Houston Chronicle

Ransomware attack may knock payroll software offline for weeks

- By Joe Williams

Ultimate Kronos Group subsidiary Kronos, a provider of payroll and time-sheet software, said it suffered a ransomware attack that may force its systems offline for weeks.

The company became aware of the issue over the weekend and began steps to “investigat­e and mitigate” it, according to a message the company sent to its customers and posted on its website. Kronos said it was “working with leading cyber-security experts to assess and resolve the situation,” but warned users to find alternativ­e options given the delay expected before its software is working again.

“While we are working diligently, our Kronos Private Cloud solutions are currently unavailabl­e,” the company said. “Given that it may take up to several weeks to restore system availabili­ty, we strongly recommend that you evaluate and implement alternativ­e business continuity protocols related to the affected UKG solutions.”

Other products, like UKG Pro, weren’t affected, the company said. Kronos has a widespread customer base, noting on its website that clients include Tesla Inc., the city of Cleveland, Kum & Go convenienc­e stores, MGM Resorts Internatio­nal and multiple health agencies. Users, including New York City’s Metropolit­an Transporta­tion Authority, were unable on Monday to access Kronos services.

Kronos hasn’t said whether the attack is related to the Log4Shell vulnerabil­ity discovered this past weekend, which U.S. cybersecur­ity officials called “a significan­t threat.”

Alongside the ransomware attack, the company’s customer conference, UKG Connection­s, kicked off in Las Vegas on Monday.

Newspapers in English

Newspapers from United States