Guardian confirms Christmas 2022 cyber attack was ransomware

BillionPhotos.com – stock.adobe.

Guardian Media Group bosses confirm the 20 December cyber attack that left staff locked out of its London office and disrupted several key systems was an untargeted ransomware attack

Alex Scroxton

By

Published: 12 Jan 2023 9:30

Guardian Media Group (GMG), the parent organisation of the UK’s Guardian newspaper, has confirmed that the 20 December cyber attack on its systems – which left staff locked out of its London office and disrupted key systems including print production, payroll and expenses – was an opportunistic and likely untargeted ransomware attack.

In an email to staff circulated in the afternoon of Wednesday 11 January, GMG chief executive Anna Bateson and Guardian editor-in-chief Katharine Viner said that the personal data of UK staff was compromised in the “highly sophisticated” incident, which they believe to have begun via a phishing attack, but said it was not, as some had speculated, related to politically motivated hacktivism.

“We believe this was a criminal ransomware attack, and not the specific targeting of the Guardian as a media organisation,” they said. “These attacks have become more frequent and sophisticated in the past three years, against organisations of all sizes, and kinds, in all countries. We have seen no evidence that any data has been exposed online thus far and we continue to monitor this very closely.”

Bateson and Viner added that there was no evidence to suggest that any reader or subscriber data, nor any data on the organisation’s Australian or US-based workforce, was accessed. Nor is it thought, at this stage, that any of the data that was compromised has been leaked.

The organisation has been working with third-party cyber forensics and other investigators to restore the affected systems.

Having previously told staff to work from home until at least Monday 23 January, it has now pushed back the return to its Kings Cross office back until early February to enable its IT and security teams to better focus on the recovery efforts.

GMG did not attribute the attack to any known ransomware operation, nor did it say whether or not it has engaged with its attackers or paid a ransom – a tactic that is in general highly inadvisable.

Egnyte cyber security director Neil Jones praised GMG for being more upfront about its experience than many others.

“The recent ransomware attack at the Guardian is obviously unfortunate, but the attack does have an unprecedented silver lining. This is the first time I can ever remember an organisation acknowledging an attack immediately, even providing updates about it on its own website,” he said.

“There are several key lessons that can be learned from this incident: organisations need to combine ransomware detection and recovery solutions with effective data recovery programmes; companies need to have incident response plans in place, to effectively notify their customers, employees, business partners and the news media of potential breaches; and during these dynamic times, routine technological audits need to occur on a more frequent basis than they did before to prevent vulnerabilities from being exploited.”

Read more on Data breach incident management and recovery

Read More
Diego Fleishman

Latest

Glenmark Pharma Q1 profit jumps over 10-fold as India, North America businesses power growth

Pharma major Glenmark Pharmaceuticals Ltd on Friday (July 31) reported a 930% year-on-year increase in consolidated net profit to ₹483 crore for the first quarter, compared with ₹47 crore in the corresponding quarter last year. The company's revenue rose 23% year-on-year to ₹4,018 crore, compared with ₹3,264 crore a year earlier. At the operating level

Crypto Hack : COLDCARD Wallet Flaw Linked to $38 Million BTC Theft

Coinkite has disclosed a critical entropy-generation flaw affecting certain COLDCARD Mk2 and Mk3 firmware versions that may have weakened the security of wallet recovery seeds. According to PeckShield, the vulnerability has been linked to the theft of about $38 million in Bitcoin. Users who generated seeds using affected firmware are advised to update to the

Could STX See a Resurgence Through Institutional Bitcoin Capital?

Stacks (STX) powering Bitcoin-native Finance targets idle Bitcoin, an op portunity that remains one of the largest untapped pools of capital in crypto. According to Binance Research, less than 1% of total BTC supply is currently used productively across DeFi, against staking ratios above 30% for Ethereum and 60% for Solana. Whoever converts even a

FTX Repayments: Creditors to Receive Another $900 Million

FTX will begin distributing another $900 million to creditors starting tomorrow, bringing total repayments since the exchange’s 2022 collapse to nearly $10 billion. Many creditors are expected to recover more than 100% of their original claim value based on the bankruptcy filing date, while some smaller accounts could receive up to 120%. The latest payout

Newsletter

Don't miss

Glenmark Pharma Q1 profit jumps over 10-fold as India, North America businesses power growth

Pharma major Glenmark Pharmaceuticals Ltd on Friday (July 31) reported a 930% year-on-year increase in consolidated net profit to ₹483 crore for the first quarter, compared with ₹47 crore in the corresponding quarter last year. The company's revenue rose 23% year-on-year to ₹4,018 crore, compared with ₹3,264 crore a year earlier. At the operating level

Crypto Hack : COLDCARD Wallet Flaw Linked to $38 Million BTC Theft

Coinkite has disclosed a critical entropy-generation flaw affecting certain COLDCARD Mk2 and Mk3 firmware versions that may have weakened the security of wallet recovery seeds. According to PeckShield, the vulnerability has been linked to the theft of about $38 million in Bitcoin. Users who generated seeds using affected firmware are advised to update to the

Could STX See a Resurgence Through Institutional Bitcoin Capital?

Stacks (STX) powering Bitcoin-native Finance targets idle Bitcoin, an op portunity that remains one of the largest untapped pools of capital in crypto. According to Binance Research, less than 1% of total BTC supply is currently used productively across DeFi, against staking ratios above 30% for Ethereum and 60% for Solana. Whoever converts even a

FTX Repayments: Creditors to Receive Another $900 Million

FTX will begin distributing another $900 million to creditors starting tomorrow, bringing total repayments since the exchange’s 2022 collapse to nearly $10 billion. Many creditors are expected to recover more than 100% of their original claim value based on the bankruptcy filing date, while some smaller accounts could receive up to 120%. The latest payout

Hyperliquid News: HYPE Whales Unstake Millions as Protocol Revenue Tops $1.21 Billion

Hyperliquid is drawing attention after large HYPE holders unstaked millions of tokens, including one wallet that withdrew 1.02 million HYPE and another that transferred 1.89 million HYPE worth about $105.9 million to institutional brokers, a move often associated with over-the-counter sales. Despite the whale activity, the protocol generated $1.18 million in daily fees and burned

‘Sabah is open for business’: Hajiji courts investors with promise of sustainable growth, carbon‑negative credentials

Sabah is pitching itself as an Asia-Pacific hub for impact investing, betting that its forests, biodiversity and natural resources can become drivers of economic growth as it seeks private capital for sustainable development. — Picture by Firdaus Latif By Julia Chan First Published: Monday, 13 Jul 2026 11:44 AM MYT KOTA KINABALU, July 13 —

Want Your Business to Be Seen Everywhere? Meet Tonia Ryan, Creator of Fix Your Search

Some people are good at their jobs. Then there is Tonia Ryan, who has turned “getting found online” into something close to magic. She is the creator of Fix Your Search, and if you have ever wondered why some businesses pop up everywhere while others seem invisible...

Grey Business processes $61 million as stablecoins dominate payments

Grey Business enables startups and SMEs to open US Dollar (USD) corporate accounts, send and receive international payments, convert currencies, and transact using stablecoins such as USDC and USDT...