• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Nixon Williams hit by Cyber Security incident

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    #51
    Originally posted by PerfectStorm View Post

    Oh great.

    Anyone been able to pull all the files down to check their exposure? I've tried but the server is taking a hammering.

    At first sight: a lot of spreadsheets, PDFs, scans of passports... doesn't appear to be benign data in any sense.
    Passports? Oh dear. I have always had very bad feelings about companies routinely requiring an individual handing over their passport details. It just feels wrong. This simply justifies my fears about (non) security of data.
    Public Service Posting by the BBC - Bloggs Bulls**t Corp.
    Officially CUK certified - Thick as f**k.

    Comment


      #52
      Jesus, I'm glad I got out when I did https://uk.trustpilot.com/review/www.nixonwilliams.com
      ⭐️ Gold Star Contractor

      Comment


        #53
        Originally posted by PerfectStorm View Post

        Oh great.

        Anyone been able to pull all the files down to check their exposure? I've tried but the server is taking a hammering.

        At first sight: a lot of spreadsheets, PDFs, scans of passports... doesn't appear to be benign data in any sense.
        What server are you downloading from? The first one I've looked at has a lot of raw database files that are not formatted, or have been sanitised before being dumped into a database file. There are no passport details but there is everything else an identity thief would want.

        You can email Doug Crawford to ask why his amateur oversight resulted in this hack, but you will just get an out of office response that he isn't in the office.

        [email protected]

        Comment


          #54
          Originally posted by agentzero View Post

          What server are you downloading from? The first one I've looked at has a lot of raw database files that are not formatted, or have been sanitised before being dumped into a database file. There are no passport details but there is everything else an identity thief would want.
          I won't link it here, but it's all absolute files - PDFs, images, spreadsheets - nothing as complex as a database and so many files the index.html won't finish loading while it's still on the "A"s. Seems to contain every file the company ever owned, or something close to.

          It's mentioned in the article - Vice Society's blog, which is available on the clear net by appending .ly to the TLD - you'll be on the right track if you find a purple coloured website where the first link is a link to the Optionis files, presented as an HTTP folder full of files.


          ⭐️ Gold Star Contractor

          Comment


            #55
            Originally posted by PerfectStorm View Post

            I won't link it here, but it's all absolute files - PDFs, images, spreadsheets - nothing as complex as a database and so many files the index.html won't finish loading while it's still on the "A"s. Seems to contain every file the company ever owned, or something close to.

            It's mentioned in the article - Vice Society's blog, which is available on the clear net by appending .ly to the TLD - you'll be on the right track if you find a purple coloured website where the first link is a link to the Optionis files, presented as an HTTP folder full of files.



            Public Service Posting by the BBC - Bloggs Bulls**t Corp.
            Officially CUK certified - Thick as f**k.

            Comment


              #56
              Originally posted by agentzero View Post

              What server are you downloading from? The first one I've looked at has a lot of raw database files that are not formatted, or have been sanitised before being dumped into a database file. There are no passport details but there is everything else an identity thief would want.

              You can email Doug Crawford to ask why his amateur oversight resulted in this hack, but you will just get an out of office response that he isn't in the office.

              [email protected]
              I hope the corporate meltdown at the hacked businesses is so serious that the whole thing collapses into oblivion. The whole saga from the takeover by private equity has been appalling. How they even still have enough customers to complain is beyond me. The only folks I feel sorry for at the moment are the probably over worked, under paid and thoroughly pi55ed off infantry trying to patch things up. Though equally, I imagine anyone with a reasonable skill set left these firms a long time ago.
              Public Service Posting by the BBC - Bloggs Bulls**t Corp.
              Officially CUK certified - Thick as f**k.

              Comment


                #57
                Originally posted by PerfectStorm View Post

                I won't link it here, but it's all absolute files - PDFs, images, spreadsheets - nothing as complex as a database and so many files the index.html won't finish loading while it's still on the "A"s. Seems to contain every file the company ever owned, or something close to.

                It's mentioned in the article - Vice Society's blog, which is available on the clear net by appending .ly to the TLD - you'll be on the right track if you find a purple coloured website where the first link is a link to the Optionis files, presented as an HTTP folder full of files.

                It's already been repackaged for sale on various tor market sites, some available through https://dark.fail

                The data released isn't the full set, for certain. It's a mix of NW, Clearsky, Parasol and SJD. It seems to be an initial release. I would think Vice are in contact with Optionis to negotiate some crypto before releasing the rest in sets. The summary in security circles is that Vice managed to export everything, which means that the number of files must be in the hundreds of thousands. TrustPilot does reflect the reality, people are angry and are right to be angry.

                Why are there .FLAC music files on optionis servers? For staff to relax to after a hard live chat session?

                Comment


                  #58
                  For those who have had data stolen Cifas Protective Registration
                  https://www.cifas.org.uk/pr
                  "You’re just a bad memory who doesn’t know when to go away" JR

                  Comment


                    #59
                    Originally posted by agentzero View Post
                    Why are there .FLAC music files on optionis servers? For staff to relax to after a hard live chat session?
                    The audiophile in me respects that. Would have made the download take longer as well.
                    https://uk.linkedin.com/in/andyhallett

                    Comment


                      #60
                      Interestingly, they haven't notified former customers of any breaches.

                      This means one of two things, that nothing was breached for customers they don't have any more... or data was breached, and they're failing in their statutory duties.

                      Which do you think it is?
                      ⭐️ Gold Star Contractor

                      Comment

                      Working...
                      X