The attack likely started on August 26, 2023, when a gov[dot]lk domain user said they had received suspicious links over the past few weeks and that someone may have clicked one. LGC services and the backup systems were quickly encrypted.
Source: Infosecurity