UK telecommunications giant Colt Technology Services has officially confirmed that customer data was stolen during a cyberattack, marking the first time the company has acknowledged data theft since initially reporting the breach on August 12.
## What Happened
The Warlock ransomware group has gained unauthorized access to Colt’s systems and stolen sensitive customer documentation. The cybercriminals are now auctioning approximately 1 million stolen documents on the dark web for $200,000, according to posts on the Ramp cybercrime forum.
“A criminal group has accessed certain files from our systems that may contain information related to our customers and posted the document titles on the dark web,” Colt stated in an updated security advisory. The company has established a dedicated call center where customers can request lists of compromised filenames.
## Stolen Data Details
The compromised documents allegedly include:
– Financial information
– Network architecture data
– Customer information and documentation
Cybersecurity experts have verified the authenticity of the threat actors’ claims by matching identification codes used in the forum posts with those from previous Warlock Group ransom notes.
## About the Warlock Group
The Warlock Group, also known as Storm-2603, is a Chinese-attributed ransomware operation that emerged in March 2025. The group uses modified versions of leaked LockBit and Babuk ransomware tools to conduct their attacks.
Key characteristics of the group include:
– Ransom demands ranging from $450,000 to millions of dollars
– Exploitation of SharePoint vulnerabilities to breach corporate networks
– Use of customized ransom notes and dedicated dark web sites for negotiations
## Company Response
Colt has taken steps to limit the visibility of the incident by adding technical measures to prevent search engines from indexing their security advisory page. The company continues to investigate the breach and work with cybersecurity experts to assess the full scope of the attack.
This incident highlights the ongoing threat posed by sophisticated ransomware groups targeting critical infrastructure providers and the importance of robust cybersecurity measures in the telecommunications sector.
