The Scottish Mail on Sunday

Police f iles posted on dark web after shadowy Russian hackers target Scottish IT f irm

- By Kevin O’Sullivan, Michael Powell and Ashlie McAnally

POLICE in Scotland are investigat­ing after confidenti­al informatio­n held by forces around the country was stolen by Russian cyberhacke­rs.

In a hugely embarrassi­ng security breach, a notorious gang has managed to hack a Scottish IT firm that handles access to the UK’s police national computer (PNC).

Swathes of police data plundered from the firm’s files has been released on the dark web with the threat of more to follow.

The hackers – a notorious Russian gang called Clop – are believed to have demanded a ransom from the company after launching a ‘phishing’ attack in October that gave it access to material including the PNC which holds personal informatio­n and records of 13 million people.

The firm targeted by the hackers is IT management company Dacoll, based in Bathgate, West Lothian.

After the data was stolen, the hackers demanded a ransom. But when Dacoll refused to pay, the cyber gang uploaded hundreds of the files onto the dark web, a hidden area of the internet only accessible through a specialise­d web browser.

It includes images of motorists which Clop appears to have taken from the national vehicle licence plate recognitio­n camera system. Raw footage from Automatic Number Plate Recognitio­n (ANPR) includes close-up images of the faces of drivers who have been snapped speeding by motorway gantry or traffic monitoring cameras.

It is unclear what additional – and potentiall­y even more sensitive –

‘Damage caused by this leak is unfathomab­le’

informatio­n Clop has taken and may release on the dark web, where it could be scooped up by fraudsters and blackmaile­rs.

Philip Ingram, a national security expert and former British military intelligen­ce colonel, said: ‘This is an extremely serious breach of a company that is providing a capability to police forces across the UK.

‘The damage caused by this kind of data leak is unfathomab­le as it brings into question the oversight and cybersecur­ity arrangemen­ts that exist between multiple public and private organisati­ons to manage sensitive law enforcemen­t data.’

Dacoll was establishe­d in 1969 by electrical engineer Brian Colling, who had previously repaired washing machines and fridges before doing national service with the RAF. The 88-year-old has grown the company into a UK-wide IT solutions provider with 160 staff.

One of Dacoll’s subsidiari­es, NDI Technologi­es, provides a ‘critical’ service for 90 per cent of the UK police forces, allowing officers to gain remote access to the PNC when they are on the beat or in cars. Another Dacoll firm, NDI Recognitio­n Systems, provides IT support for the ANPR systems used by the police, Highways England and the DVLA.

Last night, a spokesman for the company said: ‘Dacoll Group can

Ransomware attack on company that manages access to UK national crime computer ++ GCHQ launches probe

confirm we were the victims of a cyber incident on an internal company network on October 5.

‘Steps were taken to contain and mitigate the incident, and we were able to quickly start returning to our normal operationa­l levels.

‘We have kept everyone affected fully informed. There is an ongoing criminal investigat­ion led by Police Scotland. All relevant agencies including the Informatio­n Commission­er’s Office have been notified.’

UK security services have also launched investigat­ions into the cyber attack.

A spokesman for the National Cyber Security Centre, which is part of GCHQ, said: ‘We are aware of this incident and are working with law enforcemen­t partners to fully understand and mitigate any potential impact.’

Clop has earned millions of pounds through ransomware hacks in the past two years. Victims have included the oil giant Shell, American bank Flagstar and the University of California.

Like many ransomware groups, they send phishing emails to employees which appear genuine but actually contain a virus that harvests data when opened by the unsuspecti­ng recipient.

An NCA spokesman said: ‘The National Crime Agency is aware of an incident affecting Dacoll and we are supporting the criminal investigat­ion, which is being led by Police Scotland.’

Last night, Police Scotland confirmed that it is investigat­ing the incident. A spokesman said: ‘Police Scotland’s Cyber Investigat­ion Unit has received a report of an incident concerning Dacoll and an investigat­ion is under way into the matter.

‘Inquiries are ongoing and we are working with our partners to support them.’

 ?? ?? BREACH: Clop gang’s data hack was passed to experts attached to GCHQ, right
BREACH: Clop gang’s data hack was passed to experts attached to GCHQ, right

Newspapers in English

Newspapers from United Kingdom