Menu
Browse

Cyber Incident Victim: MBA Group

Date:

Mar 2021

Location:

United Kingdom

Summary

MBA Group, a UK-based print services provider, experienced a cyber attack attributed to the Revil threat actor group, disrupting operations at its London and Warrington facilities. The incident caused phone systems to become inoperable, with the company aiming to restore services by the end of that week. This attack aligns with broader concerns that threat actors are specifically targeting firms supporting financial institutions.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

MBA Group, a UK-based print services provider with operations in London and Warrington, experienced a disruptive cyber attack around March 30, 2021. The incident halted normal business operations across both sites, rendering phone lines inoperable and forcing the company to work toward restoring systems. Sales director Kevin Stewart issued a public statement indicating the organization aimed to resolve the situation by the end of that week, though specific technical details regarding the attack vector or compromised systems were not disclosed. External analysis of dark web activity identified the ransomware group REvil (also known as Sodinokibi) as the perpetrators of the attack. The company’s lack of responsiveness to media inquiries by the time of reporting left several aspects of the incident unconfirmed, including the full scope of data access or encryption and precise recovery timelines.

Cyber Incident Image

The attack occurred amid broader concerns that threat actors were deliberately targeting third-party service providers to financial institutions, potentially seeking indirect access to sensitive banking or customer data through supply chain vulnerabilities. MBA Group’s operational disruption demonstrated immediate consequences, including communication breakdowns evidenced by non-functional phone systems and unspecified delays in service delivery. No public evidence emerged during the initial reporting period confirming whether client data was exfiltrated or whether ransomware payment demands were made. The company’s recovery efforts remained focused on restoring operational continuity, with no detailed disclosures regarding containment measures, forensic investigations, or coordination with law enforcement. The incident underscored the risks to critical business support sectors from sophisticated cyber criminal groups actively exploiting network vulnerabilities.

Sources
Sources available to members
1 source