Connect with us

Infosecurity

Former UK privacy chief reportedly preparing legal action against woman who reported him, minister says

Published

on

John Edwards legal action

Minister reveals legal threat against whistleblower

Britain’s former Information Commissioner, John Edwards, is reportedly preparing to serve legal papers on a female employee who raised concerns about his conduct, the science and technology secretary told Parliament on Wednesday. Liz Kendall, speaking before the Science, Innovation and Technology Committee, said she was “absolutely appalled” by the development.

Kendall revealed that an independent investigation at the Information Commissioner’s Office (ICO) had upheld multiple allegations of “sexual harassment and bullying” against Edwards. The specific nature of the complaints had not been publicly disclosed until now.

“I’m also going to be launching an independent review of the culture, accountability and governance of the ICO,” Kendall told the committee. “I take very seriously what’s happened there and I will do everything I can to try and put this right.” She added that “the women who’ve spoken up have been incredibly brave.”

Edwards’ resignation and LinkedIn statement

Edwards formally resigned as Information Commissioner in June, after voluntarily stepping back from his duties in February. That move came amid an internal workplace investigation into what was initially described only as unspecified conduct.

In a LinkedIn post at the time, Edwards acknowledged his position had “become untenable.” He wrote: “From the time the investigation was launched, I have accepted that there have been occasions where I exercised poor judgment and made attempts at humor that were inappropriate and caused offense.”

He added that while he did not agree with how the investigation was conducted, he accepted that resigning was the appropriate course.

Government response and new leadership

Kendall told the committee the government will launch the recruitment process for Edwards’ successor next week. That process will run alongside “the appointment of a new board of non-executive directors, the majority of whom will be women.”

The minister also revealed the legal threat. “It has come to my attention that the former Information Commissioner is preparing to serve legal papers on one of the women at the ICO who raised concern about his behavior earlier this year,” she said.

“I don’t know who this woman is, but by reporting her concerns, she supported the independent investigation that upheld multiple allegations made against him. I have reached out as best I can and said they need to know that they will always be listened to without being put at personal risk. Quite frankly, I’m appalled by that behavior.”

ICO leadership under scrutiny

The ICO, which oversees Britain’s data protection and privacy regulations, has faced growing scrutiny over its internal culture. The independent review Kendall announced Wednesday aims to examine how the organization handles accountability and governance.

Edwards served as Information Commissioner from January 2022. Before that, he was New Zealand’s Privacy Commissioner. His tenure at the ICO included major decisions on WhatsApp HD photo sending and data-sharing rules, but his leadership is now overshadowed by the misconduct allegations.

The Department for Science, Innovation and Technology (DSIT) has not commented on the legal threat beyond Kendall’s remarks. Neither Edwards, the ICO, nor the government immediately responded to requests for comment.

Broader implications for workplace whistleblowing

Kendall’s disclosure raises questions about the protections available to whistleblowers in UK public bodies. The minister made clear she views the legal action as an attempt to intimidate someone who came forward in good faith.

Employment lawyers say that while individuals have a right to defend themselves against allegations, threatening legal action against a complainant can be seen as retaliation. Under UK employment law, whistleblowers are protected from detriment or dismissal for making protected disclosures.

The case could prompt wider discussions about how regulators handle internal complaints. The ICO, which enforces rules on data privacy, is now itself under investigation for its handling of workplace conduct.

For the women who spoke up, Kendall’s public support may offer some reassurance. But the prospect of facing legal proceedings from a former boss — one who once held one of the most powerful regulatory posts in the country — is daunting.

“The women who’ve spoken up have been incredibly brave,” Kendall repeated. “They need to know they will always be listened to without being put at personal risk.”

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

One Government Agency Hit by Ransomware Every Day: New Data Shows a Relentless Surge

Published

on

ransomware government agencies

Attack Frequency Reaches a New Milestone

Ransomware is no longer a periodic threat for public-sector organizations — it’s a daily reality. New data from cybersecurity researchers at Comparitech shows that, on average, one government agency somewhere in the world has its systems encrypted and services crippled every single day.

The study, published on July 16, tracked ransomware incidents targeting government bodies between January and June 2026. It recorded 187 attacks over 182 days — a pace that works out to just over one per day. That marks a 13% jump from the 165 attacks logged in the second half of 2025.

Of those 187 incidents, only 89 — roughly half — were publicly acknowledged by the affected organizations. The rest either went undisclosed or remained unconfirmed at the time of reporting.

Why Governments Are Prime Targets

Government agencies hold a toxic combination of assets: vast troves of sensitive citizen data and systems that the public depends on daily. When ransomware locks up a municipal billing system or a state health portal, the pressure to restore services fast is immense.

“From weeks-long disruptions due to system encryption to extensive data breaches, governments are the ideal target for hackers,” said Rebecca Moody, head of data research at Comparitech.

That pressure often translates into a higher likelihood that the victim will pay the ransom. Attackers know this. A city hall can’t afford to be offline for a month while IT teams rebuild from scratch — so the calculus for paying up shifts dramatically.

