
Royal Mail is currently investigating a significant security breach after a threat actor leaked over 144GB of data allegedly stolen from the company’s systems. The British postal service confirmed they are aware of an incident affecting Spectos GmbH, a third-party data collection and analytics provider that works with Royal Mail.
“We are working with the company to investigate the issue and establish what impact there may be regarding their data,” a Royal Mail spokesperson stated. “We can confirm there has been no impact on Royal Mail operations and services continue to function as normal.”
Spectos acknowledged that their systems were breached on March 29, with attackers gaining unauthorized access to customer data. “The exact scope of the incident is currently the subject of intensive forensic investigations,” a Spectos representative explained.
## Leaked Information
The threat actor, using the handle “GHNA” on BreachForums, released 16,549 files allegedly containing:
– Royal Mail customers’ personally identifiable information (names, addresses, planned delivery dates)
– Mailchimp mailing lists
– Datasets of delivery/post office locations
– WordPress SQL database for mail agents.uk
– Internal Zoom meeting recordings between Spectos and Royal Mail Group
## Breach Method Identified
Cybersecurity firm Hudson Rock reports that attackers accessed Royal Mail systems using credentials of a Spectos employee that were compromised in a 2021 info stealer malware incident.
“The infected Spectos employee’s credentials provided a gateway to Royal Mail Group’s systems,” explained Hudson Rock CTO Alon Gal. “The stolen data sat dormant until recently, when it was weaponized in these high-profile leaks.”
This isn’t Royal Mail’s first security incident. In January 2023, the organization suffered a ransomware attack by the LockBit group that disrupted international shipping services for three weeks. Another outage in November 2022 affected tracking services for over 24 hours.
