UK rail network Merseyrail was a victim of a cyber attack, which operates rail services across Merseyside. A ransomware gang has also compromised the email system of the organization to inform employees and journalists about the attack.
Bleeping Computer reported that it has received an email earlier from the account of Andy Heath, the Director of Merseyrail that also speculate. Having the subject, “Lockbit Ransomware Attack and Data Theft,” BleepingComputer speculates the involvement of the Lockbit ransomware in the security incident.
The same email was sent to several UK newspapers, and to the Merseyrail employees, likely to make pressure on the organization to pay the ransom. It seems that the Lockbit Ransomware gang managed to compromise the Director’s @merseyrail.org Office 365 email account to inform the employees of the incident that was downplayed by the internal staff. The message includes a link to an image showing an employee’s personal information as proof of the attack.
The attackers claim to have stolen employee and customer data before encrypting the systems of the company.
UK rail network Merseyrail reported the incident to the UK authorities, including the Information Commissioner’s Office (ICO), and is investigating the incident with the help of law enforcement.