News: 1715166913

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK opens investigation of MoD payroll contractor after confirming attack

(2024/05/08)


UK Government has confirmed a cyberattack on the payroll system used by the Ministry of Defence (MoD) led to "malign" forces accessing data on current and a limited number of former armed forces personnel.

There is no evidence to suggest that the criminals who broke into the systems actually removed any data, but they did access personal information including names, financial data, and in some cases home addresses.

The affected systems have been pulled offline but there is no indication as to how long the attackers had access to the data.

[1]

Defence secretary Grant Shapps addressed the Commons on Tuesday afternoon, confirming ministers' suspicions that Shared Services Connected Ltd (SSCL) was the contractor running the system during the attack.

[2]

[3]

SSCL started out as a joint venture in 2013 between the Cabinet Office and Sopra Steria, the French IT provider, which as of last year owns SSCL entirely.

Sopra Steria has 43 active contracts across government and five with the MoD, according to data from public sector spending researcher Tussell. SSCL's contract to deliver armed forces pay, pensions, and military HR services is its most lucrative contract of the 43, and according to Tussell, its most lucrative with the MoD, with a value of more than £294 million ($366.8 million).

[4]

Per its website, SSCL's contract with the MoD sees it managing HR services for 230,000 military personnel and reservists, and two million veterans. Its other contracts with the likes of the police and wider areas of government see it managing the payments for hundreds of thousands more public servants.

Shapps said the estimated number of people affected by the latest incident is up to 272,000, though this number is likely to be reduced after it goes through refinements.

Founding CEO of the NCSC and current Oxford professor Ciaran Martin told BBC Radio 4's Today show that while the incident will bring cause for concern, the data involved could have been a great deal more sensitive.

[5]

"So [the government's safeguards for outsourced work] will vary depending on the sensitivity of the data set, and whilst this is on the basis of the information available at the moment, it looks serious, it's at the lower end of serious.

"It seems like a broad data set but not a very deep one. It's not what you would call a crown jewel data set."

Martin compared the incident to the [6]breach at the US's Office of Personnel Management in 2015, which was far more serious.

"We do worry what we call in the jargon in the cybersecurity industry about supply chain risk or the soft underbelly of professional services firms doing this type of thing, often more cheaply and arguably more efficiently than perhaps they're done in government. But it does require robust security procedures to be applied by the company and overseen by the sponsoring agency, in this case the MoD, and clearly that's something that's going to have to be looked at in this case."

Shapps withheld many details on national security grounds, including how the malign actors were able to access the data, however, Shapps said the "strongest action" will be taken if SSCL is found to have been negligent.

Responding to ministers' concern about the situation and state of cybersecurity at SSCL, Shapps said a full review had already been launched.

[7]UK elections are unaffected by China's cyber-interference, says deputy PM

[8]Electoral Commission had internet-facing server with unpatched vuln

[9]US charges Chinese nationals with cyber-spying on pretty much everyone for Beijing

[10]Five Eyes tell critical infra orgs: Take these actions now to protect against China's Volt Typhoon

"We have both ordered a full review of their work within MoD, but have gone further than that as well, and I've requested from the Cabinet Office a full review of their work across government as well as within MoD, which is underway."

As for the impact on individuals, all April salaries have been paid and there is currently no reason to suspect any future salary and pension payments will be disrupted, Shapps said.

However, some service personnel expense payments have experienced "a slight delay" but ensuring high-value payments are made is a current priority.

The MoD is now in the process of contacting all of those who are believed to be affected.

The UK isn't formally attributing the activity to any specific individual or group, but sources speaking to [11]Sky , which broke the news, suggested China was behind it.

Two years ago, shortly after Russia invaded Ukraine, an act that was preceded by cyberattacks on Viasat, the UK's National Cyber Security Agency (NCSC-UK) officially attributed the Viasat attacks to Russia during its annual CYBERUK conference. This year's event is being held next week, but there is nothing to suggest officials will point to any group any time soon.

Shapps said that formal attribution will take time to reach firm conclusions and he refused to confirm suggestions that China was behind the incident, although he did say state interference couldn't be ruled out.

Conservative MP and former chair of the Commons Defence Committee, Tobias Ellwood, [12]told BBC Radio 4's Today show: "Targeting the names of the payroll system and service personnel's bank details, this does point to China because it could be as part of a plan, a strategy to see who might be coerced."

