CSIDB logo
Incident

Kingfisher plc

Incident posture

Attack window
Oct 2022
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2025-10-16 00:00

Linked entities

Victim
Kingfisher plc
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Oct 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Kingfisher experienced a breach of its IT systems by the LockBit ransomware group, which claimed to have stolen 1.4 terabytes of data including employee and customer personal information. The company acknowledged unauthorized access but contested the scale of the theft, asserting that only a limited number of non-sensitive files were copied. LockBit affiliates leaked credentials for internal systems such as Workday and Access accounts. The organization engaged third-party security specialists to investigate, secured affected systems, and reported no ongoing operational disruptions following the incident.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On or around October 1, 2022, Kingfisher experienced unauthorized access to its IT systems. The breach became public on October 17, 2022, when the LockBit ransomware cartel listed Kingfisher on its data leak site, claiming to have exfiltrated 1.4 terabytes of company data. LockBit affiliates asserted the stolen data included sensitive personal information belonging to employees and customers. The group published samples of allegedly compromised credentials, including email addresses and passwords tied to Kingfisher’s Workday and Access accounts. Kingfisher promptly engaged third-party IT security specialists to investigate the incident and contain the breach. The company confirmed the unauthorized access but contested LockBit’s claims regarding the scale and sensitivity of the stolen data.

Initial findings from Kingfisher’s investigation indicated only a limited number of non-sensitive files were copied during the intrusion. The company stated it found no evidence supporting LockBit’s assertion of 1.4 terabytes of exfiltrated data. Kingfisher secured its affected systems and reported no ongoing operational disruptions stemming from the incident. LockBit, a ransomware operation active since 2019, distinguished itself through a business-like affiliate model and persistence compared to defunct groups such as REvil and Darkside. While researchers noted LockBit’s operational efficiency, Kingfisher maintained its internal review did not corroborate the threat actors’ data theft claims. The company concluded its response by emphasizing system remediation and the absence of material operational impact.

Sources

Sources available to members: 1 source.

CSIDB