Microlise cyberattack knocked out DHL and Serco vehicle tracking in the UK

Organization
Microlise
Exploit
Ransomware
Industry
Technology

Microlise, a Nottinghamshire telematics company that supplies vehicle tracking to UK fleet operators, told the London Stock Exchange on October 31, 2024 that it had detected unauthorized activity on its network. The company took systems offline while it investigated, cutting off tracking services that several large customers relied on.

Serco was among the most visibly affected. Tracking units and panic alarms fitted to prisoner transport vans stopped working, and crews fell back on 30 minute check-ins and paper maps, although Serco said the systems were disabled only for a short time and its services were not interrupted. DHL lost delivery tracking used by Nisa Group convenience stores. The Register reported that Tesco was also contacted about the outage but declined to comment.

In a follow-up statement on November 6, Microlise said no customer systems data had been compromised but that some limited employee data was affected. It notified the staff involved and informed the Information Commissioner's Office. The AIM-listed company's shares fell about 16 percent after the disclosure and had not fully recovered a week later.

Microlise said it was making substantial progress containing and clearing the threat and expected services largely restored within a week. On November 22, 2024 the SafePay ransomware group claimed the attack, said it had taken 1.2 TB of data and gave the company under 24 hours to respond. Microlise repeated that no customer systems data had been compromised and said it did not expect a material financial impact.

Sources