UK Research and Innovation (UKRI) has revealed that it has been hit by a ransomware attack, which has encrypted data and affected two of services . UKRI is a public sector body of the UK government, investing in science and research. It operates across the country with a budget of over £6 billion, funded by the Department for Business, Energy and Industrial Strategy.

Given the resources it works with, the company is an attractive target for ransomware gangs. Specifically, hackers target organizations with “deep pockets,” who are then forced to pay large sums of money to decrypt their data.
The UK’s Research and Innovation announced that it had been hit by a ransomware attack that resulted in being encrypted by a third party. However, the organisation did not provide further details about the security or who was behind it. This is because an investigation is currently underway to investigate the matter. The UK’s Research and Innovation only said the following: “We have reported the incident to the National Crime Agency, the National Cyber Security Centre and the Information Commissioner’s Office.”

The two services affected by the incident are a portal of the UK Research Office (UKRO) based in Brussels that offers an information service to subscribers, and an extranet used by UKRI boards for peer review activity. Both services have been suspended.
So far, there is no evidence that the attackers stole data from UKRI's systems. However, the organization notes that hackers have compromised grant applications and are checking information from the extranet service.

As BleepingComputer reports, the UKRO subscription service has 13,000 users and hackers may have stolen data from it, which could include personal information. If the investigation reveals theft , the UK Research and Innovation will contact the affected individuals.
The organization is unable to disclose further information until the incident assessment is complete, but is investigating the loss of personal, financial or other types of sensitive data.