Ellwood went on to reference the UK's threat in 2022 to prosecute former Royal Air Force (RAF) pilots under the National Secrets Act after it was revealed China was recruiting them to train Chinese pilots.

The news today is the latest in a long line of allegations against China focusing on its allegedly illegal acts in cyberspace.

Perhaps most notably, the [13]US charged seven individuals over their alleged involvement in APT31 a cyber-espionage group with assumed ties to the Chinese state. Otherwise known as Zirconium, it's just one of many suspected groups run by China to fulfill its various military objectives.

Volt Typhoon, another suspected band of Beijing-sponsored cybercriminals, has also attracted a great deal of [14]attention from authorities, which fear the group is [15]readying destructive cyberattacks after multiple compromises at critical infrastructure orgs.

Going back further, the UK previously pinned a 2021 attack on the Electoral Commission on China but deputy PM Oliver Dowden recently [16]dismissed concerns that the country had ever been successful in disrupting UK elections.

These are just a number of highlights from a sprawling list of allegations against China and its efforts in cyberspace, which date back many years.

It should be said that China has repeatedly denied any involvement in offensive cyber campaigns targeting the West.

A spokesperson for the Chinese embassy said: "The said accusation made by the UK side is nothing but a fabricated and malicious slander. It is extremely absurd and despicable. We strongly condemn it.

"China has all along been fighting cyberattacks according to law. We firmly oppose any groundless accusations against China out of political motives.

"We urge the UK side to stop spreading disinformation, and stop such self-staged political farces." ®

Get our [17]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zjuhn7Z@8a0EFENClF8kpAAAAEI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zjuhn7Z@8a0EFENClF8kpAAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zjuhn7Z@8a0EFENClF8kpAAAAEI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zjuhn7Z@8a0EFENClF8kpAAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightonrsa&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zjuhn7Z@8a0EFENClF8kpAAAAEI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2015/06/05/opm_data_breach/

[7] https://www.theregister.com/2024/03/26/uk_elections_are_unaffected_by/

[8] https://www.theregister.com/2023/08/11/electoral_commission_vulnerability/

[9] https://www.theregister.com/2024/03/25/china_apt31_charges/

[10] https://www.theregister.com/2024/03/20/five_eyes_volt_typhoon/

[11] https://news.sky.com/story/china-hacked-ministry-of-defence-sky-news-learns-13130757

[12] https://www.bbc.co.uk/sounds/play/m001yy5r

[13] https://www.theregister.com/2024/03/25/china_apt31_charges/

[14] https://www.theregister.com/2024/03/20/five_eyes_volt_typhoon/

[15] https://www.theregister.com/2024/02/07/us_chinas_volt_typhoon_attacks/

[16] https://www.theregister.com/2024/03/26/uk_elections_are_unaffected_by/

[17] https://whitepapers.theregister.com/



Another military privatisation success

Lurko

Just like air sea rescue, air tankers, recruitment, military accommodation.

Given that government believe EVERYTHING is better done by the private sector, maybe they should cut out the complication of piecemeal private provision, and just hire mercenaries for all the UK's defence needs. I'm sure minister's mates can put together credible bids to the VIP procurement lane.

Re: Another military privatisation success

Anonymous Coward

it seems you can't win, get it under the gov umbrella, and they fail, at huge cost. Outsource it to the lowest (?) bidder, and they fail it at huge cost. Mix the two together and they fail at huge cost.

Pascal Monett

Yeah but look at how much money their buddies make in the process !

Re: Another military privatisation success

elsergiovolador

No, government do not believe everything is done better by private sector.

They believe it is better if friendly big corporations do the job, make profit and then once someone from government retires from their position, they'll get a nice cushy job as a "thank you".

That's why the public sector is set up so that big corporations get the contracts and departments themselves cannot deliver anything, because by design they cannot hire people capable of delivering.

What

elsergiovolador

So far, SSCL has saved taxpayers more than £750 million in 10 years – providing more funds for frontline public services.

Go to their website. The "Green" mode takes the cake though.

LOL

Re: What

cyberdemon

https://sscl.com/go-green-button/

Reduces the site's carbon footprint by er, hiding HTML elements that you have already downloaded and cached locally..

Any CO2 savings from that one completely obliterated by the cigar smoke from whichever greenwashing consultant who invented it!

It'd be more hilarious if we weren't the ones paying for it ...

