• Our booking engine at tickets.railforums.co.uk (powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

ASLEF website suffers cyber attack

357

Established Member
Joined
12 Nov 2018
Messages
1,371
Just received the following text:

Update: Ourselves and a number of other trade unions' websites have been the victims of a cyber attack. The DDoS attack was launched against the members' area of our website which has made the log in to the members' area inaccessible. We are working to resolve the issue. There has been no data breach.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Efini92

Established Member
Joined
14 Dec 2016
Messages
1,747
I've only ever used it to check salaries personally
You’ve already answered my reply :D

I don’t like that it’s possible to buy service badges on the store. They should be earned not bought.
 

357

Established Member
Joined
12 Nov 2018
Messages
1,371
You’ve already answered my reply :D

I don’t like that it’s possible to buy service badges on the store. They should be earned not bought.
They should be given for free once earned!
 

380101

Member
Joined
18 Feb 2015
Messages
1,001
They should be given for free once earned!

They are. Head office send out the appropriate badges to every Branch Secretary once a year for them to give out to the members due them.
 

357

Established Member
Joined
12 Nov 2018
Messages
1,371
They are. Head office send out the appropriate badges to every Branch Secretary once a year for them to give out to the members due them.
I've never had mine!

They are, but it’s wrong that I could log in tomorrow and buy a 50 year medallion.
Never got mine but agree on the second point!
 

Efini92

Established Member
Joined
14 Dec 2016
Messages
1,747
I've never had mine!


Never got mine but agree on the second point!
Your branch secretary from the year it was due should have it. I have a few spare from when I was BS, which one do you need?
 

Yew

Established Member
Joined
12 Mar 2011
Messages
6,552
Location
UK
I would imagine the intent is more for if they are lost, than to allow early acquisition.
 

mpthomson

Member
Joined
18 Feb 2016
Messages
970
Someone has a point to prove, although be better hacking the RDG/DFT as this will only offer more fuel for union fires,
Much more likely to be random mischief. All sorts of non-governmental organisations suffer from these kind of attacks occasionally. Often it's just people proving they can do it rather than any political motivation. Government departents are targetted almost daily.
 

PyrahnaRanger

Member
Joined
16 Aug 2022
Messages
83
Location
Lancashire
Much more likely to be random mischief. All sorts of non-governmental organisations suffer from these kind of attacks occasionally. Often it's just people proving they can do it rather than any political motivation. Government departents are targetted almost daily.

Whilst that may have been the case, most cyberattacks these days are all about the money - nearly half of those suffering an encryption attack will pay some ransom to try and recover their data. Most are criminal gangs based in Russia or the far east, and are regularly targeting government departments as well.

The attack described (denial of service) isn’t the most complicated, and may just have been bought as a service on the dark web, but if I were CISO to one of those unions, I’d be incredibly concerned that everything was in place to reduce the likelihood and mitigate against any further incursions.
 

Rail Quest

Member
Joined
8 Apr 2023
Messages
294
Location
Cheshire
Someone has a point to prove, although be better hacking the RDG/DFT as this will only offer more fuel for union fires,
Much more likely to be random mischief. All sorts of non-governmental organisations suffer from these kind of attacks occasionally. Often it's just people proving they can do it rather than any political motivation. Government departents are targetted almost daily.
The OP references something about other trade union websites being affected. To me, this could mean one of two things:
- The unions in question share the same service/service provider and are hosted on the same infrastructure, which would mean an attack on one is an attack on all
- Or there was some sort of anti-union influence here given that there are still some hacktivist actors in the cyber space, perhaps some have something against the unions, who knows

At the end of the day though, it's a DDoS. It's an attack that most modern systems and hosting options (such as Microsoft Azure) have built in protections against anyways. Given this system sounds like it might be an older system (?) then if it was just an attack on a single service provider, then I doubt this is anything more than a random attack.
 

DarloRich

Veteran Member
Joined
12 Oct 2010
Messages
29,306
Location
Fenny Stratford
MI5 never had to hack the NUM website ;)

This will be about data theft or extortion rather than intelligence - obviously!
 

43066

Established Member
Joined
24 Nov 2019
Messages
9,429
Location
London
ASLEF have sent a communication this afternoon stating that the attack is continuing, hence access to their website remains restricted, and suggesting that other TUs are also being targeted.
 

northwichcat

Established Member
Joined
4 Mar 2023
Messages
1,201
Location
Northwich
ASLEF have sent a communication this afternoon stating that the attack is continuing, hence access to their website remains restricted, and suggesting that other TUs are also being targeted.

I would make an educated guess that if anyone's specifically targeting trade union websites, it's because they've found a flaw in one and are attempting others to see if they have the same flaw.

At the end of the day though, it's a DDoS. It's an attack that most modern systems and hosting options (such as Microsoft Azure) have built in protections against anyways. Given this system sounds like it might be an older system (?) then if it was just an attack on a single service provider, then I doubt this is anything more than a random attack.

Indeed. The people behind Wannacry didn't originally intend to disable NHS trust systems or attempt to shut down DB, it was just those organisations were using an outdated system and had employees who were ignorant when downloading email attachments from unverified sources.
 

YorkRailFan

On Moderation
Joined
6 Sep 2023
Messages
1,245
Location
York
ASLEF website is showing a 403 Error when I go on it. Anyone else having this issue?
 

Top