploying patches and updates.

When software reaches its end-of-life date, like Windows 7 did back in early 2020, it no longer receives updates. Hence, if someone for example discovers a high-severity flaw that grants remote code execution capabilities, the software’s makers will not release a patch and users will be left at risk. For Windows 7, Microsoft offered Extended Security Updates for sale, but the service was shut down in early 2023. Mainstream support ended in 2015, and the OS’ end of life was in January 10, 2020. 

LockBit is one of the largest and most active ransomware operators around, which has so far assaulted dozens of organizations around the world.

Via: TheRegister

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
An American flag flying outside the US Capitol building against a blue sky
US military and defense contractors hit with Infostealer malware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
More reports claim 2024 was the worst year for ransomware attacks yet
An illustration of a silhouetted thief in motion running while carrying a stolen fingerprint
The 5 worst cyberattacks of 2024
Hands typing on a keyboard surrounded by security icons
35 years on: The history and evolution of ransomware
A computer being guarded by cybersecurity.
Huge cyberattack found hitting vulnerable Microsoft-signed legacy drivers to get past security
Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
Sam Altman and OpenAI
OpenAI is upping its bug bounty rewards as security worries rise
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Latest in News
Nintendo Switch 2 Joy-Con up-close from app store
Nintendo's new app gave us another look at the Switch 2, and there's something different with the Joy-Con
cheap Nintendo Switch game deals sales
Nintendo didn't anticipate that Mario Kart 8 Deluxe was 'going to be the juggernaut' for the Nintendo Switch when it was ported to the console, according to former employees
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa speakers, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does