https://www.bleepingcomputer.com/news/security/royal-mail-investigates-data-leak-claims-no-impact-on-operations/
Royal Mail is investigating claims of a security breach after a threat actor leaked over 144GB of data allegedly stolen from the company’s systems. When asked to confirm the authenticity of the leaked data, a Royal Mail spokesperson told BleepingComputer that the British postal service is aware of an incident at Spectos GmbH, a third-party data collection and analytics service provider. “We are aware of an incident which is alleged to have affected Spectos, a supplier of Royal Mail. We are working with the company to investigate the issue and establish what impact there may be regarding their data,” BleepingComputer was told. “We can confirm there has been no impact on Royal Mail operations and services continue to function as normal.” Spectos also confirmed in a statement shared with BleepingComputer that its systems were breached on March 29, and the attackers gained access to customer data. … The threat actor behind this leak (who uses the “GHNA” handle on BreachForums) released 16,549 files allegedly containing Royal Mail customers’ personally identifiable information (including names, addresses, planned delivery dates, and more) and other confidential documents. GHNA says the leaked documents also include Mailchimp mailing lists, datasets containing delivery/post office locations, the WordPress SQL database for mail agents.uk, internal Zoom meeting video recordings between Spectos and the Royal Mail Group, and more. While Royal Mail and Spectos have yet to share more information on the breach, cybersecurity company Hudson Rock says the attackers gained access to Royal Mail systems using the credentials of a Spectos employee compromised in a 2021 info stealer malware incident. …
Regards