MoD contractor hacked by China failed to report breach for months

mod contractor hacked by china failed to report breach for months

Grant Shapps said the payroll records of about 270,000 current and former military personnel, including their home addresses, had been accessed. Photograph: James Veysey/Rex/Shutterstock

The IT company targeted in a Chinese hack that accessed the data of hundreds of thousands of Ministry of Defence staff failed to report the breach for months, the Guardian can reveal.

The UK defence secretary, Grant Shapps, told MPs on Tuesday that Shared Services Connected Ltd (SSCL) had been breached by a malign actor and “state involvement” could not be ruled out.

Shapps said the payroll records of about 270,000 current and former military personnel, including their home addresses, had been accessed. China has not been openly named by the government as the culprit.

The MoD was told of the hack in recent days but a number of sources said SSCL, an arm of the French tech company Sopra Steria, became aware of the breach in February.

Sopra Steria did not respond to requests for comment.

One Whitehall insider did not comment on the timeframe but said that concern about SSCL being “slow to respond” was one of the issues being examined in an official inquiry into the hack.

It can also be revealed that SSCL was awarded a contract worth more than £500,000 in April to monitor the MoD’s own cybersecurity – several weeks after it was hacked. Officials now believe this contract could be revoked.

The payroll data that was hacked reflects only a fraction of the work SSCL does for the government.

Sopra Steria and SSCL are understood to have other undisclosed government cybersecurity contracts, according to Whitehall sources. However, these are deemed so sensitive that they have never been publicly disclosed. The Cabinet Office declined to comment on the detail of contracts, citing security restrictions.

The cybersecurity arm of the UK’s intelligence services, the National Cyber Security Centre, has warned of a growing threat to the country’s businesses and critical national infrastructure from hostile states. Chinese and Russian state-sponsored actors were highlighted among attackers using a range of routes to try to hide malicious activity on networks containing sensitive information.

Whitehall worries over a lack of transparency by SSCL have raised concerns that there could be a wider compromise of its systems. Sopra Steria is one of a handful of strategic suppliers to the government, with work ranging from administering pensions to wider payments systems for government departments and agencies.

Shapps told parliament that the government had “not only ordered a full review of its [SSCL’s] work within the MoD, but gone further and requested from the Cabinet Office a full review of its work across government, and that is under way”. He added that specialists had been brought in to carry out a “forensic investigation” of how the breach happened.

Earlier this week, a spokesperson for the Cabinet Office said: “An independently audited, comprehensive security review of the contractor’s operations is under way and appropriate steps will be taken based on its findings.”

SSCL was part-owned by the government until October last year when it sold its 25% stake to Sopra Steria for £82m. SSCL was aware of being a “magnet” for cyber-attacks, sources said. A public warning about identity theft has been on the website of its parent company, Sopra Steria, for at least three years, according to an examination of the page’s history.

The hack was first internally detected in February, sources said, with concerns about potentially successful phishing attacks on the company dating back to December 2019.

SSCL and its parent company hold a total of £1.6bn in government contracts. These include a range of highly sensitive functions such as Home Office recruitment and online testing for officers, according to information from contracts gathered by the data company Tussell.

The Chinese embassy has said China was not responsible for the hack. A spokesperson said: “We urge the relevant parties in the UK to stop spreading false information, stop fabricating so-called China threat narratives, and stop their anti-China political farce.”

OTHER NEWS

17 minutes ago

NASCAR All-Star Race: Joey Logano runs away with $1 million win

17 minutes ago

Scout’s Analysis: The evolution of Canucks goaltender Arturs Silovs

17 minutes ago

‘Superman’s Sara Sampaio Signs With UTA

18 minutes ago

Liverpool's new head coach confirmed on three-year deal

18 minutes ago

Madame Web's Netflix Streaming Numbers Are Actually Pretty Good

18 minutes ago

Drake Bell says he and former Nickelodeon exec Dan Schneider have spoken

20 minutes ago

'We're winning it next season!'

20 minutes ago

15 Loose-Fitting Summer Staples That Are Super Flattering

21 minutes ago

Hunter Biden says he’s suing Fox News because they used drug addiction to ‘dehumanize’ him and take down dad

22 minutes ago

Liverpool icon names the three hardest players and scariest leaders he played alongside

22 minutes ago

Cohen says he stole from Trump’s company as key hush money trial witness quizzed

22 minutes ago

Burberry Introduces a Lighthearted Selection of Swimwear, T-Shirts and More for the Summer

22 minutes ago

Arne Slot to build around six Liverpool stars after huge Darwin Nunez and Mo Salah transfer decisions

22 minutes ago

Thunderstorms and downpours set to hit south-west England and Northern Ireland

22 minutes ago

Rishi Sunak issues ‘wholehearted and unequivocal’ apology to infected blood victims

22 minutes ago

Paul McCartney is now a billionaire, the first British musician to do it—and the former Beatle can thank Beyoncé

22 minutes ago

More B.C. property owners should soon be eligible to qualify for a heat pump rebate

23 minutes ago

Lamar High School evacuates students, staff due to 'strong smell of gas'

24 minutes ago

How much will it cost to stream every NFL game in 2024? Breaking down every subscription

25 minutes ago

Player ratings for Manchester City’s 2023-24 Premier League title winners

25 minutes ago

Ukraine’s destruction of warship signals shift in use of US weapons

25 minutes ago

Real Madrid midfielder to miss Champions League final, in huge blow for Spanish side

25 minutes ago

Who are Africa's Premier League winners and losers?

25 minutes ago

Viagra firm to begin offering 'budget' Ozempic prescriptions that cost $50 a week

25 minutes ago

Overjoyed boy, 11, is finally adopted after living in 25 foster homes - with his supportive Arkansas classmates cheering as they watch court verdict

25 minutes ago

Marjorie Taylor Greene posts video of herself heavy lifting in short purple gym ensemble as she claps back at Democrat who smeared her 'bleach blonde bad built butch body'

25 minutes ago

Frontier Airlines passenger forces entire flight to deboard after refusing to comply with exit row instructions

26 minutes ago

Additional Candy and Snacks Sold at Walmart and Target Recalled for Possible Salmonella

26 minutes ago

Supreme Court Justice Alito sold Bud Light stock, then bought Coors, during boycott

26 minutes ago

Ex-boyfriend eyed in murder of NYC woman, 29, butchered in front of her home

27 minutes ago

UK pharmacists demand powers to change whooping cough prescriptions

27 minutes ago

Tina Knowles talks teaming up with Beyoncé on hair care line

27 minutes ago

The Sandman season 2 has found its Delirium, Destiny, and The Prodigal – and they're all curiously great hires

27 minutes ago

‘Yellowstone' Starts Production on Final Season 5 Episodes

27 minutes ago

Scottie Scheffler's Louisville Court Appearance Postponed Until June 3

27 minutes ago

BMW imported 8,000 vehicles into US with parts from banned Chinese supplier, Senate report says

27 minutes ago

Is a $10,000 deposit into a high-yield savings account worth it?

28 minutes ago

'Clear Favourites For Me': Ambati Rayudu Makes His Pick Between RCB and RR Ahead of IPL 2024 Eliminator Clash

28 minutes ago

Government covered up infected blood scandal that left 3,000 dead

28 minutes ago

Chiefs WR Rashee Rice Attending OTAs

Kênh khám phá trải nghiệm của giới trẻ, thế giới du lịch