NCSC Annual Review 2021
Pages
Page 8 of 44
The Threat
The cyber threat to the UK and its allies continued to grow and evolve this year: from indiscriminate phishing scams against mass victims, to ransomware attacks against public and private organisations, to targeted hostile acts against critical national infrastructure and government.
While the threats came from a range of actors using an array of methods, they had one thing in common: they led to real-world impact. Life savings were stolen, critical and sensitive data was compromised, healthcare and public services were disrupted, and food and energy supply was affected.
In the past 12 months the NCSC continued, in partnership with law enforcement, to monitor, counter and mitigate the threat, whether committed by sophisticated state actors, organised criminal groups or low-level offenders. This section describes the key themes, who was behind them and how the NCSC responded.
COVID-19 continued to shape the cyber security landscape. Cyber criminals continued to exploit the pandemic as an opportunity, while hostile states shifted their cyber operations to steal vaccine and medical research, and to undermine other nations already hampered by the crisis. The pandemic has also brought about an acceleration in digitisation, with businesses and local government increasingly moving services online and essential services relying ever more on cloud IT provision. This has broadened the surface area for attacks and has often made cyber security more challenging for organisations.
In response the NCSC built on the experiences of last year in protecting sectors responding to the pandemic, including the NHS (across all four nations), medical research, vaccine manufacturers and distributors, encouraging them to take up the services available to respond to threats to their security.
The compromise of the software company SolarWinds and the exploitation of Microsoft Exchange Servers highlighted the threat from supply chain attacks. These sophisticated attacks, which saw actors target less-secure elements - such as managed service providers or commercial software platforms - in the supply chain of economic, government and national security institutions were two of the most serious cyber intrusions ever observed by the NCSC.
In March 2021, Microsoft announced that four zero-day vulnerabilities in Microsoft Exchange Servers were being actively exploited with at least 30,000 organisations reportedly compromised in the US alone, affecting many more worldwide.
In July the NCSC assessed this attack was highly likely to have been initiated and exploited by a Chinese State-backed threat actor, with the objective of enabling large-scale espionage, including the acquisition of personal data and intellectual property.
The SolarWinds attack enabled the onward compromises of multiple US Government departments, and the British cloud and email security firm Mimecast, among other victims. In April the NCSC assessed that Russia’s Foreign Intelligence Service (SVR) was highly likely to have been responsible for the attack.
Ransomware became the most significant cyber threat facing the UK this year. Due to the likely impact of a successful attack on essential services or critical national infrastructure it was assessed as potentially harmful as state-sponsored espionage.
In 2020 the NCSC observed the evolving model of criminals exfiltrating data before encrypting victim networks; data which they then threatened to leak unless the ransom was paid (known as double extortion).
Ransomware gained increased public attention following attacks on the Colonial Pipeline Co. in the US, which supplied fuel to the East Coast, and against the Health Service Executive in Ireland. In the UK there was an increase in the scale and severity of ransomware attacks, targeting businesses, charities, the legal profession and public services in the education, local government and health sectors.
Among other ransomware incidents investigated was a major attack on the American software firm Kaseya. In July, the NCSC helped to identify and support British victims after the Florida-based company was infiltrated by a hacking group, which seized troves of data and demanded $70m (£51.5m) in cryptocurrency for its return.
The NCSC welcomed international efforts in tackling ransomware when it was discussed at the G7 meeting of world leaders in Cornwall, underlining the need for co-ordinated multilateral attention.
Global threat actors
The NCSC continued its work with global partners to detect and disrupt shared threats, the most consistent of these emanating from Russia and China. In addition to the direct cyber security threats posed by the Russian state, it became clear that many of the organised crime gangs launching ransomware attacks against Western targets were based in Russia.
China remained a highly sophisticated actor in cyberspace with increasing ambition to project its influence beyond its borders and a proven interest in the UK’s commercial secrets. How China evolves in the next decade will probably be the single biggest driver of the UK’s future cyber security.
While less sophisticated than Russia and China, Iran and North Korea continued to use digital intrusions to achieve their objectives, including through theft and sabotage.
We will work with the FCDO to put cyber power at the heart of the UK’s foreign policy agenda, strengthening our collective security, ensuring our international commercial competitive advantage and shaping the debate on the future of cyberspace and the internet.
We will need to reinforce our core alliances and lead a compelling campaign aimed at middle-ground countries to build stronger coalitions for deterrence and counter the spread of digital authoritarianism. This will involve better connecting our overseas influence to our domestic strengths, leveraging our operational and strategic communications expertise, thought leadership, trading relationships and industrial partnerships as a force for good.
Lindy Cameron, NCSC’s CEO