Copy article

Network Rail cyber attack: "A potential danger is that anyone else using the public WiFi at the time could have had their data snooped"

ended 26. September 2024

Following the Network Rail cyber attack this morning, cyber attack, Newspage asked cyber security experts for their views on how it happens and whether consumers are at risk.

One, Alex Richards, Director at Liberate IT, said: "This will have been a malicious actor directly targeting the public wifi for propaganda purposes or to promote an agenda. Public WiFi is the easiest target due to its accessibility, and the most visible when tampered with. A potential danger is that anyone else using the public WiFi at the time could have had their data snooped. This is where information being sent from/to your device on the public WiFi is inspected and listened to. This is why it is important to only use encrypted services on public wifi, or a VPN service using encryption. Better yet, stay clear of public wifi and use your 4G/5G data service."

Another, James Bore, Managing Director at Bores Group warned that “the protection against this sort of attack is not to use public WiFi. When you do use it you are placing trust in the provider not to do this sort of thing, and while it's rare that these attacks happen there is nothing individuals can do to prevent them.”

Meanwhile Philip Cluff, CEO at Macartney-Cluff Advisory, a management consulting firm specialising in geo-political risk assessment including cyber security, commented: “The bulk of these attacks seem to focus on outdated software. No catch all solution exists, but tech literacy and the ability to recognise and mitigate an attack immediately through all levels of an organisation is the closest you get to effectively raising the alarm.”

3 responses from the Newspage community

Copy all

Star Quote
Copy

This will have been a malicious actor directly targeting the public wifi for propaganda purposes or to promote an agenda. Public WiFi is always isolated and firewalled from any other network so there will be no risk to data held or processed by Network Rail themselves. Public WiFi is the easiest target due to its accessibility, and the most visible when tampered with. A potential danger is that anyone else using the public WiFi at the time could have had their data snooped. This is where information being sent from/to your device on the public wifi is inspected and listened to. This is why it is important to only use encrypted services on public wifi, or a VPN service using encryption. Better yet, stay clear of public wifi and use your 4G/5G data service.
Star Quote
Copy

This sort of attack largely isn't a threat to users of the WiFi as it appears to be an activist attack designed to spread a message. From the details available it's likely the provider of the WiFi system was the one that was compromised, and a lot more of their clients than Network Rail will have been affected. However, with the busy stations they were noticed first. This sort of attack involves changing the home page (called the captive portal) to another page, and it can be used to steal credentials but in this case was used to spread a message. Honestly, the protection against this sort of attack is not to use public WiFi. When you do use it you are placing trust in the provider not to do this sort of thing, and while it's rare that these attacks happen there is nothing individuals can do to prevent them.
Copy

The Network Rail cyber-attack has exposed a ticking time bomb under the UK economy, highlighting a stark reality where today's cyber breach could lead to tomorrow's financial ruin. This is a stark reminder of the growing economic threats posed by cyber incidents to the UK's critical infrastructure. This incident raises serious questions about the resilience of our national systems and the potential economic impact of such breaches. Beyond the immediate financial toll, cyber attacks on infrastructure carry wider economic implications. In our interconnected economy, a significant attack on one sector could trigger a domino effect, with particularly acute risks for the financial and healthcare industries. While the attack on NR may not have caused significant wider economic damage, it has exposed potential fragilities in the UK's defences. Addressing these vulnerabilities must be a top priority as threats evolve, with cyber resilience a fundamental pillar of economic stability.