GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 04-Sep-2025 03:50:06 JST Kevin Beaumont Kevin Beaumont

    The lapsus guys continue to go nuts on IRC^H^H^HTelegram https://www.bbc.co.uk/news/articles/c4gqepe5355o

    In conversation about 10 days ago from cyberplace.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: ichef.bbci.co.uk
      M&S hackers claim to be behind Jaguar Land Rover cyber attack
      The hack has caused severe disruption at manufacturing plants globally, with some staff told not to come into work.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 02-Sep-2025 22:23:01 JST Kevin Beaumont Kevin Beaumont

      Jaguar Land Rover have contained their network and stopped production after what appears to be a ransomware incident. VPNs and network border in UK all down.

      In conversation about 11 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 02-Sep-2025 22:32:31 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Jaguar Land Rover moved their cybersecurity and IT functions to TCS two years ago 🫡

      In conversation about 11 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 02-Sep-2025 23:27:20 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Jaguar Land Rover is ransomware, I can see network traffic from infrastructure used by multiple e-crime groups over the past week.

      They (JLR) appear to be doing contain to eradicate, i.e. all UK border services shut, Windows infrastructure offline etc.

      In conversation about 11 days ago permalink
    • Embed this notice
      J$ (js@mastodon.nl)'s status on Tuesday, 02-Sep-2025 23:34:24 JST J$ J$
      in reply to

      @GossiTheDog JLR allowed Windows in their infrastructure. Those seeking to celebrate the same achievements should follow the lead.

      The rest of us: keep the leper colony at bay.

      In conversation about 11 days ago permalink
    • Embed this notice
      翠星石 (suiseiseki@freesoftwareextremist.com)'s status on Tuesday, 02-Sep-2025 23:38:26 JST 翠星石 翠星石
      in reply to
      • Christoffer S.
      @nopatience @GossiTheDog Windows is not cheap - it has extremely expensive "license" fees, things break all of the time and there is also the cost of getting hit by ransomware.

      The cost of breaking all of microsoft's shackles over the short term just seems expensive compared to continuing to use windows.
      In conversation about 11 days ago permalink
    • Embed this notice
      Christoffer S. (nopatience@swecyb.com)'s status on Tuesday, 02-Sep-2025 23:38:28 JST Christoffer S. Christoffer S.
      in reply to

      @GossiTheDog Cheap will almost always prevail, until it doesn't.

      In conversation about 11 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 03-Sep-2025 04:50:28 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Jaguar Land Rover latest from the outside looking in.

      AS205756 aka JAGUAR LAND ROVER AUTOMOTIVE PLC is shut down - UK network only (however it hosts their most important infrastructure).

      Staff have been told not to turn up to manufacturing facilities.

      Tata Motors (parent company) appears to be online still but looks like a mess on Shodan, e.g. lots of SAP Netweaver boxes dangling directly off the internet.

      In conversation about 11 days ago permalink
    • Embed this notice
      Mark Koek (mkoek@mastodon.nl)'s status on Wednesday, 03-Sep-2025 05:09:30 JST Mark Koek Mark Koek
      in reply to

      @GossiTheDog Did a Red Team against a TCS-run SOC once. So easy it wasn’t even funny.

      In conversation about 11 days ago permalink
    • Embed this notice
      apth (apth@infosec.exchange)'s status on Wednesday, 03-Sep-2025 05:43:25 JST apth apth
      in reply to

      @GossiTheDog I would love to hear a little bit about what you're using to see that network traffic, as an aspiring CTI nerd

      In conversation about 11 days ago permalink
    • Embed this notice
      Alameals (alameals@cyberplace.social)'s status on Wednesday, 03-Sep-2025 18:36:55 JST Alameals Alameals
      in reply to

      @GossiTheDog Any claimed responsibility for this yet?

      In conversation about 10 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 03-Sep-2025 19:25:25 JST Kevin Beaumont Kevin Beaumont
      in reply to

      JLR - network border all still offline. Liverpool Echo reports factory production still at all stop.

      In conversation about 10 days ago permalink
    • Embed this notice
      Alex (alex02@cyberplace.social)'s status on Wednesday, 03-Sep-2025 23:02:24 JST Alex Alex
      in reply to

      @GossiTheDog they must like the party van.

      In conversation about 10 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 03-Sep-2025 23:02:25 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The lapsus$ guys are taking credit for the Jaguar Land Rover thing, speed run to see how many times they can get v&'d in 5 years.

