Colt
– Colt

U.K. telecom giant Colt Technology has given an update on its recent cybersecurity attack, telling users its recovery will continue into November.

August saw a ransomware breach take various services from the operator offline, with the attack detected on its internal business support system (BSS), separate from Colt’s customer network.

In an update from this week, Colt wrote the majority of its recovery efforts are set to complete within eight to 10 weeks, with a priority on early restoration of customer services such as its customer portal and Voice API platform.

Colt also reminded users its BSS and operational support system (OSS) were separate environments, with “no reason to believe that the OSS is at risk of compromise.”

“We can also confirm that important foundational work in our recovery program is now complete, and we are moving at pace on the restoration of our core processes and systems, which we will bring back in a deliberate sequence,” the operator shared.

Colt attack timeline

On August 14, cybersecurity analyst Kevin Beaumont reported web scan data illustrating malicious network traffic attempting to connect to Colt's Microsoft SharePoint servers, which Colt subsequently disconnected.

Evidence suggested that attackers had secretly installed web shells, which are malicious scripts uploaded to a web server that allow an unauthorized user to gain remote administrative control via a browser.

Beaumont speculated that the breach was connected to a pair of remote code execution (RCE) flaws in SharePoint, specifically one identified as CVE-2025-53770. Palo Alto Networks’ Unit 42 recently told SDxCentral that the “high-severity, high-urgency threat” enabled threat actors to circumvent authentication mechanisms, including multifactor authentication (MFA) and single sign-on (SSO), to achieve privileged access.

Ransomware group WarLock admitted responsibility for the attack on August 15, with reports it was selling one million Colt company documents for the price of $200,000.

Colt later revealed customer data was included in the haul, with a permanent FAQ section on its site stating: “It is possible that such customer or supplier personal data is contained within the accessed files. However, this does not mean that all of this information is in the files accessed by the threat actors. The threat actor has only posted document titles on the dark web. So far, no Colt data other than a list of file names has been published.”

Colt has seemingly yet to confirm whether financial and employee data are also leaked in Warlock’s files, as claimed by the ransomware group.

The breach represents a rare cybersecurity concern for Colt, which earned secure access service edge (SASE) plaudits from industry trade group MEF in November 2024, meeting its standards in SD-WAN, secure service edge (SSE), and zero-trust capabilities.