News
MARKET SIGNAL:

NFSP Ransomware Attack Turns Supplier Email Pause Into a Security-Control Test

Newsroom brief

The National Federation of Subpostmasters was hit by ransomware after a cPanel-related hosting software bug was exploited. The NFSP was targeted on 30 April, and the Post Office paused some email interactions with the federation while saying branch operations were not affected. The immediate test is whether trusted communications can resume without pushing subpostmasters toward insecure workaround channels.

Verified against source materialEdited by SendTech Times Cybersecurity Desk
NFSP Ransomware Attack Turns Supplier Email Pause Into a Security-Control Test
Image source: ComputerWeekly.com

NFSP Email Pause Shows a Supplier-Side Cyber Risk

The National Federation of Subpostmasters (NFSP) has been hit by a ransomware attack after a bug was exploited in software used by its web hosting provider, forcing the Post Office to pause some email interactions with the federation.

The NFSP was targeted on 30 April, days after a vulnerability in cPanel software was discovered and exploited by hackers. cPanel is a web-based hosting control panel used to manage servers and websites.

NFSP CEO Calum Greenhow said the website was hit by ransomware after the cPanel attack.

He said attackers made “demands for release of our files,” the incident had been reported to the Information Commissioner’s Office (ICO), and his IT team had confirmed no data was lost.

Operational Controls Move Beyond the Victim Network

Ransomware is malware that locks or encrypts files, devices or systems until attackers receive payment.

In this case, the immediate operational impact is not described as a Post Office network compromise, but as a disruption to communications with an external supplier.

A Post Office spokesperson said some interactions and integrations with the affected supplier had been temporarily suspended as a precaution.

The spokesperson added that branch operations were not affected and that no compromise of Post Office networks or applications had been identified.

Post Office Chief Information Security Officer Neil Bennett warned subpostmasters on 22 May that inbound and outbound email between the Post Office and the NFSP had been paused.

Emails to @nfsp.org.uk would not be delivered, and emails from @nfsp.org.uk would not reach inboxes during the pause.

The Reader-Risk Control Is Identity and Channel Discipline

Bennett told subpostmasters not to work around the pause using insecure electronic channels such as personal email, text or WhatsApp.

If telephone calls with NFSP stakeholders were required, he advised validating identity before discussing potentially sensitive information, including turning on cameras.

In an update on 2 June, Bennett said the issue remained ongoing and that earlier guidance had not changed.

The practical question is whether the NFSP and the Post Office can restore trusted communications without creating a secondary social-engineering risk through unofficial channels.

Share this article
inXf

Related articles

More
Check Point VPN Exploitation Puts Legacy IKEv1 Access In The Ransomware Spotlight
Cybersecurity

Check Point VPN Exploitation Puts Legacy IKEv1 Access In The Ransomware Spotlight

A critical Check Point VPN flaw, CVE-2026-50751, is being exploited against legacy IKEv1 remote-access configurations, with activity tied in one case to a Qilin ransomware affiliate and a second related VPN issue also disclosed.

AI-Built Ransomware Toolkit Turns EDR Evasion Into a Faster Cybercrime Workflow
Cybersecurity

AI-Built Ransomware Toolkit Turns EDR Evasion Into a Faster Cybercrime Workflow

A ransomware-focused threat actor adopted an AI-built toolkit for Active Directory discovery and endpoint detection and response evasion. Sophos found Cursor and Claude Opus agents assisted development, with close to 80 modules tested against more than 70 techniques. The practical question is whether defenders can shorten validation cycles as AI accelerates the move from offensive research to working malware components.

UAE Crypto Discovery Tool Turns Post-Quantum Security Into an Inventory Test
Cybersecurity

UAE Crypto Discovery Tool Turns Post-Quantum Security Into an Inventory Test

The UAE launched a national Crypto Discovery Tool to help organisations identify and manage cryptographic systems before post-quantum migration. The platform was developed by the UAE Cyber Security Council and Abu Dhabi-based QuantumGate as part of the National Post-Quantum Migration Programme. The practical question is whether public- and private-sector organisations use the tool to build a reliable inventory of cryptographic exposure.

CISA Android and Linux Warnings Put Patch Timing Back on the Security Agenda
Cybersecurity

CISA Android and Linux Warnings Put Patch Timing Back on the Security Agenda

CISA added exploited Android and Linux vulnerabilities to its Known Exploited Vulnerabilities catalog. The Android flaw affects Android 14 through 16, while the Linux issue centers on older kernel branches and cgroups v1 container environments. The immediate test is whether agencies and infrastructure operators apply vendor updates or mitigations by CISA's June 5 deadline.

Cisco Unified CM Flaw Puts WebDialer Exposure Under Patch Pressure
Cybersecurity

Cisco Unified CM Flaw Puts WebDialer Exposure Under Patch Pressure

Cisco disclosed fixed-release guidance for a critical Unified Communications Manager flaw that can let attackers gain root privileges when WebDialer is enabled. Cisco PSIRT is aware of public proof-of-concept exploit code for CVE-2026-20230, though it has not found active exploitation or targeting. The immediate test is whether administrators patch Unified CM or disable WebDialer before proof-of-concept code turns into wider exposure.

