British NCSC Chief Describes Russian Attacks As ‘Devastating'

Criminal groups based in Russia have been blamed by Britain's Cyber Security chief for the most "devastating" ransomware attacks in the country and she said malicious actors are trying to steal coronavirus vaccination plans and data on new variants. 

Russia remains the UK’s most acute cyber threat and the source of most ransomware attacks, says head of National Cyber Security Centre Lindy Cameron.

Cyber attacks which see hackers get inside computer networks and lock the owners out until they pay a ransom present "the most immediate danger" to UK businesses in cyber space, Cameron has warned. Many ransomware gangs operate from Ukraine and Russia and the Russian ransomware gangs are often said by western government officials to operate with the Kremlin's tacit approval, but are not directly controlled by the government.

Ms Cameron said her agency, an arm of GCHQ, and the National Crime Agency had assessed that cyber criminals based in Russia, and its neighbours, were responsible for the most of the "devastating" ransomware attacks against the UK. Her remarks represent one of the firmest attempts yet by a British intelligence chief to pin the epidemic of internet extortion on Russia, which is accused of sheltering criminal hackers who seek to extract millions by seizing corporate data.

She said these types of attack posed a threat to everyone from major companies to local councils and schools.

Speaking at the Chatham House Cyber 2021 conference, Cameron said that few organisations were prepared for the threat or tested their cyber defences.  Cameron said ransomware “presents the most immediate danger” of all cyber threats faced by the UK, in her Chatham House speech. Increasingly in recent cases, criminal gangs have also threatened to release some of the data they have access to publicly.

Ms. Cameron said that the challenge the ransomware criminal gangs posed in terms of law enforcement is "acute" as "the criminals responsible often operate beyond our borders, are increasingly successful in their endeavours, and pose a global challenge we must fight together to ensure no place becomes a safe haven".

Ransomware has risen up the agenda in recent months, particularly the US where an attack on Colonial Pipeline caused fuel shortages on the US east coast. There had been some signs that Russian-linked activity dipped over the summer but cyber security experts believe much of that may be to do with the hackers taking their summer holiday rather than any fundamental shift away from what has been a highly-lucrative business model. Cameron also said that ransomware would continue to be attractive while organisations remained vulnerable and were willing to pay. She said the government had been clear that paying ransoms simply emboldened criminal groups. 

As well as improving its defences, she also said the UK would aim to deliver a "sustained, proactive" campaign to disrupt those harming the UK, including ransomware gangs. 

This would include a range of techniques including the newly established National Cyber Force which can carry out offensive hacking operations. "Malicious actors continue to try and access Covid related information, whether that is data on new variants or vaccine procurement plans... Some groups may also seek to use this information to undermine public trust in government responses to the pandemic. And criminals are now regularly using Covid-themed attacks as a way of scamming the public." she said.

Cameron made reference to the recent revelations about the Pegasus spyware sold by the company NSO Group, saying that the NCSC has raised a "red flag" about the growing commercial market for sophisticated products which can be used to hack into people's phones and carry out surveillance. 

She warned of the dangers of "authoritarian states like China" having the ability to influence the standards of new technology in a way that undermines the UK's security. She said the UK needed to be "clear eyed" and protect itself "against Chinese practices that have an adverse effect on our own prosperity and security".

Sky:         Silicon:       Independent:        Guardian:       Verdict:         HSToday:   

TechTimes:      USNews:       BBC:      Image: NCSC

You Might Also Read:

Data Privacy Is Key To The Technology Battle With China:

 

« US Proposes Legislation To Control AI
How AI Will Affect The Future Of Work »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

BackupVault

BackupVault

BackupVault is a leading provider of completely automatic, fully encrypted online, cloud backup.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

360Logica

360Logica

360Logica is a software testing company offering numerous kinds of testing services to improve the quality and performance of your software and IT systems.

SRC Secure Solutions

SRC Secure Solutions

SRC Secure Solutions is a reseller of multiplatform software solutions with which organisations can secure their data for storage and data transmission.

Wheel Systems

Wheel Systems

Wheel Systems specialize in privileged access management, user authentication and authorization and SSL/TLS encrypted traffic inspection.

CASES.lu

CASES.lu

CASES.lu is a government-driven initiative offering awareness-raising, a web resource and other tools to assist SMEs concerning information security.

Nakivo

Nakivo

Nakivo provides fast, reliable, and affordable VM backup, replication, and disaster recovery solutions for VMware, Nutanix AHV, AWS EC2.

Industrial Internet Consortium (IIC)

Industrial Internet Consortium (IIC)

The Industrial Internet Consortium is the world's leading organization transforming business and society by accelerating the Industrial Internet of Things (IIoT).

Pinpoint Search Group

Pinpoint Search Group

Pinpoint Search Group's recruiters specialize in Information Management, Cyber Security, Cloud and Robotic Process Automation (RPA).

Cyber Range Solutions (CRS)

Cyber Range Solutions (CRS)

CRS provides cyber security training and improve security team performance by providing a hyper realistic, virtual training environment.