Attacker steals customer data from UK rail operator LNER during break-in at supplier


One of the UK’s largest rail operators, LNER, is the latest organization to spill user data via a third-party data breach.… It confirmed the incident on Wednesday, saying customer contact details and “some information about previous journeys” was accessed at a third-party supplier.

London North Eastern Railway (LNER) did not name the third party responsible for the intrusion, but assured that whichever company it was, it does not store details such as bank accounts, payment cards, or passwords.

Read more…
Source: MSN News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • UK: Thousands of EU citizens ‘wrongly fined for breaching Ulez rules’ in potential record data breach

    January 26, 2024

    Hundreds of thousands of EU citizens were wrongly fined for driving in London’s Ultra Low Emission Zone (Ulez), amid claims of a record data breach. Several EU countries have accused Transport for London (TfL) of illegally obtaining the names and addresses of their citizens to issue the penalties, The Guardian reports. The paper said more than ...

  • UK councils remain downed by cyberattack

    January 26, 2024

    Three local councils in the United Kingdom continue to experience disruption to their online services, a week after confirming a cyberattack had knocked some systems offline. The councils for Canterbury, Dover, and Thanet — all of which are based in the U.K. county of Kent and have a combined population of almost 500,000 residents — said ...

  • UK: Cybercriminals claim to have stolen data from Southern Water

    January 24, 2024

    Cybercriminals claim they have stolen data from a water company’s IT systems. Southern Water, which has hundreds of thousands of customers in Kent, says it has detected suspicious activity and launched an investigation led by cybersecurity experts. But it says there is no evidence to suggest “customer relationships or financial systems” have been affected. In a ...

  • New TTPs observed in Mint Sandstorm campaign targeting high-profile individuals at universities and research orgs

    January 17, 2024

    Since November 2023, Microsoft has observed a distinct subset of Mint Sandstorm (PHOSPHORUS) targeting high-profile individuals working on Middle Eastern affairs at universities and research organizations in Belgium, France, Gaza, Israel, the United Kingdom, and the United States. In this campaign, Mint Sandstorm used bespoke phishing lures in an attempt to socially engineer targets into downloading ...

  • Hackers target UK in huge cyber attack ‘in response to airstrikes in Yemen’

    January 13, 2024

    Hackers say they launched a massive cyber attack against the UK in response to airstrikes in Yemen. Anonymous Sudan said Friday’s raid on an internet company was also because Britain had shown “support” for Israel. In a statement on messaging platform Telegram, the group warned: “Big attack on UK soon, in response to the air attacks ...

  • Cyber-hackers target UK nuclear waste company RWM

    December 31, 2023

    Hackers have targeted the company behind a £50bn project to build a vast underground nuclear waste store in Britain, its developer has said. Radioactive Waste Management, the company behind the Geological Disposal Facility (GDF) project, has said that hackers unsuccessfully attempted to breach the business using LinkedIn. RWM is the government-owned entity behind a trio of ...