Tewkesbury Borough Council have a cybersecurity incident and are containing their network.
I can see from their network border they’re shutting down edge and Windows services.
HT @d4rkshell
Tewkesbury Borough Council have published an FAQ on their cyber incident
They have isolated card payment.
Tewkesbury Borough Council are on day 5 of containment for their cyber incident. Media reporting suggests they have called in GCHQ, who are local to them (it’s probably more they just reported it to NCSC).
In their updated FAQ they ask the press to stop calling them about it.
From network traffic it looks like a crimeware group. #threatintel
@GossiTheDog Props to them for being somewhat open about this! Other councils have previously tried to just.. not talk about anything.
@GossiTheDog "network traffic"; where did you get that? I thought ISPs selling netflow data was an american enterprise