Cyber-Attack Shuts Down London Councils; Aussie Industry Breaches Exposed

Show Links

In this episode, we discuss two recent, alarming cybersecurity incidents: a major attack that disrupted services across three London city councils, and a troubling new report on the mining and manufacturing sectors in Australia — revealing repeated, prolonged delays in detecting and reporting data breaches that exposed personal information of millions. These stories show that no business — whether government, public service or private enterprise — is immune.

Stories Covered

  • London councils cyber-attack disruption — Multiple UK councils had phone lines and online services taken offline following a cyber-attack on shared IT infrastructure.

  • Delayed breach detection in Australian mining & manufacturing sectors — 187 breaches since 2018 exposed personal data of up to 3.6 million people, often going undetected for months or even years.

Key Takeaways

  • Shared infrastructure creates systemic risk: a breach in one system can cascade across many organisations.

  • Delays in breach detection/reporting dramatically increase the damage and recovery cost.

  • Sensitive personal and financial data remains a prime target — not just for large enterprises, but across all sectors including industrial.

  • Proactive cybersecurity hygiene — monitoring, segmentation, data minimisation and clear breach response plans — are essential.

Sources & Further Reading

What To Do Next

  • Book your free Empower Systems Assessmentnationalpc.com.au/empower

  • Listen to my audiobook: Sitting Duck – The Phone Call You Don’t Want to Receive → Available now on Spotify and leading audiobook platforms

  • Subscribe to the Don’t Be A Sitting Duck Podcast for daily insights

Episode Transcript

Picture this: councils in central London have just shut down phone lines and online systems across several boroughs — affecting hundreds of thousands of residents — after a cyber-attack hits shared infrastructure. Meanwhile, across the oceans, some of Australia’s biggest mining and manufacturing operators are only discovering cyber breaches months or even years after the fact, potentially exposing personal data of millions. In this episode we’ll dig into both stories — what happened, why it’s so alarming, and what it means for any organisation, big or small. Welcome to the Don’t Be A Sitting Duck Podcast, I’m Leigh Kefford — let’s dive in.

A cyber-attack recently struck several London local governments: Royal Borough of Kensington and Chelsea (RBKC), Westminster City Council (WCC), and Hammersmith & Fulham London Borough Council. The shared IT infrastructure between them was compromised, leading to immediate shutdowns of phone lines and online services while authorities assessed the impact.

How It Happened & Why It Matters (UK Councils):
Because these councils share services and systems, a breach affecting one quickly rippled across all of them — demonstrating the systemic risk of shared infrastructure.

The disruption impacted essential public services (housing, billing, social services, etc.), threatening residents’ access to urgent support. With over half a million people served collectively, the fallout is significant.

Investigations are ongoing by the National Cyber Security Centre (NCSC) and the National Crime Agency (NCA), and it’s not yet clear whether data was exfiltrated — meaning potential privacy breach as well as service disruption.

Take Action (UK Councils → for businesses and organisations):

  • Treat any shared or outsourced infrastructure as a potential single point of failure — ensure you know exactly what you share with partners.
  • Maintain a solid incident response and business continuity plan — including isolation procedures to limit spread if a breach is detected.
  • Monitor all network segments, especially shared/third-party infrastructure, for suspicious activity.
  • Communicate proactively with stakeholders (clients, customers, or in this case residents) about potential disruption — transparency builds trust.

Incident Summary (Australian Mining & Manufacturing Sectors):
New data obtained under Freedom of Information reveals that since 2018, there have been 187 data breaches across Australia’s mining and manufacturing sectors, exposing personal information of up to 3.6 million people.

How It Happened & Why It Matters (Mining & Manufacturing):
Many of these operators took months — in some cases over a year — to detect an intrusion, and then additional time (on average 39 days) to report the breach. One particular breach took 520 days to detect, then 84 more days before reporting.

Most breaches (over 90%) were attributed to malicious attacks, including ransomware (which accounted for over a quarter).

A large portion of exposed data was highly sensitive — more than half involved financial information; 40% included tax-file numbers; and nearly 90% exposed contact details like addresses, emails or phone numbers.

The delay in detection and reporting drastically increases the potential harm: attackers get more time to move laterally, exfiltrate data, or deploy ransomware.

Take Action (Mining/General Business Advice):

  • Implement continuous monitoring and intrusion detection — don’t assume legacy industrial systems are “safe.”
  • Adopt data minimisation practices: only store what you truly need. Sensitive financial and personal data should be retained only if absolutely essential.
  • Segment networks — especially separate IT and operational systems — so that a breach in one area doesn’t compromise everything.
  • Establish strict and prompt incident detection + reporting procedures: aim to detect intrusions quickly, and notify relevant Stakeholders/regulators without unnecessary delay.
  • Regularly test and audit security on legacy/industrial systems (OT/IT convergence environments), where vulnerabilities are often overlooked.

That’s a wrap for today’s episode! Want more cybersecurity insights? Head over to sittingduck.com.au for show notes, resources, and the latest updates. Thinking about your business security? Here’s what to do next: Book your free Empower Systems Assessment to uncover vulnerabilities and learn how to strengthen your defences. Listen to my audiobook, Sitting Duck – The Phone Call You Don’t Want to Receive—a real-world look at Business Email Compromise. Available now on Spotify and leading audiobook platforms.

Until next time—stay safe, stay informed, and don’t be a sitting duck!

This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.