NCSC investigate whether UK was impacted by cyberattack on US agencies

14 December 2020, 15:54

Jeremy Fleming
GCHQ investigate whether any UK impact from cyber attack on US agencies. Picture: PA

GCHQ chief says UK is ‘working at pace’ with US partners in government to understand cyber threat.

Security services are currently investigating whether a major cyber attack targeting US government agencies has had any impact on the UK.

Experts suspect that Russian hackers are behind the incident which affected a server software called SolarWinds Orion, used by organisations across the world, including US Treasury and Commerce departments, and thought to be linked to an earlier cyberespionage campaign against cybersecurity firm FireEye.

According to the US Cybersecurity and Infrastructure Security Agency (CISA), the vulnerability allowed an attacker to gain access to network traffic management systems with a “high potential for a compromise of agency information systems”.

The Embassy of Russia in the USA called reports of the country’s involvement “unfounded attempts of the US media to blame Russia for hacker attacks on US governmental bodies”.

In the UK, the National Cyber Security Centre (NCSC), part of GCHQ, said it is “working closely with FireEye and international partners” to understand any ramifications across the Atlantic.

“Investigations are ongoing and we are working extensively with partners and stakeholders to assess any UK impact,” a spokesman said.

“The NCSC recommends that organisations read FireEye’s update on their investigation and follow the company’s suggested security mitigations.”

Speaking about the situation at a Chatham House event on Monday, GCHQ director Jeremy Fleming said both cases are “very serious”.

“We are working at pace with US partners in government and in the private sector to understand what this means,” he said.

“I haven’t seen any news as yet on the extent to which any customers of FireEye – or the particular instances which have affected US government – have been affected here and have had an impact here in the UK, but obviously we’ll continue to work very closely with them and if we do we’ll work very quickly to make sure that the most up-to-date advice is out there. “

By Press Association

More Technology News

See more More Technology News

Person on laptop

UK cybersecurity firm Darktrace to be bought by US private equity firm

Mint Butterfield is missing in the Tenerd

Billionaire heiress, 16, disappears in San Francisco neighbourhood known for drugs and crime

A woman’s hand presses a key of a laptop keyboard

Competition watchdog seeks views on big tech AI partnerships

A woman's hands on a laptop keyboard

UK-based cybersecurity firm Egress to be acquired by US giant KnowBe4

TikTok�s campaign

What next for TikTok as US ban moves step closer?

A laptop user with their hood up

Deepfakes a major concern for general election, say IT professionals

A woman using a mobile phone

Which? urges banks to address online security ‘loopholes’

Child online safety report

Tech giants agree to child safety principles around generative AI

Holyrood exterior

MSPs to receive cyber security training

Online child abuse

Children as young as three ‘coerced into sexual abuse acts online’

Big tech firms and financial data

Financial regulator to take closer look at tech firms and data sharing

Woman working on laptop

Pilot scheme to give AI regulation advice to businesses

Vehicles on the M4 smart motorway

Smart motorway safety systems frequently fail, investigation finds

National Cyber Security Centre launch

National Cyber Security Centre names Richard Horne as new chief executive

The lights on the front panel of a broadband internet router, London.

Virgin Media remains most complained about broadband and landline provider

A person using a laptop

£14,000 being lost to investment scams on average, says Barclays