CSIDB logo
Incident

One Call Insurance

Incident posture

Attack window
May 2021
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2025-10-24 00:00

Linked entities

Victim
One Call Insurance
Threat actors
2 actors
Sources
1 source

Timeline

Occurred
May 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

One Call Insurance suffered a ransomware attack by the Darkside gang, which demanded £15 million to prevent public release of customer data including passwords and bank details. The incident caused significant IT system disruptions, prompting the company to engage forensic specialists to restore services in a new secure environment while prioritizing customer support systems; investigations were ongoing to determine potential data compromise. Authorities including the ICO and industry regulators were notified, with Darkside's involvement highlighting the group's continued criminal activity despite prior claims of disbanding, and the gang was linked to the Carbanak cybercrime operation known for financial malware attacks.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On May 13, 2021, One Call Insurance, a Doncaster-based insurance firm, experienced disruption to its IT systems, later confirmed as a ransomware attack by the Darkside criminal group. The attackers deployed ransomware that displayed a message demanding £15 million in exchange for not publicly releasing stolen customer data, including passwords and bank details. One Call immediately engaged IT forensic specialists to investigate the incident and restore systems. The company prioritized rebuilding customer service systems in a new, secure environment to maintain support for existing clients. By May 21, One Call had not yet determined whether any data was exfiltrated or compromised during the attack. The incident was reported to the UK Information Commissioner’s Office (ICO) and relevant insurance industry regulators. One Call publicly apologized for service disruptions caused by the attack but did not disclose operational downtime duration or specific system vulnerabilities exploited.

The attack occurred amid heightened scrutiny of Darkside following its high-profile ransomware strike against Colonial Pipeline on May 7, 2021. Darkside had publicly announced its shutdown on May 14—one day after One Call’s compromise—but the Doncaster incident demonstrated the group’s continued operations despite this claim. Forensic investigators linked the ransomware to Darkside’s characteristic tactics, including Tor-based extortion threats and VMware ESXi hypervisor targeting observed in earlier campaigns. Security researchers previously associated Darkside’s infrastructure with Carbon Spider (Carbanak), a financially motivated cybercrime group active since the mid-2010s. One Call’s forensic team worked with authorities investigating the criminal organization, though no payment or data leakage was confirmed publicly. The company maintained customer services through its rebuilt environment while the original systems remained under investigation.

Sources

Sources available to members: 1 source.

CSIDB