Menu
Browse

Cyber Incident Victim: Serco Group

Date:

Jan 2021

Location:

United Kingdom

Summary

Serco, a contractor supporting NHS Test and Trace operations, experienced a cyberattack involving Babuk ransomware targeting its continental European division, which represented under 3% of its global business. The incident involved network encryption and data theft, with attackers demanding payment to restore access and prevent data disclosure; however, UK operations including NHS services remained unaffected. Security experts highlighted systemic vulnerabilities exposed by the breach, emphasizing risks to personal data despite no confirmed compromise of sensitive information in this instance.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On or around January 31, 2021, public services contractor Serco experienced a cyberattack impacting its mainland European operations. The company confirmed the incident involved Babuk ransomware, a malicious software variant designed to encrypt victim networks and exfiltrate data, with attackers demanding payment to restore access and prevent public release of stolen information. Serco, one of two primary contractors supplying call handlers for the UK's NHS Test and Trace program and one of five firms managing COVID-19 testing centers, emphasized that its UK operations—including all NHS-related services—remained unaffected. The attack was contained within Serco's continental European business division, which represented less than 3% of the company's global operations. No disruption to NHS Test and Trace contact tracing or testing center management occurred.

Cyber Incident Image

Serco's public response stated the incident had been isolated to European systems without compromising UK customer services. The company did not disclose whether data was stolen, operational systems were encrypted, or if a ransom was paid. Miles Tappin, VP of EMEA at cybersecurity firm ThreatConnect, identified the attack as exposing systemic vulnerabilities in data protection frameworks, particularly given Serco's role in public health initiatives. He noted that while no documents were confirmed compromised in this instance, the breach highlighted risks to personal information collected during pandemic response efforts. Tappin advocated for enhanced collaboration between government entities and contractors to centralize threat intelligence and strengthen defensive measures against evolving ransomware threats. The incident underscored ongoing security challenges for critical infrastructure suppliers during large-scale public health operations.

Sources
Sources available to members
1 source