Menu
Browse

Cyber Incident Victim: Black and White Cabs

Date:

Jan 2023

Location:

Australia

Summary

A cyber attack involving a CryptoLocker virus disrupted Black and White Cabs' dispatch, administration, and booking systems, forcing the temporary shutdown of customer-facing services. The company engaged cybersecurity experts and its IT team for forensic investigation, reporting the incident to the Australian Cyber Security Centre. While no evidence of customer data compromise was found, additional security measures were implemented as a precaution. Restoration efforts prioritized containment, with phone bookings—representing over 80% of operations—resuming after partial system recovery. The attack was suspected to originate from a phishing vector, encrypting network contents and causing prolonged operational outages.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On January 31, 2023, Black and White Cabs detected suspicious activity on its network, prompting an immediate investigation. By the afternoon of February 1, the company confirmed a serious cybersecurity threat had compromised its dispatch and administration systems. Managing Director Greg Webb announced on February 2 that forensic analysis identified a CryptoLocker virus infiltrating the network, though investigations revealed no evidence of unauthorized access to customer, driver, operator, or staff data. The attack forced the company to take all customer-facing systems offline, including phone and online booking platforms, which handled over 80% of reservations. External cybersecurity experts were urgently dispatched from Sydney to assist the internal IT team in containment and recovery efforts. Black and White Cabs reported the incident to the Australian Cyber Security Centre (ACSC) in compliance with mandatory cyber incident reporting requirements.

Cyber Incident Image

The company implemented additional security measures across its network as a precautionary step while maintaining partial operations through staff working in-office and fielding communications via phone, email, and in-person visits. Service restoration faced significant delays due to concerns about residual virus activity, with Webb emphasizing that resuming operations prematurely risked further compromise. By February 6 at 1pm AEST, critical phone booking systems were restored after a week-long outage, though broader system recovery timelines remained unspecified. Throughout the incident, the company provided regular updates via email, SMS, Facebook, and dedicated web page announcements, including an FAQ section for passengers published on February 3. Operational disruptions primarily affected booking capabilities, while customer data protection and system integrity remained the organization's stated priorities during remediation.

Sources
Sources available to members
2 sources