Re: What

Anonymous Coward

The Register site has the same option - it's in your user settings. It's getting more common and shouldn't be laughed at. The more people use that mode, the less networking kit is needed, the less cooling, the less electricity and the less data centres. It's not a small benefit if used widely. But to be fair when snapchat users send messages and photos of their feet (they have to attach a message to a pic) by the billions, then changes like this are less successful.

Much as I "dislike" the MoD...

xyz

This has the smell of a Cab Off hipster driven screw up, by trying to shoehorn shared services into compartmentalised areas. There will be more cases out there that'll show up.

Not very clever

Mike 137

" Per its website, SSCL's contract with the MoD sees it managing HR services for 230,000 military personnel and reservists, and two million veterans. "

How to guarantee you get picked as a target by malicious actors -- openly publicise that you process particularly sensitive information.

Re: Not very clever

elsergiovolador

Also look at this:

[1]Senior Database Administrator – Oracle e-Business Suite | SSCL

Salary: £48,000 – £58,000

That's a pay level only attractive to hostile state actors.

I wonder what is the mark up.

[1] https://g.co/kgs/NcHBbRg

Re: Not very clever

Anonymous Coward

But the system in question was a MOD system hosted in a MOD datacentre, made by the MOD? SSCL currently run it but their name is only in the mix because they're the last people carrying the hot potato.

cyberdemon

Also how to guarantee that you are vulnerable to such actors: Run the operation for profit and spend as little as possible on the IT service that you are contracted to deliver

I'm Shocked

EvilDrSmith

Shocked, I tell you.

Not that MoD payroll records were being handled by a private company.

Nor that the records were hacked.

Nor even that the Chinese government was probably responsible.

No, I'm shocked that, after near enough 35 years of continuous cut backs, with an army smaller than any time since the Revolutionary and Napoleonic wars, the RAF smaller than any time in its existence, and the RN suffering a shortage of personnel, the UK still has 230,000 service personnel.

Re: I'm Shocked

Lurko

230k service personnel? No, active, trained military personnel is about 145k, with a further 37k volunteer reservists:

https://www.gov.uk/government/statistics/quarterly-service-personnel-statistics-2024/quarterly-service-personnel-statistics-1-january-2024

I'd guess the difference is the bloated MoD itself with 60k civil servants who are probably on the SSCL payroll.

Re: I'm Shocked

Anonymous Coward

SSCL is only 2500 people? And of 43 contracts, only 5 are MOD? Seems unlikely that 60,000 civil servants are on the SSCL payroll lol.

"nothing but a fabricated and malicious slander"

Pascal Monett

That coming from a country that has been repeatedly fingered for stealing industrial secrets and has an army of hackers willing and able to attack just about anything they turn their attention to.

This was just waiting to happen...

Anonymous Coward

If you know anything about this Orable HR system then there are several things of note:

1) Operations are the same people who have been running it for the last 20 years. They may have been TUPEd to all sorts of companies, but it's the same people, or their children, or their children's children...

2) The people running the system have a single view on security processes, its manual and its been that way for 20 years, so must be good! They will not accept that process is not the same as security.

3) There is only one security classification to cover all the data. But then strictly speaking there are only 3 classifications for the whole MOD... This system is not in the top classification.

4) There is only one HR system to cover the whole of the MOD... it doesn't matter who you are, where you are, what you do or how you do it, Think about that one carefully.

So is this the crown Jewels of MOD data, hidden in plain sight and jobsworthiness or just a signpost to it?

I don't actually blame SSCL for the shitshow... They were just the last ones in the hotseat, they did try to tell the MOD... its the people rearranging the chairs that are really at fault here, because they dont understand what they have and its all they know how to do.

P.s. Read point 4 again and again until I sinks in...

Re: This was just waiting to happen...

elsergiovolador

I don't actually blame SSCL for the shitshow... They were just the last ones in the hotseat, they did try to tell the MOD...

Such nonsense. If you see a hot mess you can't sort, you simply don't take the contract! But I guess the smell of the money was overpowering.

Phil O'Sophical

the "strongest action" will be taken if SSCL is found to have been negligent.

Oooh, smacked on both wrists...

Unfair

Anonymous Coward

I think it's a little unfair to judge just yet. Not only has it not been confirmed that any data has been accessed, SSCL inherited these systems from the MOD themselves and have been working to modernise them since. Given that it was a bodge by the lowest bidder in the first place the blame should be shared.

brain, v: [as in "to brain"]
To rebuke bluntly, but not pointedly; to dispel a source
of error in an opponent.
-- Ambrose Bierce, "The Devil's Dictionary"