Fallout from Guardian cyber attack to last at least a month

BillionPhotos.com – stock.adobe.

The Guardian newspaper’s offices remained shut into the New Year following a supposed ransomware attack, with disruption likely to last some time

Alex Scroxton

By

Published: 05 Jan 2023 12:30

Staffers at the UK’s Guardian newspaper have been informed that their offices will remain shut for at least a month, following the 20 December 2022 suspected ransomware attack on the media organisation’s systems.

According to an internal notice seen by media sector publication Press Gazette, Guardian Media Group (GMG) chief executive Anna Bateson said at the beginning of the week that journalists and other staff would have to continue to work from home.

She said that a fortnight after the incident, a number of key systems still remain offline and are unavailable, and that this was a result of the steps the organisation took to secure itself.

“To reduce strain on our networks and help the enterprise tech, ESD and other involved teams focus on the most essential fixes, everyone must work from home until at least Monday 23 January in the UK, US and Australia, unless you are specifically asked to work from our offices,” said Bateson.

Other reporting described a “total nightmare”, with problems supposedly affecting print production, financial systems including payroll and expenses, and even the on-site canteen at GMG’s London office.

The incident is understood to have begun on the evening of Tuesday 20 December and. according to the Guardian, which broke the news of the incident itself the following day, affected unspecified parts of its infrastructure, although its online publishing systems were not affected, meaning the newspaper was able to continue to publish stories online.

Two weeks on, confirmed details on the incident remain sparse and GMG has not made any further statements as to the precise nature of the incident, although its online subscriber help centre appears to have acknowledged that it was indeed a ransomware attack.

Although it cannot be stated for certain that the attack on GMG was a targeted incident, what can be said with relative confidence is that media outlets are increasingly targeted by threat actors as such incidents can prove highly disruptive and are likely to resonate with a far wider audience.

It can also be fairly said that reporting on major international incidents such as Russia’s war on Ukraine may leave a title exposed to malicious actions by Russia-backed or aligned groups. Additionally, any publisher of titles that skew to the different ends of the political spectrum – in GMG’s case, its titles lean to the liberal centre and left wings – may also find themselves the targets of politically motivated hacktivism.

Dan Vasile, vice-president of strategic development at BlueVoyant, and a former cyber security operator in the media sector, conducted research into the security challenges that the media industry faces in 2022.

“The media industry is often targeted because of the influence it holds. Media companies get high-volume traffic and are trusted by their audience,” Vasile told Computer Weekly in emailed comments.

“This puts a target squarely on the backs of news organisations. The domino effect is in full force: Thomson Reuters, The New York Post, Fast Company, and now The Guardian, among countless previously reported breaches.

“Generally speaking, large media organisations have structured cyber security programs in place, but as companies’ digital estates become well defended, malicious actors turn their attention to the supply chain, opening up a whole new attack surface,” he said.

The BlueVoyant research – which was published in August 2022 – said there were material security failings across the media sector’s supplier ecosystem, compounding the issue.

The incident at GMG also demonstrates a firmly established trend of executing large-scale cyber attacks around major holiday periods – the 2021 attack on Kaseya that unfolded over the US 4 July holiday being an excellent example – with IT and security teams stretched thinly due to holiday cover, the chances of a successful attack can slightly increase.

Read more on Data breach incident management and recovery

Read More
Larisa Fetzer

Latest

Glenmark Pharma Q1 profit jumps over 10-fold as India, North America businesses power growth

Pharma major Glenmark Pharmaceuticals Ltd on Friday (July 31) reported a 930% year-on-year increase in consolidated net profit to ₹483 crore for the first quarter, compared with ₹47 crore in the corresponding quarter last year. The company's revenue rose 23% year-on-year to ₹4,018 crore, compared with ₹3,264 crore a year earlier. At the operating level

Crypto Hack : COLDCARD Wallet Flaw Linked to $38 Million BTC Theft

Coinkite has disclosed a critical entropy-generation flaw affecting certain COLDCARD Mk2 and Mk3 firmware versions that may have weakened the security of wallet recovery seeds. According to PeckShield, the vulnerability has been linked to the theft of about $38 million in Bitcoin. Users who generated seeds using affected firmware are advised to update to the

Could STX See a Resurgence Through Institutional Bitcoin Capital?