      In conversation about 10 days ago permalink
    • Embed this notice
      Alex (alex02@cyberplace.social)'s status on Wednesday, 03-Sep-2025 23:05:20 JST Alex Alex

      @GossiTheDog these kids have no idea how badly they're ruining their future. I have a misdeamnor cuz I took a plea deal and I still got majorily fucked. I bet they think becoming infamous like the kids in the 90's and early 2000's will make them rich and famous while landing jobs with zero effort.

      In conversation about 10 days ago permalink
    • Embed this notice
      Alex (alex02@cyberplace.social)'s status on Thursday, 04-Sep-2025 00:19:36 JST Alex Alex
      in reply to

      @GossiTheDog o_O

      In conversation about 10 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 04-Sep-2025 00:19:38 JST Kevin Beaumont Kevin Beaumont
      in reply to

      I can see ecrime infrastructure was talking to this at JLR https://beta.shodan.io/host/185.193.35.39

      It's a SAP Netweaver box. The Lapsus$ kids have been running around with a SAP exploit for a while, prior thread reference: https://cyberplace.social/@GossiTheDog/115005311849134541

      In conversation about 10 days ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: beta.shodan.io
        185.193.35.39It
        Search Engine for the Internet of Things
      2. Domain not in remote thumbnail source whitelist: cyberplace.social
        Kevin Beaumont (@GossiTheDog@cyberplace.social)
        from Kevin Beaumont
        Attached: 1 image What a time to be alive Tl;dr of the Scatter Spider LAPSUS$ chat aka fuckmandiantunit221bcr0wdshart is: - they’ve owned a lot of big companies by phoning them up and asking for access - this includes orgs who haven’t disclosed their incidents - they also appear to have an Oracle WebLogic exploit (unclear if zero day) and a SAP Netweaver exploit and used that to get inside orgs - They appear to also be (or owned) ShinyHunters ransomware, as they include internal ShinyHunter emails and IMs.
    • Embed this notice
      Alex (alex02@cyberplace.social)'s status on Thursday, 04-Sep-2025 00:20:53 JST Alex Alex
      in reply to

      @GossiTheDog imagine bragging about this being so easy when they probably bought the exploit with bitcoin.

      In conversation about 10 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 04-Sep-2025 00:20:55 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The lapsus$ guys also posted this screenshot, on an internal Jaguar Land Rover SAP box last night:

      In conversation about 10 days ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/115/141/028/360/932/279/original/b2dbfb38b546080e.png
    • Embed this notice
      Jon PENNYCOOK (jonpsp@mstdn.social)'s status on Thursday, 04-Sep-2025 00:41:40 JST Jon PENNYCOOK Jon PENNYCOOK

      @GossiTheDog have they really still got servers in the ford.com domain after all these years?

      In conversation about 10 days ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 04-Sep-2025 05:42:35 JST Kevin Beaumont Kevin Beaumont
      in reply to

      To back up ReliaQuest - this is the exploit LAPSUS guys have running around with on SAP Netweaver, just had a look this evening after acquiring the exploit. https://reliaquest.com/blog/threat-spotlight-reliaquest-uncovers-vulnerability-behind-sap-netweaver-compromise/

      There’s a metric ton - over 5 figures - of these boxes directly internet facing. Worse; from version printing, less than 5% are patched for the two CVEs being exploited.

      In conversation about 10 days ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/115/142/288/116/732/815/original/281c73aed6b48701.jpeg

    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 04-Sep-2025 20:50:39 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Liverpool Echo reports Jaguar Land Rover production still isn't running, with factory stop told to stay at home, and report it impacts all manufacturing locations. https://www.liverpoolecho.co.uk/news/liverpool-news/update-jaguar-land-rover-shut-32411513

      Separately, the network border is also still offline (I have monitoring in place to see when they come back online).

      In conversation about 9 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 04-Sep-2025 20:54:53 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If anybody runs into a LAPSUS$ incident at their org hit me up on Signal, I can try to help profile their MO as been there, done that.

      They'll frequently not even bother to deploy ransomware, they'll also do crazy things (and like to write about poo, and send people poo packages in the mail). It's basically like fighting Mr Bean, who is also good at computers.

      In conversation about 9 days ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 04-Sep-2025 21:09:59 JST Kevin Beaumont Kevin Beaumont
      in reply to

      This isn't anything against the LAPSUS guys btw as they're basically having a five year ninja fight with Mandiant, DART, cyber standards and law enforcement while playing teenage Mr Bean and lets be honest... that's pretty funny and eye opening.

