Personnel Today
  • Home
    • All PT content
  • Email sign-up
  • Topics
    • HR Practice
    • Employee relations
    • Learning & training
    • Pay & benefits
    • Wellbeing
    • Recruitment & retention
    • HR strategy
    • HR Tech
    • The HR profession
    • Global
    • All HR topics
  • Legal
    • Case law
    • Commentary
    • Flexible working
    • Legal timetable
    • Maternity & paternity
    • Shared parental leave
    • Redundancy
    • TUPE
    • Disciplinary and grievances
    • Employer’s guides
  • AWARDS
    • Personnel Today Awards
    • The RAD Awards
  • Jobs
    • Find a job
    • Jobs by email
    • Careers advice
    • Post a job
  • Brightmine
    • Learn more
    • Products
    • Free trial
    • Request a quote
  • Webinars
  • Advertise
  • OHW+

Personnel Today

Register
Log in
Personnel Today
  • Home
    • All PT content
  • Email sign-up
  • Topics
    • HR Practice
    • Employee relations
    • Learning & training
    • Pay & benefits
    • Wellbeing
    • Recruitment & retention
    • HR strategy
    • HR Tech
    • The HR profession
    • Global
    • All HR topics
  • Legal
    • Case law
    • Commentary
    • Flexible working
    • Legal timetable
    • Maternity & paternity
    • Shared parental leave
    • Redundancy
    • TUPE
    • Disciplinary and grievances
    • Employer’s guides
  • AWARDS
    • Personnel Today Awards
    • The RAD Awards
  • Jobs
    • Find a job
    • Jobs by email
    • Careers advice
    • Post a job
  • Brightmine
    • Learn more
    • Products
    • Free trial
    • Request a quote
  • Webinars
  • Advertise
  • OHW+

Payroll softwareLatest NewsHR Technology

Payroll services at some firms disrupted after Kronos cyber attack

by Ashleigh Webber 17 Dec 2021
by Ashleigh Webber 17 Dec 2021 Some Kronos software products have been hit by a cyber attack
Postmodern Studio / Shutterstock.com
Some Kronos software products have been hit by a cyber attack
Postmodern Studio / Shutterstock.com

Payroll and timekeeping services at organisations that use Kronos HR software have been disrupted after it suffered a cyber attack which has forced its system offline.

Parent company Ultimate Kronos Group (UKG) warned that Kronos Private Cloud had been hit by a ransomware attack and had been taken offline, which had affected employers that use UKG Workforce Central, UKG TeleStaff, Healthcare Extensions, and Banking Scheduling Solutions.

In a message posted on its support forums, which was also emailed to customers, executive vice president Bob Hughes said it could be several weeks before the systems are back online.

“Given that it may take up to several weeks to restore system availability, we strongly recommend that you evaluate and implement alternative business continuity protocols related to the affected UKG solutions,” he said.

“We deeply regret the impact this is having on you, and we are continuing to take all appropriate actions to remediate the situation. We recognise the seriousness of this issue.”

Cyber security

How Covid-19 has added to ‘insider threat’ risks

Five ways HR can improve cyber security

Customers questioned whether any of their data had been compromised or lost, and asked why there was no back-up arrangement.

“This going to to be a huge hardship for our employees that depend on the premium pay such as night diff, meals, overtime,” one said.

Among the organisations affected in the UK were Sainsbury’s and Boots. Sainsbury’s uses Kronos software to log, store and process the hours staff work, and it has reportedly lost a week’s worth of data.

A Sainsbury’s spokesperson told Personnel Today: “We’re in close contact with Kronos while they investigate a systems issue. In the meantime we have contingencies in place to make sure our colleagues continue to receive their pay.”

Boots has also been affected by the outage.A spokesperson said: “UKG is the third party supplier of the time and attendance system that we use. It is currently experiencing a service outage following a suspected cyber attack. Whilst we wait for the service to be reinstated, we have implemented manual solutions to protect team member pay.”

A UKG spokesperson said: “UKG recently became aware of a ransomware incident that has disrupted the Kronos Private Cloud, which houses solutions used by a limited number of our customers. We took immediate action to investigate and mitigate the issue, have alerted our affected customers and informed the authorities, and are working with leading cybersecurity experts.

“We recognise the seriousness of the issue and have mobilised all available resources to support our customers and are working diligently to restore the affected services.”

Cyber security experts have warned that the attack is likely put significant pressure on HR teams in the busy weeks before Christmas.

“The estimated outage time of several weeks is likely to have a significant impact on organisations as they try to close the year while managing not only basic payroll, but also the bonuses and other annual calculations that need to take place,” said Erich Kron, a security awareness advocate at KnowBe4.

