{"id":3486,"date":"2024-05-08T18:15:13","date_gmt":"2024-05-08T23:15:13","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/breach-of-uk-military-personnel-data-a-reminder-of-third-party-risk-in-defense-sector"},"modified":"2024-05-08T18:15:13","modified_gmt":"2024-05-08T23:15:13","slug":"uk-military-data-breach-a-reminder-of-third-party-risk-in-defense-sector","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/08\/uk-military-data-breach-a-reminder-of-third-party-risk-in-defense-sector\/","title":{"rendered":"UK Military Data Breach a Reminder of Third-Party Risk in Defense Sector"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blte815ff52d94d65ba\/663c083ad760b329fcda3fe4\/ukmod_Bumble_Dee_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/uk-military-data-breach-a-reminder-of-third-party-risk-in-defense-sector.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/uk-military-data-breach-a-reminder-of-third-party-risk-in-defense-sector.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The disclosure of a breach exposing data on over 225,000 UK military personnel underscores the global security risks associated with external contractors to defense entities.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The exposure, which came to light just this week, stemmed from a threat actor accessing the names, bank account details, and other information for current, former, and reserve members of the British Army, Naval Service, and Royal Air Force from a company handling payroll services for the UK Ministry of Defence (MoD).<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"External Contractor at Fault\">External Contractor at Fault<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.bbc.com\/news\/uk-68967805\" rel=\"noopener\">BBC<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and other UK media outlets identified the external contractor as Shared Services Connected Ltd and say the breached payroll system contains information on military personnel going back several years. In <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.youtube.com\/watch?v=RCiHYbGTZ8A\" rel=\"noopener\">comments to Members of Parliament<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, the UK&#8217;s Secretary of State for Defence Grant Shapps identified the attack as the work of a &#8220;malign actor&#8221; that was very likely nation-state backed. While some senior government officials pointed to China as the most likely suspect, Shapps himself stopped short of pinning the attack on anyone by name.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Instead, he blamed the third-party contractor for not doing enough to protect its systems against attack. Malign actors gained access to a part of the armed forces payment network via an external system that is completely separate from the MoD core network and not connected to the main military HR system, Shapps said. &#8220;It is operated by a contractor, and there is evidence of potential failings by them which may have made it easier for the malign actor to gain entry,&#8221; he emphasized. Shapps added that the UK government has initiated a special security review of the contractor and their operations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The latest incident marks the second time in less than one year that an external contractor was responsible for exposing data related to the UK military. Last August, the LockBit ransomware gang managed to steal some 10GB of data from Zaun, a company that provides mesh-fencing services for UK military facilities. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.zaun.co.uk\/zaun-data-breach-update\/\" rel=\"noopener\">Zaun described the breach<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> as the result of a rogue Windows 7 system on its network. The company claimed LockBit actors accessed a system that contained &#8220;historic emails, orders, drawings, and project files&#8221; but no classified information or military secrets.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Supply Chain Risks in the Defense Sector\">Supply Chain Risks in the Defense Sector<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Breaches like these highlight the vulnerable underbelly that external contractors present to attackers who want to target military and defense data and systems. In June 2023, Adlumin reported on a threat actor dropping a novel backdoor called <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/us-aerospace-contractor-hacked-powerdrop-backdoor\" rel=\"noopener\">PowerDrop<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on systems belonging to at least one US defense contractor. And last month, the US government released details on a multiyear effort by <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/iran-dupes-military-contractors-govt-agencies-cybercampaign\" rel=\"noopener\">Iranian cyberspies to steal US military secrets<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> by targeting employees at defense contracting firms who have high-level security clearances.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Eric Noonan, CEO of CyberSheath, says third-party contractors that work with the military are an attractive target because these organizations often overlook vital security measures. &#8220;In the US, there has been over a decade-long fight by the DoD to force minimum security standards on third-party contractors through its [Cybersecurity Maturity Model Certification] program,&#8221; he says. &#8220;But until contractors are faced with losing out on contracts due to poor security, I don&#8217;t expect much will change.