      In conversation about 9 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 04-Sep-2025 22:47:15 JST Kevin Beaumont Kevin Beaumont
      in reply to

      ITV reports Jaguar Land Rover has shut down car production in the UK, Slovakia, China, India and Brazil.
      https://www.itv.com/news/2025-09-04/jaguar-land-rover-temporarily-halts-all-car-production-following-cyber-attack

      In conversation about 9 days ago permalink

      Attachments


    • Embed this notice
      Gary Parker :party_porg: (witewulf@cyberplace.social)'s status on Thursday, 04-Sep-2025 23:20:19 JST Gary Parker :party_porg: Gary Parker :party_porg:
      in reply to

      @GossiTheDog

      In conversation about 9 days ago permalink

      Attachments


    • Embed this notice
      Stephan (erlenmayr@chaos.social)'s status on Friday, 05-Sep-2025 00:36:00 JST Stephan Stephan
      in reply to

      @GossiTheDog That does not sound like ransomware any more. That sounds like an SAP migration.

      In conversation about 9 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 05-Sep-2025 03:11:19 JST Kevin Beaumont Kevin Beaumont
      in reply to

      ITV News 6pm lead story on Jaguar Land Rover

      Key take away is anonymous source at JLR saying they may need UK government support for motor sector off the back of the incident.

      https://www.youtube.com/watch?v=V4xQz0iKK4g

      In conversation about 9 days ago permalink
    • Embed this notice
      Just_Patch_It (just_patch_it@cyberplace.social)'s status on Friday, 05-Sep-2025 06:03:21 JST Just_Patch_It Just_Patch_It
      in reply to

      @GossiTheDog well I’m glad I don’t have that shit hanging off my edge.

      In conversation about 9 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 05-Sep-2025 20:50:22 JST Kevin Beaumont Kevin Beaumont
      in reply to

      JLR is keeping all factory production suspended today, tomorrow, Sunday and at least Monday (possibly longer) in UK, Slovakia, China, India and Brazil.
      https://www.liverpoolecho.co.uk/news/liverpool-news/jaguar-land-rover-staff-until-32413174

      In conversation about 8 days ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: i2-prod.liverpoolecho.co.uk
        JLR staff to be off until at least Tuesday as cyber crisis grows
        from https://www.facebook.com/LiamThorpECHO
        Email to production workers at car giant's Halewood plant says they will be stood down on Friday and Monday after hack
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 05-Sep-2025 20:57:00 JST Kevin Beaumont Kevin Beaumont
      in reply to

      JLR direct employ 32k people in the UK so I imagine there's going to be ripple effects on the wider economy off the back of this one the longer it goes on.

      In conversation about 8 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 05-Sep-2025 21:08:48 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Meanwhile the LAPSUS guys were busy posting large numbers of US defense Top Secret marked documents last night. They've seen been deleted from Telegram.

      In conversation about 8 days ago permalink
    • Embed this notice
      greem (greem@cyberplace.social)'s status on Friday, 05-Sep-2025 21:53:52 JST greem greem
      in reply to

      @GossiTheDog the docs, or the LAPSUS folks?

      In conversation about 8 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 06-Sep-2025 05:18:17 JST Kevin Beaumont Kevin Beaumont
      in reply to

      One surprising thing with the Jaguar Land Rover incident - they've only isolated JAGUAR LAND ROVER AUTOMOTIVE PLC (AS205756), the UK network. The India, China etc networks are still online.

      When I dealt with LAPSUS elsewhere they entered via a different country network/biz unit and then pivoted to target country/biz unit.

      In conversation about 8 days ago permalink
    • Embed this notice
      Seven (creativegamingname@cyberplace.social)'s status on Saturday, 06-Sep-2025 05:55:31 JST Seven Seven
      in reply to

      @GossiTheDog this whole event is... extra.

      But you caught me with the IRC^H^H backspace.

      In conversation about 8 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Sunday, 07-Sep-2025 05:46:46 JST Kevin Beaumont Kevin Beaumont
      in reply to

      JLR UK have got one internet facing system back online - wslx.jlrext.com

      Single factor auth only because that's how automotives roll. If you visit direct IP, it's still branded Ford - Ford sold the business in 2008.

      In conversation about 7 days ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/115/159/299/569/876/844/original/05fd184fd3380da1.png

      2. https://cyberplace.social/system/media_attachments/files/115/159/304/176/412/317/original/98e3fae443376099.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 09-Sep-2025 06:43:12 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Just checked in on JLR - factory production won't be resuming tomorrow (day 7).