The estimated outage time of several weeks is likely to have a significant impact on organisations as they try to close the year while managing not only basic payroll, but also the bonuses and other annual calculations that need to take place” – Erich Kron, KnowBe4

“This attack drives home the need to not only have, but also to practice, disaster recovery and continuity of operations plans that can be enacted quickly and efficiently. The more heavily reliant organisations are on technical services, even those in the cloud, the more important it becomes to have a plan to operate without these services, even for a short time.”

Organisations should also be alert to the fact that ransomware gangs often act when firms are short-staffed due to holidays or when they are extremely busy, Kron added. This is because they hope the attack will take longer to spot and the victim will pay the ransom in order to get systems back online quickly.

Jake Moore, a global cyber security advisor at IT security company ESET and the former head of digital forensics at Dorset Police, said the impact of the attack on customers would be “tremendous”.

“Holidays, bonuses and a limited workforce all make this attack all that much worse plus the knock on effect to other businesses will also be felt more than usual,” he said.

“When you hear of attacks forcing companies back to pen and paper for trivial tasks such as monitoring timekeeping, it is shocking to think we are heading into 2022 with the same attack vectors as we have seen for much of the last decade.”

Sign up to our weekly round-up of HR news and guidance

Receive the Personnel Today Direct e-newsletter every Wednesday

OptOut
This field is for validation purposes and should be left unchanged.

Kronos and Ultimate Software merged to form Ultimate Kronos Group in 2020.

HR Systems opportunities on Personnel Today


Browse more HR systems jobs

Ashleigh Webber

Ashleigh is a former editor of OHW+ and former HR and wellbeing editor at Personnel Today. Ashleigh's areas of interest include employee health and wellbeing, equality and inclusion and skills development. She has hosted many webinars for Personnel Today, on topics including employee retention, financial wellbeing and menopause support.

previous post
Movers and shakers: HR appointments – Virgin Money appoints new group chief people officer
next post
Time to ditch the Covid clichés?

You may also like

HMRC taking ‘years’ to fix simple RTI payroll...

28 Feb 2025

Real-time reporting of benefits in kind to start...

30 Oct 2024

Taking off: how careers in payroll are evolving...

6 Sep 2024

Payroll professionals believe future lies in AI

2 Sep 2024

‘Be flexible’ with staff hit by IT outage,...

19 Jul 2024

How to avoid payroll errors when rolling out...

12 Jul 2024

Thousands of Asda staff hit by payroll error

25 Mar 2024

Surrey payroll error sees employees receive wrong wages

5 Mar 2024

The computer says ‘fraud’: how the Post Office...

2 Feb 2024

Leeds City Council selects MHR for HR and...

5 Oct 2023

  • 2025 Employee Communications Report PROMOTED | HR and leadership...Read more
  • The Majority of Employees Have Their Eyes on Their Next Move PROMOTED | A staggering 65%...Read more
  • Prioritising performance management: Strategies for success (webinar) WEBINAR | In today’s fast-paced...Read more
  • Self-Leadership: The Key to Successful Organisations PROMOTED | Eletive is helping businesses...Read more
  • Retaining Female Talent: Four Ways to Reduce Workplace Drop Out PROMOTED | International Women’s Day...Read more

Personnel Today Jobs
 

Search Jobs

PERSONNEL TODAY

About us
Contact us
Browse all HR topics
Email newsletters
Content feeds
Cookies policy
Privacy policy
Terms and conditions

JOBS

Personnel Today Jobs
Post a job
Why advertise with us?

EVENTS & PRODUCTS

The Personnel Today Awards
The RAD Awards
Employee Benefits
Forum for Expatriate Management
OHW+
Whatmedia

ADVERTISING & PR

Advertising opportunities
Features list 2025

  • Facebook
  • Twitter
  • Instagram
  • Linkedin


© 2011 - 2025 DVV Media International Ltd

Personnel Today
  • Home
    • All PT content
  • Email sign-up
  • Topics
    • HR Practice
    • Employee relations
    • Learning & training
    • Pay & benefits
    • Wellbeing
    • Recruitment & retention
    • HR strategy
    • HR Tech
    • The HR profession
    • Global
    • All HR topics
  • Legal
    • Case law
    • Commentary
    • Flexible working
    • Legal timetable
    • Maternity & paternity
    • Shared parental leave
    • Redundancy
    • TUPE
    • Disciplinary and grievances
    • Employer’s guides
  • AWARDS
    • Personnel Today Awards
    • The RAD Awards
  • Jobs
    • Find a job
    • Jobs by email
    • Careers advice
    • Post a job
  • Brightmine
    • Learn more
    • Products
    • Free trial
    • Request a quote
  • Webinars
  • Advertise
  • OHW+