Desk live·
ForensicPost
Ransomware/Availability/File 23-0110

Royal Mail Could Not Send a Parcel Abroad for Six Weeks After LockBit Attack

The encryption landed on the systems at the distribution centre through which almost all mail leaves the UK. No customer database is at the centre of this file — the harm was that a national postal operator stopped being able to do the thing it exists to do.

Constructed geometry · not a chart of case data
JurisdictionUnited KingdomLangleythe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetRoyal Mail
ActorLockBit
S. Rosler10 min readConfidence: high2 sources reviewed

On 10 January 2023 Royal Mail was hit by a ransomware attack reported as LockBit, affecting IT systems at the Heathrow Worldwide Distribution Centre in Langley, Berkshire — the facility through which effectively all international mail enters and leaves the United Kingdom.

International export services stopped. Royal Mail restored them progressively and announced it was processing international parcels normally again on 23 February, six weeks after the attack.

One Building Was The Whole Service

The geography is the finding. A single distribution centre handling almost all cross-border mail means the resilience question was answered years before the attack, by the decision to concentrate the function there.

The corpus records the same shape at 26-0704 for shared airport IT platforms and at 25-1219b for a supplier serving two thousand practices. Concentration is chosen for cost and efficiency, and it is not wrong; it simply relocates the failure mode from many small outages to one total one.

The Cost Is Not The Ransom

Royal Mail’s parent, International Distributions Services, was reported to have spent £10 million on remediation and systems resilience in the six months to 24 September 2023. That figure is a rebuild, not a payment.

This desk files the distinction repeatedly — most directly at 25-0430, where the Co-op stated a revenue loss rather than an incident cost. What an organisation spends after an attack and what an attack cost it are different quantities, and only the first one ever gets published.

Nobody Could Post A Parcel

The people affected here had no account with Royal Mail, no credentials to rotate and no notification letter coming. They had a parcel that could not be sent. Availability harm falls on a population that the breach-notification apparatus has no way to see, which is why the corpus counts it separately and why the count is always missing.

How we reported this

Built on contemporaneous reporting of the attack, the service restoration and the parent company’s stated remediation spend. The attribution to LockBit is as reported at the time and is not a finding of this desk. The £10 million figure is International Distributions Services’ own reported spend on remediation and resilience over a stated six-month period; it is not a total cost of the incident and is not presented as one. No ransom demand figure is reproduced — the amounts circulated came from the operators’ own leak site. No volume of affected mail is asserted. Graded high on the outage, its duration and the reported spend. Corrections: corrections@forensicpost.com.

Sources
  1. Royal Mail restores global shipping weeks after LockBit ransomware attackTechCrunch
  2. Royal Mail spent £10m on cyber measures after LockBit attackComputer Weekly
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary