Become Cyber Safe – 2nd November

Table of Contents

[fusion_builder_container type=”flex” hundred_percent=”no” equal_height_columns=”no” hide_on_mobile=”small-visibility,medium-visibility,large-visibility” background_position=”center center” background_repeat=”no-repeat” fade=”no” background_parallax=”none” parallax_speed=”0.3″ video_aspect_ratio=”16:9″ video_loop=”yes” video_mute=”yes” border_style=”solid” margin_top=”1px” flex_align_items=”center” flex_justify_content=”flex-start”][fusion_builder_row][fusion_builder_column type=”1_1″ type=”1_1″ layout=”1_1″ background_position=”left top” border_style=”solid” border_position=”all” spacing=”yes” background_repeat=”no-repeat” margin_top=”0px” margin_bottom=”0px” animation_speed=”0.3″ animation_direction=”left” hide_on_mobile=”small-visibility,medium-visibility,large-visibility” center_content=”no” last=”true” hover_type=”none” first=”true” background_blend_mode=”overlay” min_height=”” link=””][fusion_text]

Welcome to the latest edition of the Cyber Safe Cyber Threats, a weekly series in which we bring attention to the latest cyber attacks, scams, frauds, and malware including Ransomware, to ensure you stay safe online.

Here are the most prominent threats which you should be aware of:


Boeing Investigates LockBit Ransomware Breach Claims

Aerospace company Boeing is evaluating claims made by the ransomware group LockBit, which asserts it has acquired a significant amount of sensitive data from Boeing, according to Info Security Magazine. The group warned that the data would be published unless Boeing contacts them before a specified deadline, and the company has until November 2 to pay an undisclosed ransom to prevent the data from being made public.

LockBit is a highly active ransomware-as-a-service group responsible for numerous attacks. It has allegedly made around $91 million from US victims alone since January 2020. Boeing has yet to confirm whether it will engage with LockBit’s demands, with its response likely dependent on the quality of the exfiltrated data.

While LockBit typically provides decryption keys after receiving ransom payments, there is always a risk of data not being recovered, and paying ransoms to ransomware groups is illegal in many countries. Security experts recommend that organisations affected by ransomware contact their countries’ cyber security agencies for assistance.

Hear more about this particular scenario on our latest Neuways Cyber Safe Digest Podcast, brought to you by the experts at Neuways.

‘My business had £1.6m stolen in 20 minutes’ – The impact of cyber attacks on small businesses


Kent Brushes, a company established in 1777 that supplies hairbrushes to the Royal Family, suffered a significant blow when £1.6 million was stolen through a sophisticated authorised push payment (APP) scam. The firm, with around £11 million in turnover and several dozen employees, does not have the same protections as individual consumers regarding fraud, leading to delays in recovering the stolen funds.

How can cyber attacks affect small and medium enterprises?

The boss of the small business in the UK affected by the cyber attack is highly critical of the response from authorities after his company lost £1.6 million in a matter of minutes due to fraud. An employee was tricked into giving access to the company’s account, leading to a substantial loss. The business owner, Steve Wright, expressed frustration with both his bank and Action Fraud for their handling of the case.

In related news, the Home Office recorded 1.25 million fraud cases in the year ending March 2023, with only about 4% of cases investigated and roughly 4,000 resulting in court proceedings.

Despite the severity of the crime, the bank has not refunded the money, no arrests have been made, and there is no sign of further investigation. Mr Wright criticised the handling of the case, emphasising the need for serious attention to such crimes.

As for Kent Brushes, Mr Wright stated that the company is resilient but had to reevaluate its cyber security strategies following the theft, resulting in a slower rollout of new products to maintain financial stability. Despite the setback, all staff received their pay on time.

One month after the theft, Action Fraud sent a letter to Mr Wright stating “case closed,” but it was later revealed that the crime details were recorded incorrectly. The bank, Barclays, noted that the customer had fallen victim to a sophisticated scam, but it maintained that the business would be held liable.

BlackCat ransomware group claims major cyber attack on LBA Hospitality

The ALPHV/BlackCat ransomware group has announced that it successfully targeted LBA Hospitality, one of the largest hospitality management companies in the United States, and managed to steal approximately 200 GB of sensitive data from the firm’s servers. The company oversees nearly one hundred hotels operating under four major brands: Marriott, Hilton, Holiday Inn, and Best Western. All very big names who are all well-renowned in the UK.

According to information, the infamous ALPHV/BlackCat ransomware group infiltrated LBA Hospitality’s internal systems and identified the company as a victim of its data leak platform. The ransomware group has claimed to have exfiltrated approximately 200 GB of susceptible data from the company’s primary servers and has given LBA Hospitality a three-day ultimatum to make a ransom payment. Failure to comply would result in the publication of the stolen data.

In a statement posted by ALPHV/BlackCat, the group stated, “You have three days to contact us to decide this pity mistake, which made your IT department decide what to do in the next step. If you prefer to keep silent, we will begin publicising the data, most consisting of citizens’ confidential documents.”

