Top Stories

Co-op cyber attack: Staff urged to keep cameras on in meetings

Joe Tidy
Cyber correspondent, BBC World Service
PA Media A hanging sign outside a shop showing the pale blue Co-op logoPA Media

Staff at the Co-op are being ordered to keep their cameras on during remote work meetings, and verify all attendees, as the company deals with an ongoing cyber attack.

In an internal email to the 70,000 members of staff at the supermarket, funeral service and insurance company, workers are being urged to be vigilant as IT teams work to ensure hackers aren't inside their systems.

"Don't record or transcribe Teams calls", the instructions say.

It disclosed on Wednesday that it had shut down parts of its IT systems in response to hackers attempting to gain access.

It comes as supermarket Marks & Spencer (M&S) struggles with a major ransomware attack. It is not known if the hacks are linked.

Cyber security consultant Jen Ellis says the email implies that Co-op is worried about the presence of hackers.

"Reminding employees to keep their cameras on during conference calls is one way of enabling work to continue while ensuring that everyone is really who they claim to be, and no one unexpected is participating in calls," she told the BBC.

On Wednesday, the company said it was taking "proactive measures" to fend off the attack which it said had had a "small impact" on its call centre and back office.

But the internal email shows the company has shut off all remote access.

No internal applications that require a VPN (Virtual Private Network) can be logged into from home and workers are being told to go to a Co-op location if they need to access work tools.

They are also being urged not to post any sensitive information into Teams chats and to report any suspicious messages or emails.

The internal email was first reported by ITV News and confirmed by Co-op to the BBC.

Co-op is insisting that the cyber attack is under control and that all measures are "proactive".

In the past, cyber criminals have accessed internal messaging systems of companies including Uber and Rockstar Games to spy on communications and post ransom demands.

These kinds of tactics were used by a group called Lapsus$ which was made up of English speaking teenagers - two of whom were arrested and convicted in the UK in 2023.

The attack against M&S is being linked to a potential spin of from Lapsus$ known as Scattered Spider which has been responsible for high profile hacks against MGM Grand casino and Transport for London (TfL).

As part of TfL's response to its cyber attack all staff had to report to security teams in person to ensure that the hackers were fully kicked out of IT systems.

The incident that has crippled M&S is a ransomware attack using the DragonForce cyber crime service.

The Metropolitan Police confirmed it is looking into the cyber attack at M&S.

"Detectives from the Met's cyber crime unit are investigating," it said in a statement.

M&S has also reported it to the National Cyber Security Centre (NCSC).

The BBC understands the body is urging other retailers to be vigilant but it's not thought that retailers are a specific target.

An NCSC spokesperson said: "The NCSC routinely engages with a whole range of organisations about the cyber threats that the UK faces and regularly reminds them about the steps they can take to be as resilient as possible."

A green promotional banner with black squares and rectangles forming pixels, moving in from the right. The text says: “Tech Decoded: The world’s biggest tech news in your inbox every Monday.”

Sign up for our Tech Decoded newsletter to follow the world's top tech stories and trends. Outside the UK? Sign up here.


Source link

Leave A Comment


Last Visited Articles


Info Board

Visitor Counter
0
 

Todays visit

42 Articles 8305 RSS ARTS 107 Photos

Popular News

🚀 Welcome to our website! Stay updated with the latest news. 🎉

United States

18.116.42.179 :: Total visit:


Welcome 58.556.45.579 Click here to Register or login
Oslo time:2025-05-04 Whos is online (last 10 min): 
1 - United States - 18.111.42.179
2 - Singapore - 27.228.228.263
3 - United States - 216.244.66.237
4 - United States - 2a93:2889:f899:8::
5 - United States - 2a03:2880:ff:7::
6 - Singapore - 48.828.828.888
7 - United States - 2a03:2880:f800:22::
8 - Singapore - 47.028.026.96
9 - Singapore - 664.669.643.66
10 - Singapore - 47.525.55.60
11 - Singapore - 47.228.23.44
12 - United States - 88.888.83.888
13 - United States - 2a03:2880:f800:57::
14 - United States - 2a03:2880:f800:f::
15 - Singapore - 47.448.445.440
16 - Singapore - 444.444.436.88
17 - Singapore - 47.727.57.273
18 - Singapore - 49.998.94.936
19 - United States - 2a03:2330:f300:d::
20 - United States - 2.245.49.22
21 - United States - 2a03:2880:f800:2::
22 - Singapore - 47.628.667.66
23 - United States - 0a03:0880:f800:3::
24 - United States - 0a03:0880:f800::
25 - United States - 2a06:2880:f800:68::
26 - Singapore - 334.333.338.33
27 - United States - 1a03:1880:f800:1b::
28 - United States - 2a01:2880:f800:5::
29 - Singapore - 47.028.34.078
30 - France - 54.36.648.252
31 - United States - 52.267.222.236
32 - Singapore - 47.128.27.17
33 - United States - 20.20.204.090
34 - United States - 98.84.939.999
35 - United States - 78.777.748.739
36 - United States - 22.200.24.236
37 - Singapore - 47.028.008.000
38 - United States - 77.209.737.234
39 - United States - 100.14.167.60
40 - United States - 3.235.275.72
41 - United States - 88.289.89.889
42 - Singapore - 47.338.336.43
43 - United States - 66.249.80.39
44 - United States - 11.235.151.19
45 - Singapore - 444.449.436.408
46 - United States - 66.206.47.667
47 - Singapore - 47.328.332.239
48 - Singapore - 47.428.47.244
49 - Singapore - 40.028.002.002
50 - Singapore - 333.339.329.73
51 - United States - 2a03:2880:f800:9::
52 - Singapore - 47.728.62.247
53 - United States - 2a03:2880:33ff:8::
54 - Singapore - 47.128.11.41
55 - Singapore - 46.628.666.626
56 - United States - 40.77.467.25
57 - United States - 2a03:2880:f800:3::
58 - Singapore - 47.128.34.97
59 - Singapore - 47.929.996.229
60 - United States - 2a03:2880:f800:93::
61 - Singapore - 47.928.29.204
62 - Singapore - 47.528.522.245
63 - Singapore - 994.999.930.298
64 - Singapore - 47.525.55.222
65 - United States - 2a73:2887:f877:4::
66 - Singapore - 47.028.008.006
67 - United States - 207.46.43.44
68 - United States - 2a03:2880:f800:4c::


Farsi English Norsk RSS