      In conversation about 5 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Sep-2025 02:23:09 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Jaguar Land Rover car production is still shut down tomorrow, day 8. I’ve checked the network border, everything except one system in UK is also still offline.

      In conversation about 4 days ago permalink
    • Embed this notice
      Just_Patch_It (just_patch_it@cyberplace.social)'s status on Wednesday, 10-Sep-2025 10:16:03 JST Just_Patch_It Just_Patch_It
      in reply to

      @GossiTheDog that’s $40 million gone poor, just in sales profits.

      In conversation about 4 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Wednesday, 10-Sep-2025 19:52:07 JST Kevin Beaumont Kevin Beaumont
      in reply to

      JLR are keeping car production closed until least this weekend. They also say “some data was impacted”, whatever that means.

      https://www.liverpoolecho.co.uk/news/liverpool-news/jaguar-land-rover-issues-crisis-32447659

      In conversation about 3 days ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: i2-prod.liverpoolecho.co.uk
        Jaguar Land Rover issues update after staff told to stay at home
        from https://www.facebook.com/LiamThorpECHO
        Ten days after the major car manufacturer was hit by a cyber attack staff have still not returned to the factory
    • Embed this notice
      Khleedril (khleedril@cyberplace.social)'s status on Wednesday, 10-Sep-2025 22:21:12 JST Khleedril Khleedril
      in reply to

      @GossiTheDog It will be funny if cars start rolling off the production lines with manufactured dents in them.

      In conversation about 3 days ago permalink
    • Embed this notice
      Alex (alex02@cyberplace.social)'s status on Thursday, 11-Sep-2025 04:49:44 JST Alex Alex
      in reply to

      @GossiTheDog is this why uk keeps getting pwned by kids?

      In conversation about 3 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 11-Sep-2025 04:49:45 JST Kevin Beaumont Kevin Beaumont
      in reply to

      JLR shouldn't feel bad, Tata Motors (their parent) is way worse shape. They've even got Exchange Server with OWA internet facing without MFA.

      In conversation about 3 days ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 11-Sep-2025 04:49:46 JST Kevin Beaumont Kevin Beaumont
      in reply to

      JLR have started switching border routers back on (don't ask me why SNMP, NTP and SSH are internet facing).

      In conversation about 3 days ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/115/181/690/008/253/837/original/1771ad1e0c1a2be3.png

      2. https://cyberplace.social/system/media_attachments/files/115/181/691/371/264/487/original/4297dc1fb810b220.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 11-Sep-2025 04:55:32 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • Alex

      @alex02 I don't think it's particularly a UK issue, the whole cyber industry is basically a box ticking compliance failure. The UK's probably pivoted too hard on data theft legislation though, over prevention and protection.

      In conversation about 3 days ago permalink
    • Embed this notice
      Alex (alex02@cyberplace.social)'s status on Thursday, 11-Sep-2025 04:57:21 JST Alex Alex
      in reply to

      @GossiTheDog I was making a joke... xD

      In conversation about 3 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Thursday, 11-Sep-2025 05:13:14 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • Alex
      • lfzz

      @lfzz @alex02 yeah, it's getting worse in the trenches across the board. Orgs are going to end up buying Security Copilot because MS are really good at upselling to CIOs.. and end up losing a good portion of their security staff to pay for it. It's a mess.

      In conversation about 3 days ago permalink
    • Embed this notice
      lfzz (lfzz@mastodon.social)'s status on Thursday, 11-Sep-2025 05:13:15 JST lfzz lfzz
      in reply to
      • Alex

      @GossiTheDog @alex02 wait do you mean the overstaffed audit team is actually useless checkbox generator while I can't even get a junior hired because "security team are expensive" and we should be able to automate/ai/buzzworddujours our work away? I am very shocked!

      In conversation about 3 days ago permalink
    • Embed this notice
      Just_Patch_It (just_patch_it@cyberplace.social)'s status on Thursday, 11-Sep-2025 20:54:57 JST Just_Patch_It Just_Patch_It
      in reply to

      @GossiTheDog Clearly they don’t have an EASM program. Do they know their external footprint? NOT!

      In conversation about 2 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Friday, 12-Sep-2025 05:40:49 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Jaguar Land Rover have told factory workers worldwide to stay home until at least next Wednesday, which will be 17 days since the cyber incident began. https://www.bbc.co.uk/news/articles/c3e712nvyz9o.amp

      In conversation about 2 days ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: ichef.bbci.co.uk
        Jaguar Land Rover plants shut until Wednesday after cyber attack
        Staff in Solihull, Halewood and Wolverhampton have been told not to come into work until Wednesday.
    • Embed this notice
      Infoseepage (infoseepage@mastodon.social)'s status on Friday, 12-Sep-2025 05:52:44 JST Infoseepage Infoseepage
      in reply to

      @GossiTheDog A car maker which cannot make cars doesn't seem like they're going to be a going concern for much longer. So many companies have made complex computer networks into a single point of failure for their entire line of business when they should be managed like the fucking Battlestar Galactica.