The group alleges that the stolen data includes employees’ personal information, such as CVs, IDs, driver’s license numbers, Social Security Numbers, financial reports, accounting data, loan records, insurance agreements, etc. Additionally, the group claims to possess information about LBA’s clients, including their driver’s license numbers, other IDs, Social Security Numbers, financial data, credit card details, loan records, agreements, and more. The stolen database also contains confidential commercial data.

LBA Hospitality has yet to issue many comments regarding the claims made by the ransomware group, so it remains uncertain whether the cyber threat actors’ assertions are accurate or if the company intends to comply with the hacker group’s ransom demands.

The BlackCat ransomware group is also known for its involvement in a significant cyber attack on MGM Resorts International, which resulted in 31 MGM property websites and the company’s mobile rewards app being taken offline.

Per a post on social media platform X from vx-underground, the hacker group claimed to have infiltrated MGM Resorts’ network using social engineering tactics. The post read, “All ALPHV ransomware group did to compromise MGM Resorts was hop on LinkedIn, find an employee, then call the Help Desk. A company valued at $33,900,000,000 was defeated by a 10-minute conversation.”

—————————————————————————————————————————–

Contact Neuways to help your business become

Cyber Safe

If you need any assistance with cyber security assistance, then please contact Neuways and we will help you where we can. Just get in touch with our team today.

[/fusion_text][/fusion_builder_column][/fusion_builder_row][/fusion_builder_container]

Want to keep up with our blog?

Get our most valuable tips right inside your inbox every Friday!

Latest IT News & Insights
VPN
SonicWall VPNs under attack: What businesses need to know  
Cybercriminals are always adapting, and the latest surge in activity from the Akira ransomware group...
Read More
Ransomware on the rise
Ransomware on the rise: Meet Akira & Lynx 
Ransomware continues to be one of the most disruptive cyber threats facing businesses today. As defences...
Read More
What is Ransomware
Ransomware: What is it and how to stay protected 
You’ve probably seen the term “ransomware” pop up in the news more often over the past few years, and...
Read More
ring-doorbell
What to know about the supposed Ring doorbell security breach in May 2025
In July 2025, Ring users across social media platforms raised alarm bells after spotting what appeared...
Read More
Heading-12
Windows 10 support ends in 2025: What your business needs to know
Microsoft has officially announced that support for Windows 10 will end on 14th October 2025. If your...
Read More
browser
The hidden danger of browser extensions: Are your staff putting your business at risk?
Browser extensions represent a serious business risk Browser extensions are often seen as harmless add-ons,...
Read More
Legacy systems
Legacy systems: The silent security liability
When thinking about cyber security, it’s easy to focus on the latest threats: phishing, ransomware, or...
Read More
Captchas
CAPTCHAs: A security tool that can be used against you
We’re all used to CAPTCHAs, those little tests that make you pick out traffic lights or type in squiggly...
Read More
Neuways logo

Frequently Asked Questions

As a leading IT and technology provider, we offer three core services, all of which have additional add-ons. We offer Managed IT Support, Business Central implementation and consultation, as well as Managed Cyber Security. Call us on 01283 753333 if you are interested in any of our services.

Contact us

Support: 01283 753300

Business Development: 01283 753333

Purchasing: 01283 753322

Admin and Accounts: 01283 753311

Email: hello@neuways.com

Managed IT support is a comprehensive solution where an expert IT provider, like Neuways, handles your technology infrastructure. This includes proactive monitoring, maintenance, cyber security, and support.

Yes we do. Your business needs Cyber Security due to the increasing number of cyber threats that are affecting businesses in all industries. If your business has data and technology systems implemented, you will need Managed Cyber Security.

We can help you conduct Cyber Audits to assess whether your business would gain Cyber Essentials and Cyber Essentials Plus Certification. Our dedicated departments work with your team to assess how much work is required before you gain Cyber Essentials Plus certification. We will then provide advice and consultation on what aspects you need to change within your business before providing a quote on how we can assist your company become Cybersafe.

Yes we can. We have our own dedicated Microsoft Dynamics 365 Business Central teams who work to ensure that we can implement the right systems and solutions into your website that are absolute right for you. Our experienced business consultants have worked all over the world for organisations operating on a global scale. 

Exclaimer Pro is a dynamic email signature that helps clients to switch and change around email signatures so that clients are able to advertise different offers and brands to a variety of email recipients. Administrators can also manage user emails internally, meaning the user does not have to touch their own email signature.

We offer Managed Security Training to help employees spot email phishing attacks, spear phishing attacks and vishing attacks. We also help train clients on how to use the various pieces of software we provide to clients, like Exclaimer Pro, Business Central and Cybersafe software.

We are a Managed IT Support provider based in Derby, East Midlands. However, we cover so many areas including the whole of the UK, Europe, and America. We are always willing to travel and send our expert technicians to ensure you have the best experience. 

Got a question?

Reach out
& Connect

Name