In December, the British newspaper The Guardian was hit by a serious security and has now confirmed that it was a ransomware attack which led to a data breach of employees in the UK.

On Wednesday afternoon, Anna Bateson (chief executive of Guardian Media Group) and Katharine Viner (editor-in-chief) emailed staff to update them on the new findings from the investigation.
The ransomware attack was described as a “highly sophisticated cyberattack that led to unauthorized access to selected elements of The Guardian’s network,” which was likely triggered by phishing email. The Guardian assured its readers and subscribers that there was no indication that their personal data had been accessed.
See also: RAT malware campaign uses multilingual files to avoid detection
He further stated that it is unlikely that the personal data of Guardian staff in the US or Australia.
The UK data protection authority, the Information Commissioner's Office, was informed of the attack, as were UK law enforcement authorities.
According to the email sent to employees, there is currently no evidence to suggest that any of the compromised data of UK employees has been exposed online. The ransomware attack was detected on December 20 and affected parts of The Guardian's technology infrastructure.
See also: Royal Mail: Breach linked to LockBit ransomware group
Employees, most of whom had been working from home after the attack, were able to continue some work and online news publishing was not affected.

“We believe this was a criminal ransomware attack and not a specific targeting of The Guardian as a organization media,” Bateson and Viner said. “These attacks have become more frequent and sophisticated over the past three years, targeting organizations of all sizes and types, in all countries.” In order to accurately assess the impact of the attack and respond to it, The Guardian has called on external professionals who specialize in this. The company is also continuing to work on restoring systems.
The Guardian expects some essential systems to be up and running within the next fortnight. However, to give IT staff time to restore networks and systems more quickly, the return of the remaining staff to the offices has been delayed until early February.
See also: Hackers exploit major vulnerability in Control Web Panel
According to KnowBe4 ’s Erich Kron , the ransomware attack on The Guardian should serve as a lesson: regardless of industry, anyone can be the target of a ransomware attack . “ To prepare for such attacks, organizations should ensure they have good, tested, off-line backups and should ensure they train their staff on how to recognize and report emails phishing ,” Kron told Infosecurity.