The United States Leads as the Most Frequent Target

The geographic distribution of attacks is lopsided. The US absorbed 31% of all ransomware incidents against government agencies during the six-month period. No other country came close.

Germany was the second-most targeted nation, accounting for just 7% of attacks. Spain and Italy each registered 4%. The gap between the US and the rest of the world is partly explained by population size — more government bodies means more attack surfaces — but it also reflects the aggressive focus of ransomware groups on high-value English-speaking targets.

Ransom Demands: A Calculated Gamble

The median ransom demand during the period sat at $100,000. That figure is relatively modest compared to the multimillion-dollar demands seen in the private sector. The logic is straightforward: ask for too much from a taxpayer-funded entity, and the chance of payment plummets.

Still, outliers exist. The most extreme case was a $3.1 million demand directed at the Land and Agricultural Development Bank of South Africa following a January 2026 attack. The bank refused to pay, and its systems were only fully restored in April. The perpetrator of that attack remains unknown.

Known Threat Groups and Their Methods

While some attackers fly under the radar, many incidents can be traced to established ransomware crews. The most active groups between January and June 2026 were:

  • The Gentlemen — responsible for 10% of attacks
  • Qilin — linked to 9% of incidents
  • LockBit — accounted for 7%

These groups frequently exploit well-known, publicly disclosed vulnerabilities. They move fast once a patch is available — often faster than government IT departments can deploy it.

How Agencies Can Fight Back

Prevention, Comparitech argues, comes down to fundamentals. Moody outlined a set of measures that are unglamorous but effective: keep systems updated, patch vulnerabilities as soon as they are flagged, perform regular backups, and invest in continuous employee training.

“Making sure employees are regularly trained and are on high alert at all times are crucial to mitigating the risks of attacks,” she said.

That last point matters more than many realize. A single phishing email opened by a busy clerk can undo months of security work. For agencies already stretched thin, the cost of proactive defense is far lower than the cost of a recovery operation that takes weeks — or, in the case of the South African bank, months.

The takeaway is sobering: ransomware is not going away, and government networks remain in the crosshairs. The question is not whether another agency will be hit tomorrow. It’s whether they’ll be ready when it happens.

Continue Reading

Infosecurity

SANS Report: AI Adoption Surges Among Security Teams, But Governance Is Playing Catch-Up

Published

on

AI governance gap

Security Teams Are Moving Faster Than Their AI Policies

A new survey from the SANS Institute paints a stark picture: cybersecurity professionals are racing to deploy artificial intelligence, but the safety nets meant to keep that deployment under control aren’t keeping up.

The 2026 SANS AI Survey Insights report, based on responses from 536 global cybersecurity and IT practitioners plus 57 security leaders, found that 78% of organizations now actively use AI in their cybersecurity strategy. That’s a jump from 50% just a year earlier. But the same survey reveals a troubling parallel trend: 63% of respondents reported “significant shortcomings” in threat detection and response — up sharply from 45% in 2025.

“For two years now, we’ve asked security teams where they actually stand with AI,” said Matt Bromiley, the report’s author and a SANS certified instructor. “Both years, the honest answer has been some version of moving fast and working it out as we go. What’s changed in 2026 is how much weight is now sitting behind that answer.”

The AI governance gap is real — and it’s widening.

Trust in AI Decisions Hits a Wall

One of the report’s most striking findings: trust in AI decisions (40%) has replaced “wiring AI into existing systems” as the top barrier to deeper integration. Teams aren’t just struggling to plug AI into their workflows anymore. They’re questioning whether they can rely on the outputs.

That trust deficit is compounded by a governance vacuum. Only half (50%) of the cybersecurity leaders surveyed said their organization has a formal AI governance program in place. Meanwhile, 44% described themselves as being in the early stages of drafting policy — and some respondents claimed to be in both categories at once, suggesting confusion over what “governance” actually means in practice.

AI governance isn’t just a buzzword. Without clear rules on data access, model validation, and incident response, organizations are essentially flying blind with powerful — and fallible — tools.

Where AI Is Actually Helping (and Where It’s Not)

It’s not all bad news. The survey identified two areas where AI is delivering clear value for network defenders: behavioral detection (48% of respondents reported effective use) and user awareness training (45%). These are practical, measurable wins.

But the threat landscape is shifting just as fast. 78% of organizations reported confirmed or suspected AI-enabled attacks in the past year. The most common incidents involved deepfakes, vulnerability exploitation, phishing, and adversarial attacks on AI models themselves. Attackers are weaponizing the same technology defenders are trying to harness.

The Upskilling Crunch

Perhaps the most urgent finding concerns the workforce. Three-quarters of respondents (73%) said AI has changed their training requirements, up from 51% in 2025. That’s a massive shift in just 12 months.

“You can’t fix these gaps without people who can catch what the tools miss,” Bromiley said. “The teams that invest in upskilling now are also the ones positioned to get more out of the AI they have already bought, because the people running it know when to trust it and when to step in.”