      In conversation about 2 days ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 13-Sep-2025 02:21:55 JST Kevin Beaumont Kevin Beaumont
      in reply to

      Unite are calling on the government to urgently intervene over the Jaguar Land Rover cyber incident, to introduce a furlough scheme for their suppliers.

      https://www.unitetheunion.org/news-events/news/2025/september/jlr-supply-chain-workers-impacted-by-cyberattack-must-receive-government-support-says-unite

      In conversation about a day ago permalink

      Attachments


    • Embed this notice
      Gary Parker :party_porg: (witewulf@cyberplace.social)'s status on Saturday, 13-Sep-2025 03:46:35 JST Gary Parker :party_porg: Gary Parker :party_porg:
      in reply to

      @GossiTheDog as a tax payer, but also a union member: screw that.

      JLR should have insurance to cover this.

      In conversation about a day ago permalink
    • Embed this notice
      Just_Patch_It (just_patch_it@cyberplace.social)'s status on Saturday, 13-Sep-2025 05:27:51 JST Just_Patch_It Just_Patch_It
      in reply to

      @GossiTheDog Have they not heard of Disaster Recovery? It’s also called “Business Continuity Plan” just in case I’m not clear.

      In conversation about 21 hours ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 13-Sep-2025 05:36:57 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • Gary Parker :party_porg:
      • greem

      @greem @WiteWulf yeah it’s exactly that, JLRs suppliers. Because JLR have ceased production, their downstream suppliers essentially have no work.

      In conversation about 21 hours ago permalink
    • Embed this notice
      greem (greem@cyberplace.social)'s status on Saturday, 13-Sep-2025 05:36:59 JST greem greem
      in reply to
      • Gary Parker :party_porg:

      @WiteWulf

      It isn't JLR that's affected here though (although they are, and friends of mine who work for them are currently having nightmares) - it's their suppliers. By that argument, they should also have insurance.
      I guess tying a small company's entire output to one upstream behemoth used to be a safe bet, but not now.

      @GossiTheDog

      In conversation about 21 hours ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 13-Sep-2025 15:07:04 JST Kevin Beaumont Kevin Beaumont
      in reply to

      JLR have lost between £50m-£100m so far according to BBC estimates https://www.bbc.co.uk/news/articles/czdjn0lv64ro

      In conversation about 11 hours ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: ichef.bbci.co.uk
        Jaguar Land Rover suppliers 'face bankruptcy' due to hack crisis
        The government has been urged to "act fast" to protect hundreds of jobs following the cyber attack.
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 13-Sep-2025 15:18:10 JST Kevin Beaumont Kevin Beaumont
      in reply to

      If anybody is interested, TCS’ website says JLR outsourced cybersecurity (not sure which bits) to it a few years ago.

      TCS also run security operations and monitoring for Co-op (my old team) along with their IT and IT helpdesk, and M&S secops monitoring, IT and IT helpdesk.

      In conversation about 11 hours ago permalink
    • Embed this notice
      VessOnSecurity (bontchev@infosec.exchange)'s status on Saturday, 13-Sep-2025 15:32:44 JST VessOnSecurity VessOnSecurity
      in reply to

      @GossiTheDog I wonder how big the ransom was...

      In conversation about 11 hours ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 13-Sep-2025 15:32:44 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • VessOnSecurity

      @bontchev they likely paid it

      In conversation about 11 hours ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Saturday, 13-Sep-2025 17:01:25 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • Mark :unverified: :thisisfine:

      @sneakymonkey they aren’t, their suppliers are

      In conversation about 9 hours ago permalink
    • Embed this notice
      Mark :unverified: :thisisfine: (sneakymonkey@infosec.exchange)'s status on Saturday, 13-Sep-2025 17:01:26 JST Mark :unverified: :thisisfine: Mark :unverified: :thisisfine:
      in reply to

      @GossiTheDog

      I don’t get it..

      BBC news article,

      “However, the company made a pre-tax profit of £2.5bn in the year to the end of March, which implies it has the financial muscle to weather a crisis that lasts weeks rather than months.”

      But they call for Gov for furlough…

      In conversation about 9 hours ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.