Don’t do SECURITY. Do business SECURELY.

Royal Mail halts international exports after LockBit ransomware attack

A ransomware attack attributed to LockBit stopped Royal Mail sending letters and parcels overseas for weeks.

Royal Mail asked customers to stop sending international letters and parcels after a ‘cyber incident’ disrupted its export systems. The LockBit ransomware gang later claimed responsibility.

What happened

  • The attack hit systems used to prepare and track international mail, leaving large volumes of items stuck in the UK.
  • Ransom notes linked to LockBit were reportedly printed at a Royal Mail distribution centre.
  • LockBit published negotiation transcripts, reportedly showing an $80m ransom demand that Royal Mail refused to pay.
  • International services were restored gradually, with full service returning in late February 2023.

Why it mattered

The attack disrupted a piece of UK national infrastructure used by millions of businesses and consumers, and showed how ransomware can halt operations without touching core domestic services. The NCSC and the National Crime Agency worked with Royal Mail on the response.

Lessons for organisations

Organisations should map which systems their most important services depend on, keep tested backups and manual workarounds, and prepare a clear communications plan for customers during an outage. Decisions on ransom payment should be considered in advance with legal and law enforcement input.

Sources: BleepingComputer, TechCrunch

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights