This ransomware may have stolen Christmas in cities, states, and companies across the US


A ransomware attack is disrupting operations at many major companies, and some workers are concerned that it could affect their last paychecks before the holidays — because their payroll provider, Kronos, is the one that’s dealing with the ransom. The incident has left entire cities and states trying to come up with a plan to get paychecks out to their workers, and could affect HR operations at organizations like New York City’s Metro Transit Authority, Honda, GameStop, and more.
One Whole Foods worker told NBC News that there’s “a real fear about our paychecks this upcoming Friday,” saying that employees had been to to use “a paper punch sheet to keep track of our hours.”
Kronos Private Cloud is a suite of human resources software operated by a company called Ultimate Kronos Group, or UKG. Initially, Kronos didn’t reveal how severe the issue might actually be: the company reported that its hosted versions of Workforce Central, TeleStaff, and other services were unavailable, and said that it didn’t have an estimate when they’d be back online. UKG recommended that its customers “evaluate alternative plans to process time and attendance data for payroll processing”.
But early the next morning, UKG revealed that the issue was deeper than a service disruption: the company said it had been the victim of a ransomware attack, saying “it may take up to several weeks to fully restore system availability.” It also said its backups were “currently unavailable.”
UKG’s list of clients includes some huge names including Tesla, GameStop, Honda, Sainsbury’s, Puma, the YMCA, MGM Resorts, the city of Denver, and New York City’s Metro Transit Authority. Medical facilities have also reportedly been affected — Honolulu’s EMS and Board of Water Supply used Kronos, along with San Angelo, Texas’ Shannon Medical Center and more.
Some companies have promised to get paychecks out, despite the disruption. According to NBC News, Whole Foods has said that it’ll be able to pay its employees on Friday, and the state of West Virginia has said that it’d already processed paychecks for December 17th, and is coming up with a plan for paying workers on the 31st. The City of Cleveland has reportedly said that employees will keep getting their paychecks, though it did say that some of them may have had their names, addresses, and partial social security numbers compromised.
However, anonymous sources told ZDNet that some companies will be missing payroll for the week. A post on the Sysadmin subreddit offers some insight as to why, as one person describes the Herculean efforts they’re taking to tally up employee hours and produce and mail checks without UKG’s services.
UKG hasn’t given details on the ransom, or talked about who’s behind it, according to NBC News. Not all of its products have necessarily been affected, though — the company claims the self-hosted versions of the affected applications should keep working fine, and that it doesn’t have evidence any product outside Kronos Private Cloud was affected in any way.
There’s been speculation that the ransomware attack could be linked to the massive log4j vulnerability that was recently discovered. But in an update to the site UKG set up to respond to this incident, the company said there’s currently “no indication” that the two events are linked, though it is still investigating.
A ransomware attack is disrupting operations at many major companies, and some workers are concerned that it could affect their last paychecks before the holidays — because their payroll provider, Kronos, is the one that’s dealing with the ransom. The incident has left entire cities and states trying to come…
Recent Posts
- I tried this new online AI agent, and I can’t believe how good Convergence AI’s Proxy 1.0 is at completing multiple online tasks simultaneously
- I cannot describe how strange Elon Musk’s CPAC appearance was
- Over a million clinical records exposed in data breach
- Rabbit AI’s new tool can control your Android phones, but I’m not sure how I feel about letting it control my smartphone
- Everything missing from the iPhone 16e, including MagSafe and Photographic Styles
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010