Cyber criminals who stole thousands of digital files belonging to environmental regulator Sepa have published them on the internet.
The public body had about 1.2GB of data stolen from its digital systems on Christmas Eve.
What Data Has Been Leaked?
Sepa has rejected a request to rescue the attack by paying Ransom, which has been demanded by the international group Conti ransomware.
Contracts, strategic documents and information details are among the 4,000 files released.
The information is stored on the dark web – the part of the internet that is linked to crime and is only available through special software.
Sepa said theft equals a fraction of the content of an average laptop hard drive.
Some stolen information was already publicly available but some files containing information about employees and providers were not available.
When the information was received to date, staff members were contacted and supported.
SEPA’s Chief Executive’s Statement
Sea chief executive officer Terry A’Hearn said: “It has become clear that we will not use public funds to pay for serious and organized crime aimed at disrupting public services and embezzling public funds.

“We have made our legal obligations and duty of care in the management of sensitive information a priority and, following the advice of Police Scotland, they have ensured that the stolen information is illegally published online.
“We’re working quickly with multi-agency partners to recover and analyse data then, as identifications are confirmed, contact and support affected organisations and individuals.”
The attack blocked emails and communication centers but Sepa said “control measures, monitoring, flood forecasting and warning systems continue to operate”.
Warning For The Future
Brett Callow, of cyber security company Emsisoft, has been tracking Sepa ransomware attacks.
He said: “Conti may well be the work of the same people behind another type of ransomware called Ryuk.
“There are similarities in the code, ransom note and attack mechanisms.
“When the complete haul of data is posted like this, it usually means the group has given up hope of being able to extract payment from the victim of monetise the data in other ways.
“It’s a loss for them. At this point, they’ve lost all leverage and the action is intended to serve as a warning to future victims.”
Det Insp Michael McCullagh, of the Scottish Police Crime Investigation Unit, said: “This is still an ongoing investigation.
“Inquiries remain at an early stage and continue to progress including deployment of specialist cybercrime resources to support this response.”
The authorities will be pleased.
What’s Next?
Ransomware is a scourge that is costing organisations billions of pounds and every time a victim pays, it fuels further attacks.
Unfortunately for Sepa this is far from over.
Given the number of files the invaders have stolen, Sepa will have months of work before trying to retrieve important documents and spreadsheets from backups and rebuild their records.
It also means that, according to the hackers’ website, about 1,000 people have viewed the documents so far.
Who knows what other criminals or hackers are looking at files right now.
Making the documents open to all means that information can be extracted to potentially be used against Sepa in further attacks or extortion attempts.
It will be months, maybe even years until the organization can say it is safe and and can put this cyber attack behind it.

