Sensitive and confidential data stolen from Hackney Council has been leaked online, three months after the authority was hit by a ransomware attack. A hacking group called Pysa/Mespinoza claims to have posted data stolen from the council during the attack on the dark web. The data allegedly exposed in the leak includes sensitive personal data of staff and UK, such as passport documents.

In October 2020, the London Council revealed that it had suffered a serious cyberattack that affected many of its services and IT systems . Now, the Council has said it is working with the NCSC , the National Crime Agency, the Information Commissioner's Office, the Metropolitan Police and other experts to examine the type and volume of information exposed in the breach, as well as the next steps to be taken to investigate the matter.
As Infosecurity Magazine reports, experts believe that the data has not been published in a widely available public forum and is not visible through internet search engines, adding that, for now, it appears that the vast majority of sensitive and personal information held by the London Council has not been affected, however, the Council and its partners are carefully reviewing the data and will support any directly affected individuals.

The Mayor of Hackney, Philip Glanville, said: “I fully understand the concerns of residents and staff about any risk to their personal data and we are working with our partners to assess the data that has been compromised as quickly and effectively as possible and to take action, including informing those affected. While we believe this breach will not directly impact the vast majority of Hackney residents and businesses, we regret the concern and disruption it will cause them. We are already working closely with the police and other partners to assess any immediate action we need to take and will share further information about additional action we will take as soon as possible.”

Matt Aldridge, Principal Solutions Architect, Carbonite & Webroot, also said: “Once a breach and data has been identified, no amount of ransom payment can guarantee that all copies of the data will be destroyed. That’s why it’s important for all organizations to invest in their cyber defenses and, where possible, have their approach validated by trusted independent third parties. Understanding the importance and sensitivity of all of an organization’s data is important, and different data types, locations and classifications need to be protected appropriately, with more investment and protection for safeguarding the most sensitive data within the organization. Regular reviews should be conducted to monitor this situation, as the locations, types and flows of data are constantly changing in any modern organization.”
