Cyber Incident Victim: RMD Kwikform
Date:
Dec 2020
Location:
United Kingdom
Summary
A construction firm involved in building the NHS Nightingale Hospital suffered a cyber attack involving encryption of all servers and workstations, coupled with a significant data breach. The REvil (Sodinokibi) group claimed responsibility, alleging theft of over 700GB of critical information including financial records, contracts, banking documents, email communications, and technical data, providing directory screenshots as evidence. The incident disrupted operations at the company, which had a parent organization previously targeted in a separate cyber attack.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
In November 2020, RMD Kwikform, a Walsall-based construction firm involved in building the NHS Nightingale Hospital, experienced a cybersecurity breach. The REvil (Sodinokibi) ransomware group claimed responsibility, asserting they had encrypted all company servers and workstations. Attackers alleged exfiltration of over 700GB of critical data including financial records, contractual agreements, banking documents, sales histories, email communications, databases, and technical specifications. As evidence, REvil published directory screenshots purportedly from the compromised systems. The incident was publicly disclosed on December 6, 2020, following BirminghamLive's initial reporting about the attack. RMD Kwikform confirmed it was actively investigating the security incident but did not provide specifics regarding operational disruption or data verification.

The breach occurred against a backdrop of prior cybersecurity issues affecting the company's corporate structure. RMD Kwikform's parent company, Interserve, had itself been targeted in a separate cyber attack earlier in 2020, though no explicit connection between the two incidents was established in available reports. REvil's public claims emphasized the scale of data compromise but did not disclose specific ransom demands or data release timelines. No customer or employee data specifics were confirmed in initial disclosures. The company's investigation remained ongoing at the time of public reporting, with no subsequent containment measures or recovery actions detailed in source material. BirminghamLive served as the primary public conduit for initial breach notification before cybersecurity outlets amplified the disclosure.
