FutureScot
Cyber

Former Arnold Clark boss: cyberattack had ‘significant and long-lasting impact’ on the firm

From left, Jude McCorry, Eddie Hawthorne, Clare Adamson MSP and Calum Kerr MSP. Photograph: Cyber and Fraud Centre - Scotland

The former boss of Arnold Clark has said a cyberattack which hit the car retailer four years ago had a ‘significant and long-lasting impact’ on the business.

Eddie Hawthorne was speaking at an event at the Scottish Parliament where he called for the ‘right support’ for businesses when an attack happens and to address the ‘gaps’ that allow criminals to continue exploiting stolen data afterwards.

His call was backed by the Cyber and Fraud Centre – Scotland, which called for greater protections for victims and to close what it described as ‘legal gaps’ exploited by cybercriminals.

The centre organised the event last Wednesday with Calum Kerr MSP, which brought together politicians, business leaders and cyber experts to discuss cybercrime, stolen data and support for victims.

Hawthorne, the ex-CEO of the car sales giant, said: “Experiencing a major cyberattack first-hand showed me how significant and long-lasting the impact can be.

“We need to ensure businesses have the right support when an attack happens and address the gaps that allow criminals to continue exploiting stolen data afterwards.”

MSPs at the event included deputy presiding officer Clare Adamson, Ivan McKee, cabinet secretary for public service reform, Siobhian Brown, minister for children, young people and ‘The Promise’, and MSPs Yi-Pei Chou Turvey, Michelle Campbell and Pauline Stafford.

A major theme was that the harm caused by a cyberattack can go on long after the attack itself, because stolen data can be traded, sold and used for fraud and other crime.

The Glasgow-based retailer was hit on the evening of 23 December 2022. Staff had to record customer transactions with pen and paper after they were locked out of their computers. The company voluntarily disconnected its systems after an external security consultant warned it about suspicious traffic on its network.

The attack was later claimed by the Play ransomware gang. On 22 January 2023, the Mail on Sunday revealed that Play had leaked a 15GB tranche of data on the dark web, including customer photo ID, passport data, banking data, dates of birth and home addresses. The hackers threatened to upload a further 467 gigabytes unless a multi-million-pound ransom was paid in cryptocurrency.

Arnold Clark then acknowledged that data had been stolen and began notifying customers in staggered batches at the end of January 2023. A further 30GB was posted in mid-February, and the full dump of almost 470GB followed at the end of March. Thousands of people whose data was leaked have since come forward to join what may become one of the largest group action lawsuits seen in the UK.

Hawthorne has spoken publicly about the attack before. At a Futurescot conference last year, he said the ransomware had infected about five to 10 per cent of the company’s servers before it stopped. Arnold Clark has also made what was described as a ‘substantial’ donation to the Cyber and Fraud Hub, a service set up to help people in Scotland affected by cyber fraud and crime.

The Cyber and Fraud Centre – Scotland has now called for further action to protect businesses, public bodies and individuals from cybercrime and the misuse of stolen data.

Jude McCorry, its CEO, said: “Cyberattacks don’t end when systems are restored. Stolen data can continue to be traded and exploited, causing further harm to people and businesses.

“The Cyber and Fraud Centre – Scotland will continue working with politicians, businesses and public bodies in Scotland and across the UK to push for stronger protection for victims and action to address the criminal exploitation of stolen data.”

Calum Kerr MSP, and former IT industry executive, added: “Cybercrime affects individuals, businesses and public services across Scotland. After a near 30-year career in IT and technology I’ve seen this firsthand, and I’m keen to take the issue forward.

“While much of the relevant legislation sits at Westminster, there is much we can and should do in Scotland to strengthen resilience, support victims and make it harder for criminals to profit from stolen data.

“This discussion demonstrated why we need continued collaboration between government, law enforcement, industry and cyber experts to better protect victims and strengthen Scotland’s resilience.”

Related posts

Scottish cyber firm comes to the aid of Ukraine’s government websites

Kevin O'Sullivan
October 24, 2022

Skills Development Scotland hits cyber learning targets ‘two years early’

Will Peakin
April 23, 2019

Scottish Apprenticeship Week

Claire Gillespie
March 1, 2021
Exit mobile version