Arnold Clark cyber attack claimed by Play ransomware gang

Oleksandr – stock.adobe.com

A cyber attack that struck car dealer Arnold Clark prior to Christmas has been claimed as the work of the Play ransomware cartel

Alex Scroxton

By

Published: 25 Jan 2023 14:30

Glasgow-based Arnold Clark – one of the UK’s largest car dealer networks, which made a billionaire out of its founder – is facing a multimillion-pound ransom demand from the Play double extortion ransomware cartel following a cyber attack on its systems.

The attack on the organisation took place in the run-up to Christmas and saw staff resorting to pen and paper to record customer transactions after being locked out of their systems. It was also unable to complete handovers of new vehicles as a result.

In the wake of the attack, Arnold Clark disconnected its systems voluntarily after an external security consultant warned it of suspicious traffic on its network. It then conducted an extensive review of its IT estate in collaboration with its cyber partners. It said its priority had been to protect customer data, its own systems and its third-party partners, and that this had been achieved.

However, according to the Mail on Sunday, which was first to report the latest developments, an individual claiming association with Play posted a 15GB tranche of customer data stolen in the incident to the dark web. The data is understood to include addresses, passport data and national insurance numbers. Predictably, they are threatening to release a much larger amount of data if not paid off.

In a statement provided to Automotive Management magazine, Arnold Clark said its investigations were ongoing, and it was now trying to establish what data had been compromised as a priority, at which point it will contact affected customers. It has also been working with law enforcement, and the incident has been notified to the Information Commissioner’s Office (ICO) in accordance with its legal obligations. The organisation did not respond to a request for comment from Computer Weekly.

After springing to prominence in mid-2022 with a string of cyber attacks on organisations in Latin America, the Play ransomware cartel has become one of the more active and dangerous groups currently operating.

Most famously, it was behind the 2 December 2022 attack on Rackspace, which saw customers left out in the cold after the IT services supplier was forced to shut down its Hosted Exchange business.

Rackspace later revealed the gang accessed the Personal Storage Tables (PSTs) of 27 of its customers, out of a total of 30,000, but said there was no evidence that the data was viewed, obtained, misused or disseminated in any way.

The gang was confirmed to have hit Rackspace by chaining a pair of vulnerabilities tracked as ProxyNotShell/OWASSRF in a server-side request forgery that allowed it to achieve remote code execution (RCE) through Outlook Web Access (OWA).

Prior to its enthusiastic take-up of OWASSRF, the group favoured compromised virtual private network (VPN) accounts, as well as domain and local accounts, and exposed remote desktop protocol (RDP) servers, to gain initial access. It also exploited disclosed vulnerabilities in Fortinet’s FortiOS operating system.

Play draws its name from the .play extension it appends to encrypted files, and has been observed exhibiting broadly similar behaviour to the Hive and Nokoyawa operations, according to intelligence gleaned by researchers at Trend Micro, who suggested they may be run by the same people. There exists also the possibility of a link to the Quantum ransomware, itself thought to be a splinter group of Conti.

Whether or not Arnold Clark fell victim to the same attack chain is unconfirmed.

Read more on Hackers and cybercrime prevention

Read More
Tomi Schewe

Latest

Kusha Kapila’s Underneat co-founder left ₹3 crore job to travel the world: ‘People said I was crazy’

Reflecting on his career before taking the break, he said his work routine had become all-consuming. For 13 years, he spent most of his time at work. Underneat CEO Vimarsh Razdan says quitting ₹3 crore job to travel reshaped his approach to work. Vimarsh Razdan, co-founder and chief executive officer (CEO) of actor Kusha Kapila's

Top Stories | Iran tensions rise, Fed stands pat, M&M delivers, Assam floods and more

It was another volatile day on Dalal Street, but the bulls managed to stay in control. Strong foreign buying, corporate earnings, and optimism from global tech giants like Microsoft helped benchmarks finish in the green. Closing bell | Five key takeaways from today's market action Indian shares ended on a positive note in a volatile

Pricol Q1 profit jumps 34% as revenue crosses ₹1,100 crore

Auto components maker Pricol reported a strong June quarter, with net profit rising 34% and revenue growing 24% year-on-year. Higher operating profit and a modest improvement in margins reflected healthy business momentum despite cost pressures. 2 Min Read Pricol Ltdreported a 34.3% year-on-year (YoY) rise in consolidated net profit for the first quarter ended June

Newsletter

Don't miss

Kusha Kapila’s Underneat co-founder left ₹3 crore job to travel the world: ‘People said I was crazy’

Reflecting on his career before taking the break, he said his work routine had become all-consuming. For 13 years, he spent most of his time at work. Underneat CEO Vimarsh Razdan says quitting ₹3 crore job to travel reshaped his approach to work. Vimarsh Razdan, co-founder and chief executive officer (CEO) of actor Kusha Kapila's

Top Stories | Iran tensions rise, Fed stands pat, M&M delivers, Assam floods and more

It was another volatile day on Dalal Street, but the bulls managed to stay in control. Strong foreign buying, corporate earnings, and optimism from global tech giants like Microsoft helped benchmarks finish in the green. Closing bell | Five key takeaways from today's market action Indian shares ended on a positive note in a volatile

Pricol Q1 profit jumps 34% as revenue crosses ₹1,100 crore

Auto components maker Pricol reported a strong June quarter, with net profit rising 34% and revenue growing 24% year-on-year. Higher operating profit and a modest improvement in margins reflected healthy business momentum despite cost pressures. 2 Min Read Pricol Ltdreported a 34.3% year-on-year (YoY) rise in consolidated net profit for the first quarter ended June

Seoul Police Arrest Three in $19M Fake XRP Staking Scam

South Korean police have uncovered one of the country’s biggest XRP related crypto scams after arresting three suspects linked to a fake staking platform that promised fixed monthly returns.Ā  Authorities say the fraud pulled in about 3.4 million XRP from 71 victims, while blockchain tracking shows total wallet flows linked to the operation reached 27.3

ā€˜Sabah is open for business’: Hajiji courts investors with promise of sustainable growth, carbon‑negative credentials

Sabah is pitching itself as an Asia-Pacific hub for impact investing, betting that its forests, biodiversity and natural resources can become drivers of economic growth as it seeks private capital for sustainable development. — Picture by Firdaus Latif By Julia Chan First Published: Monday, 13 Jul 2026 11:44 AM MYT KOTA KINABALU, July 13 —

Want Your Business to Be Seen Everywhere? Meet Tonia Ryan, Creator of Fix Your Search

Some people are good at their jobs. Then there is Tonia Ryan, who has turned ā€œgetting found onlineā€ into something close to magic. She is the creator of Fix Your Search, and if you have ever wondered why some businesses pop up everywhere while others seem invisible...

Grey Business processes $61 million as stablecoins dominate payments

Grey Business enables startups and SMEs to open US Dollar (USD) corporate accounts, send and receive international payments, convert currencies, and transact using stablecoins such as USDC and USDT...