UK military targeted by Chinese hackers
In May 2024, a UK’s MOD contractor was a subject to a cyber attack by the Chinese threat actor which resulted in records of approximately 270,000 UK military personnel being stolen. The data exposed included payroll records of full-time, part-time and reservist personnel, including several MPs. The hackers got hold of their names, addresses and bank details. In addition to that, the contractor failed to report the breach for a few months. SSCL, the contractor in question, received negative publicity with then defence minister Grant Shapps announcing a full review of their work. This may well cause a loss of lucrative government contracts for them in the future. One of the consequences for the client of SSCL, the MOD, was the fact that the foreign adversary now had the name list of nearly all UK military servicemembers. This constitutes a major state security breach where the affected military personnel could potentially be targeted by phishing attacks, honey traps or tailgating attacks to gain access to the UK government’s sensitive data and systems. Following the attack, the UK government and the secretary of defence personally received a lot of unfavourable press coverage, suffering political consequences. Aside from that, the MOD had to offer the affected individuals credit check subscriptions which resulted in unnecessary expenses. It is not what the exploit was, but SSCL could have prevented the attack by following best cybersecurity practices. The company should also have reported the breach as soon as it occurred.
Comments
Post a Comment