Publishing giant Macmillan has forced the closure of its network and offices as it tries to recover from a security incidentthat appears to be a ransomware attack.
See also: Walmart: Denies being attacked by Yanluowang ransomware

The attack reportedly occurred over the weekend, with the company shutting down all of systems to prevent the attack from spreading.
Publishers Weekly first reported the incident, seeing emails from Macmillan stating that it had suffered a “security incident, which includes the encryption of certain files on our network.” The use of encryption in the attack suggests it was a ransomware attack.
Since then, Macmillan editors have been unusually transparent about the security incident, telling agents and clients that they are not being ignored, but have lost access to their systems, emails and files.
See also: NCSC on ransomware: The biggest global cyber threat
While Publishers Weekly said that Macmillan's sales team was warning that the outage could cause delays in book shipments, Macmillan has already begun bringing its systems back online ,with employees now able to access emails .

At present, it is unclear which ransomware gang is behind the attack and whether and how much data has been stolen.
However, ransomware groups typically steal data before encrypting devices, with the intention of using it in double-blackmail attacks. This way, they can threaten their victims with publishing the stolen data if they don't pay the ransom they're asking for.
See also: Vice Society: Ransomware attack on University of Innsbruck
In cases where data is actually extracted during the attack and the ransom, we will likely see a ransomware operation publish the stolen files on its data leak website within a few weeks.
Macmillan has not yet made any additional statements regarding the security incident that affected its systems.
