Kensington and Chelsea Council hit by ‘criminal’ cyberattack

Kensington and Chelsea Council hit by ‘criminal’ cyberattack

Kensington and Chelsea Council has been hit by a cyberattack with ‘criminal intent’.

A statement from the council says the attack occurred with ‘criminal intent, with data copied and taken away.’

The statement read: “Our cybersecurity team detected and contained the attack quickly. There is no evidence of any lateral movement, so we believe the attack was stopped before it spread to third-party systems that help us provide services and store data.

“We confirmed a data breach with the Information Commissioner’s Office at the earliest opportunity. We are now investigating that breach for any sensitive data. Small samples show that some of the resident data copied is likely to contain sensitive data and personal information.

“It is possible that any data copied and taken from us could be misused or published. We are planning accordingly for this, working with law enforcement at every step.”

Industry experts have been giving their opinions about what we know so far.

Sensitive data at risk

Raghu Nandakumara, VP of Industry Strategy at Illumio, said: “Cyberattacks on councils put sensitive resident data at risk and can cause real distress for all those affected. Cybercriminals are likely to exploit stolen data through seasonal scams, such as fraudulent fuel payment schemes.

“The challenge for councils is that they have tight budget constraints and limited resources. This is why the government has introduced a new cyber action plan for the public sector, with a specific push of organisations being able to contain cyberattacks. Attacks are only going to increase, so councils must focus on limiting the impact to ensure that sensitive information is kept safe and that services remain operational.

“With limited resources, councils cannot prevent every attack but containing them is entirely achievable, and it’s what citizens rightly expect.”

Breaches likely to continue

Dan Panesar, CRO at Certes, said: “What makes this breach particularly uncomfortable is that it’s happening after years of significant government investment in preventative cyber controls.

“The UK government and the National Cyber Security Centre have spent tens of millions of pounds rolling out defences like Protective DNS (PDNS) across public-sector organisations. PDNS is designed to block access to known malicious domains, and aims to significantly reduce threats like ransomware, malware, and phishing.

“But incidents like this underline the significant limits of this approach. Blocking bad domains protects the front door; it doesn’t protect the data once an attacker gets inside or sits dormant in the system.

“Local authorities hold some of the most sensitive data in society social care, housing and safeguarding records and once that data is copied, no amount of ‘containment’ can reverse the damage.

“The real issue is strategy. Public-sector cyber defence is still overly focused on keeping attackers out, rather than assuming compromise and making stolen data unusable. Until those changes are made, these breaches will continue regardless of how much is spent on perimeter controls.”

Stretched resources

Jon Abbott, CEO and Co-founder at ThreatAware, said: “With councils providing a wide range of services, from council tax and housing to social care, the data they store covers a broad range of demographics, therefore making it attractive to any cybercriminal. These data points are highly sensitive and is why councils must focus on addressing the security fundamentals.

“Councils have advised people to remain vigilant and, with us now in the middle of winter, extra caution should be taken with any unsolicited communications relating to matters such as winter fuel payments. However, attackers are often willing to wait months before launching phishing campaigns.

“Many councils operate under tight budget constraints, limiting their ability to invest in the latest cybersecurity technologies or even to maintain adequate staffing levels within their IT security teams. This, combined with the fact that councils manage large and complex networks involving third-party suppliers and outdated IT systems, means the challenge is immense.

“Fundamentals such as basic cyberhygiene, visibility across assets, and robust user validation, are the most effective ways to improve security standards, while avoiding additional strain on already stretched resources.”

Browse our latest issue

Intelligent Gov.tech Issue 01

View Magazine Archive