Tewkesbury Borough Council have a cybersecurity incident and are containing their network.
I can see from their network border they’re shutting down edge and Windows services.
HT @d4rkshell
Tewkesbury Borough Council have a cybersecurity incident and are containing their network.
I can see from their network border they’re shutting down edge and Windows services.
HT @d4rkshell
Tewkesbury Borough Council have published an FAQ on their cyber incident
They have isolated card payment.
@GossiTheDog Props to them for being somewhat open about this! Other councils have previously tried to just.. not talk about anything.
Tewkesbury Borough Council are on day 5 of containment for their cyber incident. Media reporting suggests they have called in GCHQ, who are local to them (it’s probably more they just reported it to NCSC).
In their updated FAQ they ask the press to stop calling them about it.
From network traffic it looks like a crimeware group. #threatintel
@GossiTheDog "network traffic"; where did you get that? I thought ISPs selling netflow data was an american enterprise
@GossiTheDog @interpipes can confirm. I help a small altnet and they were approached (but did not engage) by q company wanting to pay for customer facing DNS resolver feeds.
Grim.
@GossiTheDog @interpipes but gossi, that still doesn’t explain how you have access to that data? Are you buying it? Do you know people who have access to it? Who runs the queries to validate against IOCs to make such a statement? How can other small orgs do the same?
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.