Educational & easy-to consume visual guides to understanding attacks & enhancing resilience
At Cyber Management Alliance, Incident Response and Ransomware Mitigation is our passion. We study and analyse cyber-attacks and ransomware attacks to create informational visual timelines which can be easily read for educational purposes and to enhance cyber resilience.
For the Royal Mail Ransomware Attack, we have created a visual timeline and an accompanying detailed report. Download it now.
Don't forget to read our blog on the Royal Mail Ransomware Attack.
Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.
On 10 January 2023, Royal Mail, the UK's largest mail and parcel delivery company, was hit by a ransomware attack later attributed to the LockBit group. The attack disrupted the back-office systems used to prepare and despatch mail to overseas destinations, forcing Royal Mail to suspend international export services and ask customers to stop posting items abroad. More than half a million parcels and letters were reportedly left in limbo, while UK domestic post and Parcelforce Worldwide services continued largely as normal. The disruption to international services lasted for weeks.
Royal Mail detected the incident on 10 January 2023 and disclosed it publicly within about a day, confirming that international export services were suspended. Through mid-January, reporting attributed the attack to LockBit, and on 17 January 2023 Royal Mail's chief executive confirmed the cyberattack to a UK parliamentary committee. LockBit formally claimed responsibility on 6 February 2023. International services remained disrupted for several weeks while Royal Mail worked on recovery.
The attack was attributed to LockBit, a prolific Russia-linked ransomware-as-a-service operation. The ransom notes generated during the incident pointed to LockBit's 'LockBit Black' encryptor and linked to the group's dark web sites. Attribution was initially muddied - LockBit's public representative first denied involvement and blamed others using a leaked version of its builder - but the group later confirmed that one of its affiliates had carried out the attack.
No. Royal Mail stated that UK domestic mail remained unaffected and that the impact was concentrated on international export services. Parcelforce Worldwide continued to operate to international destinations with some delays, and import operations ran largely as normal. The disruption centred on the back-office systems used to prepare items for despatch abroad and to produce customs documentation.
According to reporting, LockBit's 'LockBit Black' ransomware encrypted machines that Royal Mail used to print customs labels and dockets for parcels going overseas, and ransom notes were printed out on those same printers - including at a sorting office near Belfast. With the systems that prepare and track international mail knocked out across several sites, including its large Heathrow-area distribution centre, Royal Mail was unable to despatch items abroad and asked customers to hold international post.
This was not clearly established. LockBit's representative implied that data had been stolen and threatened to publish it, but did not detail how much or what type. Royal Mail said it had no evidence that customer data had been compromised, while acknowledging the position could change, and it notified the UK's data protection regulator as a precaution. The full extent of any data theft was not confirmed in reporting at the time.
There was no indication that Royal Mail paid a ransom. Reporting suggested the demand was expected to run into the millions, and LockBit said it would only provide a decryptor and delete any stolen data once a ransom was paid. Royal Mail did not confirm paying, and security commentators urged against payment; the company instead focused on restoring services with external experts and 'workarounds'.
Customers were temporarily unable to send letters and parcels overseas, and Royal Mail asked people not to post international items until services were restored. The disruption was especially damaging for small businesses that rely on international shipping - some reported refunding orders, losing sales and being unable to plan because of the uncertainty. More than half a million items were reportedly affected, and some customers faced extended delays.
LockBit was one of the most active ransomware-as-a-service operations of the period, generally described as Russia-linked. It develops ransomware - including the 'LockBit Black' encryptor used in this incident - and lets criminal affiliates use it in exchange for a share of any ransom. Reporting at the time noted LockBit ransom demands ranging from around two hundred thousand to roughly one and a half million US dollars, with the group running dark web leak and negotiation sites.
Royal Mail launched an investigation, engaged external cybersecurity experts, and reported the incident to its regulators and UK security authorities. The National Cyber Security Centre, part of GCHQ, helped Royal Mail remove the malicious software, and the National Crime Agency investigated. Royal Mail notified the Information Commissioner's Office as a precaution, kept customers updated, and worked to restore international services while managing a backlog worsened by earlier strike action.
When the ransom notes first emerged, LockBit's public-facing representative denied that the group had attacked Royal Mail and suggested other actors were using a leaked version of LockBit's builder. However, the Royal Mail ransom notes linked to LockBit's own negotiation and data-leak sites rather than any third party's, which cast doubt on that denial. Within days the group changed its position, admitting an affiliate was responsible, and on 6 February 2023 it formally claimed the attack.
The Royal Mail incident shows how ransomware can paralyse a critical operational function - here, international despatch and customs processing - and ripple out to thousands of businesses and customers, even without confirmed large-scale data theft. Key lessons include segmenting and protecting operational and back-office systems, maintaining tested backups and manual workarounds, rehearsing crisis communications for prolonged disruption, and engaging regulators and law enforcement early. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.