Hackers publish over 4,000 files stolen from SEPA in ransomware attack
1.2GB of data was taken from the Scottish regulator's digital systems on Christmas Eve


Cyber criminals have published more than 4,000 files belonging to the Scottish Environment Protection Agency (SEPA).
The regulator fell victim to a hack on Christmas Eve, which saw around 1.2GB of data stolen from its digital systems, including databases, contracts, and strategy documents.
The incident has been claimed by the Conti ransomware group, which is considered the successor of the notorious Ryuk strain that was for a third of all ransomware attacks in 2020.
SEPA refused to pay the ransom, with its chief executive Terry A’Hearn saying that the regulator “won’t use public finance to pay serious and organised criminals intent on disrupting public services and extorting public funds”.
“We have made our legal obligations and duty of care on the sensitive handling of data a high priority and, following Police Scotland advice, are confirming that data stolen has been illegally published online.”
A’Hearn added that SEPA is “working quickly with multi-agency partners”, including the Scottish Government, Police Scotland, and the National Cyber Security Centre (NCSC), to “recover and analyse data then, as identifications are confirmed, contact and support affected organisations and individuals”.
Detective inspector Michael McCullagh of Police Scotland’s Cybercrime Investigations Unit said that the investigation remains “ongoing”.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
RELATED RESOURCE
Ransomware protection with Veritas NetBackup Appliances
How to use Veritas NetBackup and NetBackup Appliances to protect against and recover from ransomware attacks
“Police Scotland are working closely with SEPA and our partners at Scottish Government and the wider UK law enforcement community to investigate and provide support in response to this incident. Enquiries remain at an early stage and continue to progress including deployment of specialist cybercrime resources to support this response,” he added.
The Christmas Eve attack saw the environmental regulator experience a “significant systems outage” which affected its contact centre, phone lines, and email.
“Sadly we’re not the first and won’t be the last national organisation targeted by likely international crime groups. We’ve said that whilst for the time being we’ve lost access to most of our systems, including things as basic as our email system, what we haven’t lost is our twelve-hundred expert staff,” added A’Hearn.
SEPA’s regulated business and supply chain partners are able to access Police Scotland guidance and an enquiry form through a dedicated data loss support website, with a support line also available.
Having only graduated from City University in 2019, Sabina has already demonstrated her abilities as a keen writer and effective journalist. Currently a content writer for Drapers, Sabina spent a number of years writing for ITPro, specialising in networking and telecommunications, as well as charting the efforts of technology companies to improve their inclusion and diversity strategies, a topic close to her heart.
Sabina has also held a number of editorial roles at Harper's Bazaar, Cube Collective, and HighClouds.
-
From phone calls to roll calls: 3CX has the answer
How Yellowgrid, a 3CX Platinum distributor, has taken advantage of 3CX Phone System’s customisable nature to create a time-saving solution already embraced by over 100 UK schools
-
What is operational technology – and why is it at risk?
Explainer As operational technology becomes more connected, securing it from cyber threats is more urgent than ever
-
Average ransom payment doubles in a single quarter
News Targeted social engineering and data exfiltration have become the biggest tactics as three major ransomware groups dominate
-
BlackSuit ransomware gang taken down in latest law enforcement sting – but members have already formed a new group
News The notorious gang has seen its servers taken down and bitcoin seized, but may have morphed into a new group called Chaos
-
Google cyber researchers were tracking the ShinyHunters group’s Salesforce attacks – then realized they’d also fallen victim
News In an update to an investigation on the ShinyHunters group, Google revealed it had also been affected
-
Nearly one-third of ransomware victims are hit multiple times, even after paying hackers
News Many ransomware victims are being hit more than once, largely thanks to fragmented security tactics
-
75% of UK business leaders are willing to risk criminal penalties to pay ransoms
News A ransom payment ban is a great idea - until you're the one being targeted...
-
The Scattered Spider ransomware group is infiltrating Slack and Microsoft Teams to target vulnerable employees
News The group is using new ransomware variants and new social engineering techniques - including sneaking into corporate teleconferences
-
Hackers breached a 158 year old company by guessing an employee password – experts say it’s a ‘pertinent reminder’ of the devastating impact of cyber crime
News A Panorama documentary exposed hackers' techniques and talked to the teams trying to tackle them
-
The ransomware boom shows no signs of letting up – and these groups are causing the most chaos
News Thousands of ransomware cases have already been posted on the dark web this year