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Noonan points to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/cybersheath.com\/company\/news\/study-shows-defense-contractors-havent-improved-cybersecurity-despite-increasing-threats\/\" rel=\"noopener\">research<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> CyberSheath conducted last year that showed a high percentage of the Defense Industrial Base not having basic cybersecurity controls in place and putting the entire Pentagon supply chain at risk. For instance, 81% of the contractors in CyberSheath&#8217;s study did not have a formal vulnerability management system; 75% did not implement multifactor authentication; and 75% did not have a back-up plan.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A May 2022 study by <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/blackkite.com\/new-black-kite-research-reveals-top-100-us-defense-contractors-at-risk-for-ransomware-attack\/\" rel=\"noopener\">Black Kite<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> of the top 100 US defense contractors uncovered similar issues: 72%, for instance. had experienced at least one leaked credential in the preceding 90 days; 32% were vulnerable to ransomware attacks; and 17% were using out-of-date \u2014 and therefore unsupported \u2014 systems.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Time for Mandatory Minimum Standards?\">Time for Mandatory Minimum Standards?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Industries like defense and other critical infrastructure sectors must be regulated to implement mandatory minimum cybersecurity standards,&#8221; Noonan says. &#8220;The private companies operating in these sectors haven&#8217;t made the required investments in cybersecurity, and they won&#8217;t, unless it&#8217;s forced through regulation like CMMC.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Stephen Gates, principal security SME at Horizon3.ai, says third-party cyber risk has generally never been higher. &#8220;It&#8217;s one of the reasons why organizations are now nearly mandating their third-party suppliers perform continuous cyber-risk assessments of their own infrastructures to ensure they are not transferring their risk to others \u2014 especially their buyers.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The challenge for organizations is how to execute continuous cyber assessments. Checkbox self-assessment exercises and external penetration testing that test merely a small portion of the network have been largely unsuccessful, Gates says. &#8220;Therefore, initiatives are surfacing, which are all calling for increases in continuously assessing cyber risk,&#8221; he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As examples, Gates points to an initiative the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/media.defense.gov\/2023\/Nov\/21\/2003345095\/-1\/-1\/0\/DEPARTMENT%20OF%20THE%20NAVY%20CYBER%20STRATEGY.PDF\" rel=\"noopener\">US Navy<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> launched in November 2023 to provide realistic cyber assessments via automated and manual testing of security protections, and another from the US DoD called the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cybercom.mil\/Media\/News\/Article\/3689870\/jfhq-dodin-to-officially-launch-its-new-cyber-operational-readiness-assessment\/\" rel=\"noopener\">Cyber Operational Readiness Assessment<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (CORA) program.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/breach-of-uk-military-personnel-data-a-reminder-of-third-party-risk-in-defense-sector\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The disclosure of a breach exposing data on over 225,000<\/p>\n","protected":false},"author":12,"featured_media":3487,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3486","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/uk-military-data-breach-a-reminder-of-third-party-risk-in-defense-sector.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/uk-military-data-breach-a-reminder-of-third-party-risk-in-defense-sector.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/uk-military-data-breach-a-reminder-of-third-party-risk-in-defense-sector.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/uk-military-data-breach-a-reminder-of-third-party-risk-in-defense-sector.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/uk-military-data-breach-a-reminder-of-third-party-risk-in-defense-sector.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/uk-military-data-breach-a-reminder-of-third-party-risk-in-defense-sector.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/uk-military-data-breach-a-reminder-of-third-party-risk-in-defense-sector.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/uk-military-data-breach-a-reminder-of-third-party-risk-in-defense-sector.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/uk-military-data-breach-a-reminder-of-third-party-risk-in-defense-sector.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/uk-military-data-breach-a-reminder-of-third-party-risk-in-defense-sector.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/uk-military-data-breach-a-reminder-of-third-party-risk-in-defense-sector.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3486","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3486"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3486\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3487"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3486"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3486"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3486"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}