Leicester City Council shut down IT systems and phone lines after cyberattack
- Organization
- Leicester City Council
- Exploit
- Ransomware
- Industry
- Municipal Government
Leicester City Council in England shut down its IT systems and telephone lines on Thursday, 7 March 2024 after identifying a cyber incident. The shutdown took out most of the authority's digital services and left residents unable to reach staff on the usual numbers.
The council set up emergency phone lines and added more over the following days, publishing the numbers on its website. On 11 March, Richard Sword, the council's strategic director of city developments and neighbourhoods, said it would take until at least the middle of that week before the recovery process could begin, and apologised for the inconvenience. The council said officers were working to keep frontline services running and that it was coordinating with cyber security partners, law enforcement and other councils hit by similar attacks.
Most online service portals and customer service lines were operating again by late March, including waste and recycling, school registrations and libraries.
On 1 April the INC Ransom group claimed the attack on its leak blog, saying it had taken three terabytes of council data, then quickly removed the post. Two days later, on 3 April 2024, the council confirmed that around 25 confidential documents had been published, among them rent statements, applications to buy council housing, passport documents and bank statements. It said it was contacting affected individuals and was working with Leicestershire Police and the National Cyber Security Centre.
Sources
- Leicester City Council, Council expects IT shutdown to continue until at least midweek
- The Register, INC Ransom claims 'cyber incident' at UK city council
- Infosecurity Magazine, Leicester Council Confirms Confidential Documents Leaked in Ransomware Attack
- Leicester City Council, Cyber incident update: 3 April 2024