pwshub.com

The fingerpointing starts as TfL cyber incident continues

The Transport for London (TfL) "cyber incident" is heading into its third day amid claims that a popular appliance might have been the gateway for criminals to gain access to the organization's network.

TfL remains tightlipped over the nature of the incident and its broader impact, sticking instead to the line that there is currently no evidence of customer data being compromised or impact to TfL services. However, claims have emerged regarding how criminals got a foothold.

One source close to the matter told us, "The TfL hack was their Cisco VPN getting popped." Other reports noted that pretty much all outbound internet has been cut and inbound restricted, presumably to permit all the employees who found themselves suddenly needing to work from home to get online.

We put the suggestion to TfL that attackers may have gained access through a Cisco or Netscaler appliance, but the organization told us it would be inappropriate to comment while the incident was ongoing. The alarm was raised when TfL spotted some suspicious activity during routine monitoring. Access was subsequently limited.

Other reports say that an abrupt termination of Wi-Fi was the first indicator that all was not well on the network.

The contactless and Oyster account login page remains offline for the time being, while TfL does "maintenance for contactless." Other TfL functions, such as APIs used for live Tube times, are also currently offline, judging by sites such as Citymapper.

It is not unknown for researchers to point to vulnerabilities in Cisco hardware and software as handy access points for criminals. Deploying patches and keeping an eye on CVEs is an unpleasant game of whac-a-mole for administrators, but not keeping on top of things can have even more unpleasant consequences.

  • Transport for London confirms cyberattack, assures us all is well
  • Uber's gig economy business model takes a blow from London legal double-whammy
  • Mind the gap(ing mouth): London's Underground to get ubiquitous mobile phone coverage
  • EE and Three mobe mast surveyors might 'upload some virus' to London Tube control centre, TfL told judge

We asked Cisco if it wish to make a comment regarding the incident, but the the US company has yet to reply.

While TfL has remained silent during the incident, its containment steps – abruptly cutting off access – bear all the hallmarks of a reaction to a ransomware attack or exfiltration attempt. Its internal measures remain in place while the investigation takes place.

Depending on the nature of the breach, the UK's Information Commissioner's Office (ICO) should be notified within 72 hours. The Register asked the regulator if it had received a notification from TfL.

An ICO spokesperson wrote in an email, "Transport for London has made us aware of an incident and we are assessing the information provided." ®

Source: theregister.com

Related stories
1 week ago - Criminals with plenty of time on their hands may now have credit card details Around 1.7 million people will receive a letter from Florida-based Slim CD, if they haven't already, after the company detected an intrusion dating back nearly...
1 month ago - Citizen Lab also spots a COLDWASTREL swimming in the Rivers of Phish Russia's Federal Security Service (FSB) cyberspies, joined by a new digital snooping crew, have been conducting a massive online phishing espionage campaign via phishing...
2 weeks ago - It's going to take more than CAPTCHA to prove you're real Researchers at Microsoft and OpenAI, among others, have proposed "personhood credentials" to counter the online deception enabled by the AI models sold by Microsoft and OpenAI,...
3 weeks ago - The government-backed crew also enjoys ransomware as a side hustle Iranian government-backed cybercriminals have been hacking into US and foreign networks as recently as this month to steal sensitive data and deploy ransomware, and...
1 month ago - “If browser privacy were a sport at the Olympics, Apple isn’t getting on the medal stand,” one expert said.
Other stories
15 minutes ago - European regulators want Apple to open up device pairing, notifications and more to other companies' products.
15 minutes ago - We chat with the director, and with executive producer Wesley Coller, about the show's animation and storyline.
15 minutes ago - There may be plenty of sun light in the South, but does your state encourage using it to power your home? Find out if solar power is worth it down south.
15 minutes ago - There's no shortage of broadband providers in Torrance, including plenty of cable, fiber and satellite options. Here are CNET's top picks for the best internet providers in Torrance.
15 minutes ago - Gainesville offers a range of fiber broadband options, including AT&T Fiber. Depending on your needs, here are the best internet service providers to consider.