Cyberattack leaves Prisoner Vans vulnerable for three days

Serco, a services provider for the Ministry of Justice, is responsible for transferring prisoners between prisons, courts and more. Unfortunately, they have been impacted by a cyber-attack which led to the tracking devices and panic alarms being disabled on the prison vans. Microlise, who are the provider of Serco’s Tracking and Alarm software, were the target of a cyberattack which took the system offline for a reported 3 days.
Who are Microlise?
Microlise are a telematics and technology firm based in Nottingham, England who are said to provide “a seamless eco-system around remote assets for fleet operators and product manufacturers, enabling you to monitor, manage and maintain your business”. They boast a wide range of successful relationships with global corporations such as DHL, Carlsberg and JCB.
A wide range of Microlise services where reported to have been affected. However, Serco is thought to have been affected by their Fleet Telematics and Alarms downtime, which also affected mailing giant DHL.
How did this happen?
On the 31st October 2024, Microlise Group announced that a large amount of their services was affected by a cyberattack which started with them detecting unauthorised activity on their network.
During their investigation, they reported that some limited employee data had been impacted by the incident which is being handled with the relevant individuals. However, Microlise was confident in announcing that no customer data had been compromised.
As of the 18th November 2024, Microlise has published their final statement on the matter, reaffirming that no customer data had been leaked, and any employees affected would be taken care of with the correct authority.
How did this affect Serco?
After the hackers were able to take the Microlise systems offline – this led to Serco operations continuing WITHOUT proper tracking, alarms or security staff for 3 days.
As a response to this, Serco employees were told to keep their phones fully charged, and were told to make contact with their home base every 30 minutes. Despite this, Serco announced that “It is apparent that there are a number of staff concerns surrounding the safety of staff and custodies in our care, due to the Microlise outage that we are currently experiencing across the business”.
What does this mean for Businesses across the UK?
This case really highlights the threat cyberattacks can have on businesses, and how these widespread attacks can present issues across the country. No matter how big or small your business is – cybersecurity should always be the upmost priority, and can be enhanced by:
- Backup & Contingency: Based on the reactionary statement provided by Serco, they did not seem at all prepared for the threat of a cyberattack. Having a contingency plan which allow operations to go ahead as normal in these circumstances, will not only put the hearts of your staff at ease, but will also prevent any issues from arising due to downtime.
- Secure Software: As with any third-party software integration, you should always do your due diligence and ensure the software you are incorporating is secure and actively maintained by the provider in order to protect yourself in the ever-developing world of cyberattacks.
- Staff Education: Whilst in this case it may have not been a human error which led to this attack, educating your staff on the threats of cyberattacks and how they can manifest is a huge part in the battle to protect your business from threats. Do your staff know how to spot a complex phishing scam? Do they know what information they should be handing over at the appropriate points?
By keeping up to date with the latest cyber threats will not only allow you to be more informed, but will allow you to plan in advance to protect your business from these developing attacks.
Sources:
https://www.londonstockexchange.com/stock/SAAS/microlise-group-plc/company-page
https://www.techradar.com/pro/hackers-disabled-tracking-devices-and-panic-alarms-on-prison-vans




