Powered by MOMENTUM MEDIA
defence connect logo

Powered by MOMENTUMMEDIA

Powered by MOMENTUMMEDIA

Military personnel bank details exposed in UK cyber attack

The UK Ministry of Defence is set to announce details of a cyber attack targeting one of its contractors, which may have exposed details of military personnel and veterans.

The UK Ministry of Defence is set to announce details of a cyber attack targeting one of its contractors, which may have exposed details of military personnel and veterans.

According to the UK’s Sky News, Chinese-state hackers are believed to have been behind the attack, which targeted the IT systems of a UK Ministry of Defence (MOD) contractor which contained the names, bank details, and some addresses of both current personnel, reservists, and veterans.

The attack, which was confirmed by a source close to the matter, targeted a contractor responsible for payroll systems. Despite this, salaries for the month will not be impacted and personnel will still be paid.

==============
==============

Investigations to date conducted by the MOD have so far found nothing to indicate that exposed data was exfiltrated from the contractor’s systems, but the possibility has not been ruled out.

The MOD has commissioned another external contractor to monitor web activity and search for any indicators that data has been exfiltrated and leaked. Additionally, the MOD has engaged the assistance of private security specialists, intelligence firms, and the Cabinet Office for the investigation.

While the MOD has confirmed that the attack was on the contractor’s systems and that its own systems were not affected, it has so far provided no other details of the cyber attack.

Defence Secretary Grant Shapps is expected to provide details of the attack in a statement to MPs on Tuesday, UK time. While it is not expected that China will be specifically named as to blame for the attack, Shapps is expected to attribute the attack to a hostile nation.

Speaking with Sky News, former British soldier and Conservative MP Tobias Ellwood said China “was probably looking at the financially vulnerable with a view that they may be coerced in exchange for cash,” indicating that this may not have been an attack on national security, but rather the theft of financial information which would then be held to ransom or used in phishing attempts.

News of the MOD attack coincided with another threat actor claiming to have stolen the login information of over a million personnel from the UK government.

According to a BreachForums post by a threat actor called “USDoD”, a network misconfiguration issue allowed unauthorised access, leading to data exfiltration.

“The UK gov system had a misconfigured cdn issue that expose a lot of their users,” the threat actor said.

“I was able to extract more than 1M of users and a few more data.”

Within the post, the threat actor posted a “partial database” containing the username and password data of over 80 thousand users.

The database contains details for what appears to be a broad range of accounts, from immigration and visa services logins, to MoT testing, tax services, apprenticeship details and COVID-19 testing.

“I plan to release every data on UK gov I will just wait for the right moment,” the threat actor said.

“This is a friendly warning that I’m following every single action around the globe.”

You need to be a member to post comments. Become a member for free today!