Royal Mail investigates data leak claims, no impact on operations
英国皇家邮政正在调查一起涉嫌数据泄露事件,第三方服务提供商Spectos GmbH的系统被入侵,导致客户数据外泄。攻击者声称窃取了皇家邮政客户的个人信息及内部文件,并通过论坛发布。皇家邮政表示尚未确认自身系统遭入侵,并强调运营未受影响。此次事件可能与2021年一起恶意软件事件有关,当时一名Spectos员工的凭证被盗用。皇家邮政此前也曾遭遇网络攻击和系统中断。 2025-4-2 16:45:19 Author: www.bleepingcomputer.com(查看原文) 阅读量:11 收藏

Royal Mail

​Royal Mail is investigating claims of a security breach after a threat actor leaked over 144GB of data allegedly stolen from the company's systems.

While the British postal service has yet to confirm that its systems were breached, a spokesperson told BleepingComputer that Royal Mail is aware of an incident at Spectos GmbH, a third-party data collection and analytics service provider.

"We are aware of an incident which is alleged to have affected Spectos, a supplier of Royal Mail. We are working with the company to investigate the issue and establish what impact there may be regarding their data," BleepingComputer was told. "We can confirm there has been no impact on Royal Mail operations and services continue to function as normal."

Spectos also confirmed in a statement shared with BleepingComputer that its systems were breached on March 29, and the attackers gained access to customer data.

"Spectos GmbH has been the target of an ongoing cyber attack since March 29, 2025. According to the current status, unauthorized access to systems and personal customer data has occurred. The exact scope of the incident is currently the subject of intensive forensic investigations," a spokesperson told BleepingComputer.

The threat actor behind this leak (who uses the "GHNA" handle on BreachForums) released 16,549 files allegedly containing Royal Mail customers' personally identifiable information (including names, addresses, planned delivery dates, and more) and other confidential documents.

GHNA says the leaked documents also include Mailchimp mailing lists, datasets containing delivery/post office locations, the WordPress SQL database for mail agents.uk, internal Zoom meeting video recordings between Spectos and the Royal Mail Group, and more.

Royal Mail leak
Royal Mail leak on BreachForums (BleepingComputer)

​Breached using stolen credentials

While Royal Mail and Spectos have yet to share more information on the breach, cybersecurity company Hudson Rock says the attackers gained access to Royal Mail systems using the credentials of a Spectos employee compromised in a 2021 info stealer malware incident.

"In this case, the infected Spectos employee's credentials provided a gateway to Royal Mail Group's systems," Hudson Rock CTO Alon Gal said. "The stolen data sat dormant until recently, when it was weaponized in these high-profile leaks."

Stolen Spectos credentials
Stolen Spectos credentials (Hudson Rock)

This isn't the first time Royal Mail has dealt with a security breach since it was founded over 500 years ago. The British postal service was also breached two years ago in a cyberattack claimed by the notorious LockBit ransomware operation.

The January 2023 breach forced the company to halt international shipping services due to what it described as a "cyber incident" causing "severe service disruption." Royal Mail restored these services three weeks after the ransomware attack impacted its operations.

Another outage hit Royal Mail in November 2022, which took down tracking services for more than 24 hours.


文章来源: https://www.bleepingcomputer.com/news/security/royal-mail-investigates-data-leak-claims-no-impact-on-operations/
如有侵权请联系:admin#unsafe.sh