Colt Technology Services Recovering from August Cyberattack; Full Restoration Expected by November
=================================================================================================
Britannian telecommunications provider Colt Technology Services announced that its recovery from a significant cyberattack initiated in August may not be complete until late November. The attack, attributed to the Warlock ransomware group, began impacting operations on August 12, implying a recovery period exceeding three and a half months.
Ongoing Recovery Efforts and Timeline
In a recent update, Colt stated: _"We have been working around the clock to restore our core processes and systems and thank you for your patience and support during this time."_ The company estimates that most recovery efforts will conclude within 8-10 weeks, with critical customer services prioritized early in the process. Colt plans to provide weekly updates on progress and expects to share a comprehensive service status update soon.
Investigation and Security Measures
Colt engaged external cybersecurity experts to investigate its Business Support System (BSS) and Operational Support System (OSS). According to the company:
- The BSS and OSS are distinct systems.
- Penetration testing suggests the OSS remains secure and unlikely to be compromised.
- Foundational recovery work is complete, and efforts are now focused on restoring core systems in a deliberate sequence.
Service Disruptions and Customer Impact
While Colt's network infrastructure appears operational, certain platforms remain affected:
- The customer portal, network-as-a-service portal, and several hosting APIs are still offline, limiting customers' ability to manage services.
- The billing system continues to experience delays in issuing invoices, though payment collections are still operational through existing contractual methods.
- Delayed invoices will retain their original due dates, and late payment charges may apply due to processing delays.
Regulatory Reporting and Data Status
Colt reported more than 75 incidents to authorities across 27 countries, including regulators, law enforcement, and cybersecurity agencies. The alleged attacker, Warlock, continues to auction stolen data on the dark web, with no apparent change since August. Colt confirmed awareness of online posts but clarified that the stolen data remains behind the scenes, fearing it might be a facade for boasting rather than an actual data leak.
Suspected Entry Points and Vulnerabilities
While no official entry method has been confirmed, multiple sources suggest that Colt may have fallen victim to vulnerabilities in SharePoint exploited over the summer. A report by Trend Micro noted Warlock’s activity among groups exploiting such vulnerabilities. Infosec researcher Kevin Beaumont observed that Colt temporarily took its SharePoint server offline following the attack and indicated that data exfiltration likely occurred.
Industry Context and Additional Incidents
The Colt attack is part of a broader pattern of ransomware activity targeting telecom and enterprise systems, often exploiting known vulnerabilities. Similar incidents include a recent data leak involving 280,000 customer details at an Australian telco and attacks leveraging Apache ActiveMQ vulnerabilities that have been patched by attackers post-breach.
Conclusion
Colt Technology Services remains in the midst of a complex recovery, balancing operational restoration with ongoing security investigations. Customers are advised to remain vigilant as the company works to fully restore services over the coming weeks.