DXC subsidiary hit by ransomware attack
Some customers with the insurance-based company Xchanging were unable to access IT services
Global IT services provider DXC Technology has confirmed that its subsidiary managed service business, Xchanging, was recently targeted by a ransomware attack.
The company is confident that the attack was isolated to the confines of the Xchanging network, with no data that belongs to the managed services subsidiary for the insurance sector compromised or stolen.
Little information on the timescale of the attack or the scale of resultant disruption has been offered by DXC, but the company confirmed it implemented a series of containment and remediation measures to resolve the situation.
DXC is also working with affected customers to restore access to their operating environment as quickly as possible. This is in addition to a continued dialogue with law enforcement and cyber security agencies.
The company assists global firms with the smooth running of mission-critical systems and operations while also engaging in digital transformation endeavours, and ensuring security and scale across several types of cloud environment. Prominent customers include DreamWorks Animation, Aviva and the NHS.
Xchanging, meanwhile, is a business process and technology services provider and systems integrator, headquartered in London, with customers exclusively in the insurance sector.
Ransomware has been on the rise in recent months in years, causing disruption for a number of high profile targets of late, including Japanese car manufacturer Honda, in June. The ransomware attack forced the company to put manufacturing on hold in some locations.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Another key firm in the IT channel, Cognizant, suffered a large ransomware attack in April 2020, which directly involved internal systems and led to service disruptions for a handful of its clients.
The kind of ransomware that may potentially target your business also varies depending on the sector you’re in and where your business is geographically-based. In the UK, for instance, Leeds-based companies are most likely to fall victim to Rapid ransomware, while GrandCrab ransomware will be the cause for most ransomware attacks in Manchester.
What’s indisputable, however, is that ransomware threats are becoming more present, with a 195% increase in reported incidents between 2018 and 2019.

Keumars Afifi-Sabet is a writer and editor that specialises in public sector, cyber security, and cloud computing. He first joined ITPro as a staff writer in April 2018 and eventually became its Features Editor. Although a regular contributor to other tech sites in the past, these days you will find Keumars on LiveScience, where he runs its Technology section.
-
Google Cloud's record results can't quiet concerns on AI spending and model release timelinesNews Sundar Pichai defended the cost of AI rollouts and delays to frontier models following quarterly results
-
Palo Alto Networks targets application observability gains with latest acquisitionNews The company will integrate Embrace features with its Cortex AgentiX service
-
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in JuneNews The Gentlemen, a ransomware a service operator, now accounts for 17% of published attacks
-
Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clientsNews Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals
-
Ransomware negotiator sentenced for role in major cyber crime groupNews Deniss Zolotarjovs was a key player in a group associated with Conti