Originally Posted by Burgundymog
Not necessarily, last week an 18 year old was arrested on suspicion of cyber attacks was found to have $200 million in bitcoin type accounts. He was arrested while on bail for similar offences.

Either way, it doesn't excuse the companies (also M&S, Co-op, and many more) for not enforcing decent cyber security measures, if anything it makes it worse. There might possibly be a defence to say nobody could withstand a co-ordinated attack from highly skilled state-sponsored bad actors, but if you can't even keep your systems secure from a kid with a laptop? Extremely concerning. And if JLR can't keep their systems secure, what does that say about the security of the software that ends up in the cars?

Most of these type of breaches seem to originate from basic social engineering, Phone calls purporting to be from 'Steve in the back office' or emails containing an executable disguised as a spreadsheet. These kinds of attacks frequently get in by targeting poorly trained and paid staff who aren't motivated to look out for the interests of their employer or their clients.

I did some work with a Swiss company back in the early naughties, even back then their cyber security team was dealing with attacks and probes measured in the thousands per month. Fortunately their guys were highly skilled and highly paid in-house professionals committed to keep their systems secure. God knows how bad it must be for a company who have outsourced support and are depending on the honesty and integrity of someone in a far-away land being paid peanuts and highly vulnerable to bribery or coercion.


Tim H.
1986 4/4 VVTi Sport, 2002 LR Defender, 2022 Mini Cooper SE