Stacks (STX) powering Bitcoin-native Finance targets idle Bitcoin, an op portunity that remains one of the largest untapped pools of capital in crypto. According to Binance Research, less than 1% of total BTC supply is currently used productively across DeFi, against staking ratios above 30% for Ethereum and 60% for Solana. Whoever converts even a

FTX Repayments: Creditors to Receive Another $900 Million

FTX will begin distributing another $900 million to creditors starting tomorrow, bringing total repayments since the exchange’s 2022 collapse to nearly $10 billion. Many creditors are expected to recover more than 100% of their original claim value based on the bankruptcy filing date, while some smaller accounts could receive up to 120%. The latest payout

Newsletter

Don't miss

Glenmark Pharma Q1 profit jumps over 10-fold as India, North America businesses power growth

Pharma major Glenmark Pharmaceuticals Ltd on Friday (July 31) reported a 930% year-on-year increase in consolidated net profit to ₹483 crore for the first quarter, compared with ₹47 crore in the corresponding quarter last year. The company's revenue rose 23% year-on-year to ₹4,018 crore, compared with ₹3,264 crore a year earlier. At the operating level

Crypto Hack : COLDCARD Wallet Flaw Linked to $38 Million BTC Theft

Coinkite has disclosed a critical entropy-generation flaw affecting certain COLDCARD Mk2 and Mk3 firmware versions that may have weakened the security of wallet recovery seeds. According to PeckShield, the vulnerability has been linked to the theft of about $38 million in Bitcoin. Users who generated seeds using affected firmware are advised to update to the

Could STX See a Resurgence Through Institutional Bitcoin Capital?

Stacks (STX) powering Bitcoin-native Finance targets idle Bitcoin, an op portunity that remains one of the largest untapped pools of capital in crypto. According to Binance Research, less than 1% of total BTC supply is currently used productively across DeFi, against staking ratios above 30% for Ethereum and 60% for Solana. Whoever converts even a

FTX Repayments: Creditors to Receive Another $900 Million

FTX will begin distributing another $900 million to creditors starting tomorrow, bringing total repayments since the exchange’s 2022 collapse to nearly $10 billion. Many creditors are expected to recover more than 100% of their original claim value based on the bankruptcy filing date, while some smaller accounts could receive up to 120%. The latest payout

Hyperliquid News: HYPE Whales Unstake Millions as Protocol Revenue Tops $1.21 Billion

Hyperliquid is drawing attention after large HYPE holders unstaked millions of tokens, including one wallet that withdrew 1.02 million HYPE and another that transferred 1.89 million HYPE worth about $105.9 million to institutional brokers, a move often associated with over-the-counter sales. Despite the whale activity, the protocol generated $1.18 million in daily fees and burned

‘Sabah is open for business’: Hajiji courts investors with promise of sustainable growth, carbon‑negative credentials

Sabah is pitching itself as an Asia-Pacific hub for impact investing, betting that its forests, biodiversity and natural resources can become drivers of economic growth as it seeks private capital for sustainable development. — Picture by Firdaus Latif By Julia Chan First Published: Monday, 13 Jul 2026 11:44 AM MYT KOTA KINABALU, July 13 —

Want Your Business to Be Seen Everywhere? Meet Tonia Ryan, Creator of Fix Your Search

Some people are good at their jobs. Then there is Tonia Ryan, who has turned “getting found online” into something close to magic. She is the creator of Fix Your Search, and if you have ever wondered why some businesses pop up everywhere while others seem invisible...

Grey Business processes $61 million as stablecoins dominate payments

Grey Business enables startups and SMEs to open US Dollar (USD) corporate accounts, send and receive international payments, convert currencies, and transact using stablecoins such as USDC and USDT...