SANS argues the next year is critical. The report recommends a three-point investment plan:

  • AI validation infrastructure — focusing on “precision, recall, and continuous comparison” rather than simply buying more tools
  • Operationalizing governance — treating sensitive-data access and AI data exposure as core controls, not afterthoughts
  • Workforce development — handled as an immediate operational need, not a medium-term hiring goal

Closing the Gap Means Slowing Down — Just a Little

The numbers tell a clear story. Adoption is surging. Threats are evolving. And too many organizations are still making up their AI policies as they go.

For security teams, the path forward isn’t about abandoning AI — it’s about building the governance, trust, and skills to use it responsibly. That means investing in people as much as technology, and treating AI upskilling as a here-and-now priority rather than a future project.

As Bromiley put it: “Moving fast is fine — but you need to know where you’re going.”

Continue Reading

Infosecurity

‘Selfish Bravado’ Behind TfL Cyber-Attack, Judge Says as Pair Jailed for Five Years

Published

on

TfL cyber-attack

Two men who breached Transport for London’s systems in 2024, stealing data from millions of Oyster card users and forcing the shutdown of key accessibility services, have been sentenced to five years and six months in prison.

Owen Flowers, 18, and Thalha Jubair, 20, pleaded guilty in June 2026 to unauthorized acts under the UK’s Computer Misuse Act. The judge at Woolwich Crown Court, Justice Turner, said the attack was driven partly by “selfish bravado” — not purely by money.

The case is the second criminal prosecution of its kind under the CMA in the UK. And it’s the largest cybercrime prosecution ever brought before British courts, according to the National Crime Agency (NCA).

How the TfL cyber-attack unfolded

Flowers was 17 and Jubair 18 when they first broke into TfL systems on August 31, 2024. They held access for three days.

Their entry point? Partial employee credentials bought from “well-known online criminal marketplaces and forums,” a senior NCA officer confirmed. Then came social engineering: multiple attempts to reset two-factor authentication (2FA) for TfL staff accounts.

“It took multiple attempts to successfully reset that 2FA, so they were persistent — as we know they are,” the officer said. Once inside, the pair escalated privileges, moving deeper into TfL’s network.

Telegram messages between the two showed they knew they’d accessed the database of Oyster cardholders. They even streamed their progress live to an online audience, the judge noted.

£29m in damages — and a near miss for the UK economy

The TfL cyber-attack cost the transport body £29 million ($38 million) in direct losses and recovery. TfL also reported an additional £10 million ($13.5 million) in lost income.

While the hackers never shut down trains or buses, the operational fallout was severe:

  • The Oyster refund system was compromised, forcing TfL to close applications for Oyster photocards for children and young people.
  • The Dial-a-Ride booking system — used by people with disabilities — was taken offline.
  • Live Tube data on apps like TfL Go and CityMapper was suspended.
  • Over 27,000 TfL employees had to reset their passwords in person.
  • Some staff worked from home for the whole of September 2024.

In total, between seven and 10 million people across the UK were affected. Had the attackers succeeded in disabling the transport network, the NCA estimated the cost to the UK economy could have reached £56 billion ($75 billion).

Scattered Spider: from teenage hackers to a major threat

Flowers and Jubair are believed to be part of Scattered Spider, a hacking group linked to attacks on Marks & Spencer and Co-op in 2025. Scattered Spider emerged from a loose collective known as The Com, which also spawned groups like Lapsus$ and ShinyHunters.

The NCA describes Scattered Spider as “the most significant cybercrime threat to the UK in recent years.” Their tactics? Phishing, voice phishing (vishing), SIM swapping, and ransomware.

Jubair’s record is extensive: 22 prior convictions, starting at age 14. In 2023, he received a Youth Rehabilitation Order for offences linked to Lapsus$. He is also wanted by US authorities for alleged cybercrimes involving the theft and extortion of millions of dollars.

Flowers had a history too. In October 2023, West Midlands Police issued him a cease-and-desist notice. He was offered training on computer misuse laws — and turned it down. After his arrest for the TfL hack, he was granted bail but violated conditions twice: once in October 2024 and again in May 2025. He also received a formal warning in March 2025.

Sentencing: youth, neurodiversity, and high expertise

Justice Turner weighed mitigating factors — the defendants’ youth and diagnosed neurodiversity — against aggravating ones, particularly their “high expertise,” which meant they likely understood the full impact of their actions.

The five-and-a-half-year sentences reflect that balance. Deputy Director Paul Foster, head of the NCA’s National Cyber Crime Unit, called the prosecution “the culmination of nearly two years of painstaking work by the NCA, Crown Prosecution Service (CPS) and our policing partners.”

“Through this investigation, we have severely disrupted that threat and brought key offenders to justice,” Foster added.

What this means for UK cybercrime in 2026

The NCA warns that the threat from serious organized cybercrime to the UK remains “very high” in 2026. While a small number of attacks come from UK-based individuals motivated by notoriety, the vast majority are launched by criminals abroad, driven by financial gain.

The TfL cyber-attack case sets a significant precedent. It shows UK courts are willing to hand down long sentences for cyber intrusions — even when the perpetrators are teenagers. And it underscores the vulnerability of critical public infrastructure to determined, socially engineered attacks.

For TfL, the recovery continues. For the millions of Londoners whose data was exposed, the question remains: how many more attacks like this are coming?

Continue Reading

Trending