CISA WebLogic Warning Turns Oracle Patch Lag Into an Exposure Test
Cybersecurity

CISA WebLogic Warning Turns Oracle Patch Lag Into an Exposure Test

CISA ordered U.S. federal agencies to patch Oracle WebLogic Server systems affected by CVE-2024-21182 after active exploitation was observed. Shodan tracks more than 1,592 exposed WebLogic servers vulnerable to the flaw, including 961 on version 12.2.1.4.0 and 631 on version 14.1.1.0.0. The immediate test is whether public- and private-sector defenders apply Oracle fixes or remove exposed systems where mitigations are unavailable.

Keep Reading

More Stories

Latest
Coratia Gets Rs 66 Crore Navy Order For Underwater RobotsCapital & PolicyJul 21, 2026Coratia Gets Rs 66 Crore Navy Order For Underwater RobotsYourStory reported that Coratia Technologies has a Rs 66 crore Indian Navy contract for indigenous underwater ROVs, moving the Odisha startup from inspection prototypes toward defence delivery.Finland Data Centre Growth Faces Grid And Heat-Reuse TestsCloud & Data CentersJul 20, 2026Finland Data Centre Growth Faces Grid And Heat-Reuse TestsFinland is attracting AI data centre projects because of low-carbon power, cool weather and land, Data Center Knowledge reported, but grid connections, permitting and waste-heat rules now determine how much capacity becomes operational.Bank Of Korea Expands CBDC Pilot To Nine Banks In SeptemberFintech & Digital PaymentsJul 20, 2026Bank Of Korea Expands CBDC Pilot To Nine Banks In SeptemberCoinDesk reported that the Bank of Korea will move its CBDC programme into September real-transaction testing with nine participating banks, using BOK infrastructure while lenders issue and manage deposit tokens.SAP Closes Prior Labs Deal For Tabular AI ModelsAIJul 20, 2026SAP Closes Prior Labs Deal For Tabular AI ModelsSAP has closed its Prior Labs acquisition and committed more than EUR1 billion over four years to a Freiburg AI lab whose models work on structured business data rather than general chatbot content.Google DeepMind Sets AI Bioresilience Work Around 15-Plus PartnershipsAIJul 20, 2026Google DeepMind Sets AI Bioresilience Work Around 15-Plus PartnershipsGoogle DeepMind and Isomorphic Labs have outlined an AI bioresilience programme with more than 15 partners, framing biological AI safety around prevention, outbreak detection and medical response.Sateliot Seeks €150 Million For Satellite-To-Phone 5G By 2028Telco & ConnectivityJul 20, 2026Sateliot Seeks €150 Million For Satellite-To-Phone 5G By 2028Sateliot is seeking up to EUR150 million to expand from satellite IoT links toward direct-to-smartphone 5G service, with 16 more low-Earth orbit satellites planned before larger spacecraft in 2028.Raidium Launches AI Radiology Viewer At Moffitt Before FDA ClearanceAIJul 20, 2026Raidium Launches AI Radiology Viewer At Moffitt Before FDA ClearanceRaidium Read is being used at Moffitt Cancer Center for research and clinical trials before FDA 510(k) clearance, making the US launch a workflow test rather than a fully cleared commercial rollout.Denmark Grid Plan Gives Hospitals Priority Over DatacentresCapital & PolicyJul 20, 2026Denmark Grid Plan Gives Hospitals Priority Over DatacentresDenmark's emergency grid proposal would move hospitals, defence and emergency services ahead of most datacentre projects in the electricity-connection queue as applications rise far beyond peak national load.Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery ChainCybersecurityJul 20, 2026Fake GitHub Repositories Turned Developer Trust Into BoryptGrab Delivery ChainDeveloperTech's article on Arctic Wolf Labs research describes a fake-repository campaign that used polished GitHub project pages as a delivery route for BoryptGrab malware. The case makes artifact provenance and workstation controls more important than visual trust in repository pages.IBM Research Tests Agent Routing On Cost, Latency And AccuracyAIJul 20, 2026IBM Research Tests Agent Routing On Cost, Latency And AccuracyA Hugging Face post from IBM Research said model routing for enterprise AI agents should optimise cost, quality and latency together after AppWorld tests reversed a simple token-price comparison.IBM Study Finds UAE AI Vendor Switching RiskCapital & PolicyJul 20, 2026IBM Study Finds UAE AI Vendor Switching RiskMiddle East AI News, citing IBM Institute for Business Value data, said 88 per cent of surveyed UAE executives would struggle to switch their primary AI vendor or model, while 96 per cent did not fully understand dependencies across vendors, models and infrastructure.Regions Bank Digital Transactions Reach 80% After Mobile UpgradeFintech & Digital PaymentsJul 19, 2026Regions Bank Digital Transactions Reach 80% After Mobile UpgradePYMNTS reported that Regions Bank’s second-quarter materials listed digital transactions at 80% of customer activity, with mobile users, logins, Zelle usage and chat volume rising as core modernisation continues.