The National Cyber Security Centre issued a targeted alert to English councils on Tuesday warning that ransomware affiliates are scanning payroll and human-resources portals in the fortnight before month-end salary runs, after LGSS Cyber and two unnamed district authorities reported overnight lockouts on systems that generate BACS payment files for thousands of staff.

What broke

Incident responders told InfoHandle that attackers gained initial access through password-spray hits on legacy VPN gateways still tied to outsourced HR suites, then moved laterally into payroll databases that hold national insurance numbers and bank sort codes. Encryption events were timed for Sunday night—hours before Monday morning reconciliation—when skeleton IT crews are slowest to pull offline backups. One authority restored from immutable snapshots after refusing a five-figure bitcoin demand; another is still printing emergency cheques for social-care workers while printers on the corporate network stay isolated.

LGSS Cyber, which monitors roughly 40 council tenants, said it logged a 37 percent week-on-week rise in payroll-adjacent brute-force attempts between 15 and 22 September, a pattern NCSC analysts correlate with affiliate playbooks that treat local-government pay cycles as predictable ransom leverage.

What NCSC confirmed

The alert does not name victim councils while ICO breach clocks run, but it restates mandatory controls: multifactor authentication on every remote path to HR systems, separation of payroll VLANs from public Wi-Fi, and offline, tested backups that can rebuild BACS files without touching live domain controllers. NCSC liaison officers are hosting closed calls with SOC teams Wednesday to share indicators tied to a cluster of .onion negotiation pages that reference “local gov pay” in ransom notes—language previously seen in Midlands housing-authority cases this summer.

Officials did not attribute the crew to a single ransomware brand; the National Crime Agency’s cyber unit is treating the campaign as commodity access brokered through initial-access markets rather than an insider at a payroll bureau.

Who has the file

ICO breach reporting rules require 72-hour notifications when employee bank details are exfiltrated; councils that only suffered encryption without proof of download still face scrutiny if payroll data was reachable. The Cabinet Office’s government cyber security strategy team is correlating incidents with PSN compliance scores, though most affected systems sit on commercial SaaS contracts outside PSN boundaries.

Insurers told brokers that cyber policies for district councils now exclude ransom payments unless boards document MFA rollouts—renewals this autumn are quoting higher excesses for authorities still running split HR and payroll tenants on end-of-life Windows stacks.

What is still unknown

NCSC has not published how many councils received extortion demands or whether any paid quietly through third-party negotiators—a practice the Home Office discourages but does not criminalise for victims. It is unclear whether attackers exfiltrated full salary ledgers or only sampled records to prove access; without forensic images, chief finance officers cannot tell MPs whether direct-debit fraud risk extends to residents whose bank details share the same outsourced platform.

Police have not announced arrests; investigators are pulling CDN logs from HR vendors that serve multiple authorities, which may explain simultaneous probes without a single shared breach.

What payroll teams should do this week

Freeze non-essential admin accounts, rerun month-end dry runs on isolated hardware, and verify BACS submission tokens have not been rotated by attackers posing as treasury staff. NCSC wants evidence that offline backups completed after the last pay run, not before—ransomware crews often dwell for weeks to poison incremental sets.

Staff should treat urgent “payroll portal migration” emails as suspect; two councils reported phishing templates mimicking LGSS Cyber branding hours before VPN lockouts. Report indicators through CiSP and Action Fraud even when ransoms are refused, so NCSC can block negotiation wallets faster.

Council read-through

Month-end pay is the soft underbelly of local government: politically toxic if late, technically concentrated in a handful of servers, and often maintained by vendors whose patch cadence lags corporate enterprise. The NCSC alert does not pause pay runs—it forces chief executives to choose between delaying salaries and running payments from potentially compromised workflows. For Tuesday’s picture, the confirmed facts are narrow: attacks clustered before BACS day, guidance went out, and at least two districts are rebuilding payroll under ICO watch. Everything else—scale, payment, attribution—remains open on incident dashboards.