Site navigation

DIGIT Expo 2025 | Inside the West Lothian Council Ransomware Attack

Elizabeth Greenberg

,

west lothian council cyber-attack
At DIGIT Expo, Ian Forrest of West Lothian Council and Ian McGowan of Barrier Networks, gives the audience an inside view of the cyber-attack that rocked the West Lothian Council.

A look back at cybersecurity this year is a look back at some of the most high-profile cyber-attacks to rock the UK in years. 

UK retail was terrorised by a merciless round of cyber-attacks coordinated by Scattered Spider, targeting Co-op, Marks and Spencer’s, and Harrods, costing the supermarket titans millions. M&S took months to recover fully, with the attacks leaving the rest of the retail industry shaking in fear. 

More recently, Jaguar Land Rover faced one of the most expensive cyber-attacks the UK has ever seen (around £1.9bn), with the ransomware attack disabling much of the car manufacturer’s operations. 

While the private sector has faced a torrent of cyber-attacks, the public sector in the UK also felt the heat of evolving and emerging cyber threats. 

Several NHS boards faced data breaches, and the West Lothian Council faced a major ransomware attack this year that attempted to bring its educational system to its knees. 

At DIGIT Expo 2025, Ian Forrest of West Lothian Council and Ian McGowan of cybersecurity firm Barrier Networks gave delegates a first-hand account of the ransomware attack that took place just this May and is still under active investigation. 

Under Attack

Ian Forrest woke up on the 6th of May to a ping on his phone at around 7am – the first of many.

On the Tuesday morning, teachers working in West Lothian attempting to log into their school systems were met with a GPO logon screen alerting them that their accounts have been compromised, their data was encrypted, and they needed to pay a ransom in order to retrieve it. 

“Obviously, the teachers are a little bit scared,” Forrest said. When the news hit Forrest, the head of IT at West Lothian Council, his team began their investigation. 

The IT team quickly began to investigate its firewalls, and identified invalid traffic across its education network. 

“At that point we disabled staff access just to stop the traffic from hitting these systems,” Forrest said. The speed of reaction is vital in mitigating the damaging effects of a cyber-attack. For instance, while Co-op’s systems did face detrimental damage due to its cyber-attack, it avoided much worse potential circumstances by shutting its systems down sooner, rather than keeping them open to both customers and attackers. 

“For most organisations, cyber-attacks don’t happen very often, so it’s a shock to the system,” McGowan said. 

However shocking this is, the ripple effect of initial shock can be mitigated with proper incident planning. 

Adopting a “when is now” defence strategy is key in today’s world of evolving and ever-present cyber threats. 

“When not if, is the new norm” Forrest said, “We should all be planning for when it happens, not if it happens. If an actor really wants to compromise your systems, they will. It’s how you prepare for that scenario and ultimately deal with it.”

West Lothian Council dealt with that reality by implementation of a Cyber Incident Response Plan (CIRP) that streamlined their overall response.

But beyond this, the council also developed their existing business continuity plans across all their services, enabling different teams to understand how to operate under various cyber incidents. In some cases, businesses would have plans in place on how to operate without any internet access, if they were cut off from their overall systems or different data stacks. 

With this in mind, 48 hours into the West Lothian Council attack, the IT team was already making good use of the Cyber Incident Response Plan and was focused on communication across departments, third parties, and cyber agencies to delve into the problem and mitigate any fallout. Meanwhile, affected services, in this case education, were already underway in their business continuity plans. 

“So within those first 48 hours there was a lot going on with this communication process,” Forrest said. 

“We had to update our partners” – which included third-party partners, infrastructure stakeholders, and cybersecurity agencies in a bid “to give assurances at the early stage around the incident, that it had been contained, and the measures we put in place to do that.”

Defence in Action 

Upon discovering the invalid traffic, one of the decisions Forrest said made the biggest impact in their incident response was in blocking off the affected system. 

But this relied on a system of domain segmentation – West Lothian Council operates in three segregated domains in its server infrastructure. This includes a corporate network, an education network, and a public access network. 

The data involved in these systems are segregated from other departments on three levels, through a physical data level, a virtual firewall, as well as a physical appliance. 

“At the time of the incident, we were able to see the traffic within the education network, and we were able to block the VRF so that it could not communicate anymore with the outside world, disabled internal VLANS within the network to prevent any communication between user networks and server networks.”

The team was also able to block the external IP addresses and seek communication as well. West Lothian Council also employs a 24/7 service that they engaged with in order to start identifying the compromise. 

Communication continued to be paramount in every stage of the council’s response tactic, but the main factor that made a difference in their response was in their preparation. 

Making Practice Perfect

Forrest is not comfortable with only running cyber desktop exercises – they can give a false sense of security, literally. 

One of the things that set West Lothian Council apart in its  cyber breach preparation – with regards to staging a ransomware software attack – was creating its own fake ransomware and ‘infecting’ their systems, going so far as to pretend to ‘encrypt’ their own data to run a more true-to-life test. 

For Forrest, it is not just as simple as creating a CIRP and a business continuity plan, or running training. 

“Are you updating your user awareness training, are you refreshing that on a daily basis to be aware of the evolving landscape? Are you thinking about how to make these exercises more engaging to individuals rather than to just catch them out?”

Intense, true-to-life training and testing of systems and the people behind them is essential in ensuring that a response to a cyber incident is swift and effective.


Recommended reading


Lessons Learned

When West Lothian Council discovered the damage from the ransomware attack, it turned out the culprit, Interlock -a notorious ransomware group that had cropped up in the past couple of years – had done some interesting things with the Councils’ data. 

While data had been stolen, they encrypted the C-drive rather than the data, making the data itself available to a certain degree. Essentially, the data was still there despite the culprits encrypting backups. 

“It was kind of untoward,” Forrest said. 

While much of the potential damage of the cyber-attack was therefore mitigated by the nature of the attack itself, as well as the Council’s robust response, the security team was still able to use this as a learning experience. 

Improving end point security, introducing greater security practices and controls, and moving education data fully into the cloud were some of the major landscape changes the Council took following the attack. 

But more key to the Councils’ response was a change in culture. 

The education department had, according to Forrest, largely been resistant to increased security measures which could impact teaching and learning across education. 

“One example would be the discussion on the use of complex passwords of which younger learners would find difficult to remember,” Forrest said. 

This cyber-attack however ensured that the IT department could push for more stringent protocols. As teachers could directly see the fallout of lesser cyber hygiene, it was easier to make the argument to the board to push for greater changes and awareness. 

Discovering how the attack occurred also gave the IT department more authority in fighting for improved cybersecurity posture overall. 

It was a couple of months before the team identified patient zero for the cyber-attack, which turned out to be a compromised website and compromised security captcha.  

“Everyone was fairly relieved when they found it, because it could put some rationality about how this happened, and it gave justification for us,” Forrest said. 

“Its something that is easily done, something you could do tonight at home accessing the internet,” Forrest explained. 

Making sure that people understand how easily these things can happen, and taking a “when, not if” approach, can make a huge difference in the overall cyber posture of an organisation. 

The incident made it clearer to education and the overall council board that they needed to let IT take the lead on cybersecurity. Stronger passwords and MFA are the new norm across the department, while devices were replaced and issued with tightened security tools. 

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data