News: 1701757806

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK government denies China/Russia nuke plant hack claim

(2023/12/05)


The government of the United Kingdom has issued a strongly worded denial of a report that the Sellafield nuclear complex has been compromised by malware for years.

The [1]report , appearing in The Guardian , claimed that the controversial complex was hacked by "cyber groups closely linked to Russia and China," with the infection detected in 2015 but perhaps present before that year.

The report claimed that "sleeper malware" was embedded in unspecified systems, potentially compromising info on movement of nuclear materials and matters related to safety.

[2]

A UK government [3]statement insists "We have no records or evidence to suggest that Sellafield Ltd networks have been successfully attacked by state-actors in the way described by the Guardian ," adding "Our monitoring systems are robust and we have a high degree of confidence that no such malware exists on our system."

[4]

[5]

"All of our systems and servers have multiple layers of protection," reads one of the rebuttal's bullet points. Another adds "Critical networks that enable us to operate safely are isolated from our general IT network, meaning an attack on our IT system would not penetrate these."

The Guardian 's report mentioned infections in "IT systems" and malware "embedded in Sellafield's computer networks."

[6]

But it is not clear if those systems and networks are isolated, per the government response.

[7]Aspiration to deploy new UK nuclear reactor every year a 'wish', not a plan

[8]Infosec boffins meet to plan nuke plant hack response

[9]US nuke reactor lab hit by 'gay furry hackers' demanding cat-human mutants

[10]Hacktivists attack Japanese government over Fukushima wastewater release

The rebuttal's info about the isolation of some of Sellafield's IT estate is also of dubious value, given that the most infamous attack on a nuclear facility – the Stuxnet infection of Iranian enrichment plants – is thought to have been carried out using removable storage devices to get across air gaps.

Nor does the rebuttal address all the issues in the Guardian report, which claimed Sellafield "was last year placed into a form of 'special measures' for consistent failings on cyber security, according to sources at the Office for Nuclear Regulation (ONR) and the security services."

The ONR has posted its own [11]comment on the story, but it does not directly address the allegation of "special measures."

It does, however, state that the Office has "been clear that there are areas where improvements are required to achieve the high standards of safety and security we expect to see, but there is no suggestion that this is compromising public safety."

[12]

"In relation to cyber security, Sellafield Ltd is currently not meeting certain high standards that we require, which is why we have placed them under significantly enhanced attention," the doc adds, winding up with news that "Some specific matters are subject to an ongoing investigation process, so we are unable to comment further at this time." ®

Get our [13]Tech Resources



[1] https://www.theguardian.com/business/2023/dec/04/sellafield-nuclear-site-hacked-groups-russia-china

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZW8C2XqefnAmQfGrrsRF7AAAAA0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.gov.uk/government/news/response-to-a-news-report-on-cyber-security-at-sellafield

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZW8C2XqefnAmQfGrrsRF7AAAAA0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZW8C2XqefnAmQfGrrsRF7AAAAA0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZW8C2XqefnAmQfGrrsRF7AAAAA0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2023/08/01/aspiration_to_deploy_new_uk/

[8] https://www.theregister.com/2013/03/19/iaea_nuke_hack_defence_meeting/

[9] https://www.theregister.com/2023/11/22/nuclear_lab_hacked/

[10] https://www.theregister.com/2023/08/14/hactivitsts_claim_japanese_government_attack/

[11] https://news.onr.org.uk/2023/12/guardian-news-article/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZW8C2XqefnAmQfGrrsRF7AAAAA0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://whitepapers.theregister.com/



Sellafield / Windscale

Anonymous Coward

I can see another name change coming up.

That should sort the problem out, again.

Re: Sellafield / Windscale

Major N

Sellascale? Or Windfield?

Re: Sellafield / Windscale

abend0c4

They could possibly resolve another policy dilemma at the same time by renaming it "Rwanda".

Re: Sellafield / Windscale

Blazde

"A repeat of the Bibby Stockholm embarrassment is unlikely as the newly repurposed accommodation first built in the 1960s is routinely irradiated, which Home Office officials believe should have destroyed any Legionella bacteria present"

Re: Sellafield / Windscale

Throgmorton Horatio III

Wasn't the Winfield brand owned by Woolworths, now gone bust?

Re: Sellafield / Windscale

Whiskers

The "Lymeswold" brand seems to be free

Hmmm

Will Godfrey

While I don't necessarily take what the Guardian says as absolute truth, I definitely don't trust the government to get anywhere near the truth... on any matter!

Stuxnet

Mike 137

" is thought to have been carried out using removable storage devices to get across air gaps "

The Grauniad is discussing exfiltration of data at Sellafield, whereas stuxnet was aimed at local destruction of equipment. If a destruction engine jumps an airgap it can still operate, but if an airgapped system is infected it still can't exfiltrate data because of the airgap.

World Domination, One CPU Cycle At A Time

Forget about searching for alien signals or prime numbers. The real
distributed computing application is "Domination@World", a program to advocate
Linux and Apache to every website in the world that uses Windows and IIS.

The goal of the project is to probe every IP number to determine what kind of
platform each Net-connected machine is running. "That's a tall order... we
need lots of computers running our Domination@World clients to help probe
every nook and cranny of the Net," explained Mr. Zell Litt, the project head.

After the probing is complete, the second phase calls for the data to be
cross-referenced with the InterNIC whois database. "This way we'll have the
names, addresses, and phone numbers for every Windows-using system
administrator on the planet," Zell gloated. "That's when the fun begins."

The "fun" part involves LART (Linux Advocacy & Re-education Training), a plan
for extreme advocacy. As part of LART, each Linux User Group will receive a
list of the Windows-using weenies in their region. The LUG will then be able
to employ various advocacy techniques, ranging from a soft-sell approach
(sending the target a free Linux CD in the mail) all the way to "LARTcon 5"
(cracking into their system and forcibly installing Linux).