NCSC Annual Review 2024
Pages
Page 9 of 16
Chapter 01: Countering the cyber threat
We face real and enduring threats from hostile states and cyber criminals targeting our critical national infrastructure.
The NCSC continues to analyse and respond to the cyber threats facing the UK. From hostile states and commercial cyber proliferation, to ransomware and the challenges of AI-enabled intrusion, the NCSC leverages its technical expertise and unique position in government to counter conventional and unprecedented cyber threats, working alongside law enforcement and international partners.
Ransomware attacks continue to pose the most immediate and disruptive threat to our critical national infrastructure (CNI), with some state-linked cyber groups now targeting the industrial control systems that infrastructure relies on.
The NCSC’s Incident Management team worked with the Information Commissioner's Office and the legal and insurance sectors to produce joint guidance on ‘ransom discipline’, which aims to reduce the number of ransomware payments being made by victims of cyber crime and has since been internationalised through the Counter Ransomware Initiative (CRI), with 40 members and 8 insurance bodies globally endorsing it. It’s just one example of how we’re partnering with government and private organisations to improve the UK’s cyber resilience.
China
China continues to be a highly sophisticated and capable threat actor, targeting a wide range of sectors and institutions across the globe, including in the UK.
In February 2024, the NCSC and international partners co-signed an advisory on observed compromises of US CNI by ‘Volt Typhoon’, a China state-sponsored threat actor. The targeting of energy, transportation and water sectors could be laying the groundwork for future disruptive and destructive cyber attacks, and is a clear warning about China’s intent to threaten essential networks.
In March 2024, the UK government and international allies called out China state-affiliated threat actors for targeting UK institutions that underpin our democracy. The NCSC assessed that:
-
threat actor APT31 was almost certainly responsible for conducting online reconnaissance activity against UK parliamentarians’ emails in 2021
-
a separate threat actor was almost certainly responsible for the compromise of computer systems at the UK Electoral Commission between 2021 and 2022
The NCSC continues to work across government, and in partnership with international allies, industry and academic colleagues, to deter, degrade and detect the cyber threat posed by China.
Russia
Russia continues to act as a capable, motivated and irresponsible threat actor in cyberspace. Russian threat actors almost certainly intensified their cyber operations against Ukraine and its allies in support of their military campaign and wider geopolitical objectives.
Through its activities in Ukraine, Russia is inspiring non-state threat actors to carry out cyber attacks against western CNI. These threat actors are not subject to formal or overt state control, which makes their activities less predictable. However, this does not lessen the Russian state’s responsibility for these ideologically-driven attacks. The NCSC continues to publicly expose Russian cyber activity, which makes it a more challenging environment for them to operate in.
Iran
Iran-based threat actors remain aggressive in cyberspace and continue to achieve their objectives through less sophisticated cyber techniques (including prolific use of spear-phishing), but also targeting industrial control systems. In August 2024, US government agencies issued an advisory highlighting ransomware attacks by Iran-based threat actors on organisations in the education, finance, healthcare, and defence sectors in the US and other countries.
Although much of Iran’s cyber activity has likely been focused on the Israel/Hamas conflict throughout 2024, it is developing its cyber capabilities and is willing to target the UK to fulfil its disruptive and destructive objectives. The NCSC continues to work closely with government, industry and international partners to understand and mitigate the cyber threat from Iran.
Democratic People's Republic of Korea (DPRK)
The DPRK (also known as North Korea) continues to prioritise raising revenue to circumvent sanctions and intelligence collection in its cyber activity. DPRK threat actors indiscriminately target cryptocurrency companies and users globally, and attempt to steal data from defence industries, governments, and academia to improve their internal security and military capabilities. In July 2024, the NCSC co-signed an advisory on a group sponsored with the DPRK’s overseas intelligence agency that has targeted defence, aerospace and nuclear entities globally.
UK firms are almost certainly being targeted by IT workers from the DPRK – disguised as freelance third-country IT staff – to generate revenue for the DPRK regime. The DPRK remains a prolific and capable threat actor, and the NCSC continues to work with partners to understand and address the risk to the UK.
Defending democracy
The UK general election in July 2024 presented an attractive target for a range of threat actors, due (in part) to the UK’s membership of NATO, the G7 and our continued support for Ukraine. More generally, threats against UK officials and election candidates – particularly their personal devices and accounts – are seen as a softer target by adversaries, and were highlighted in public attributions that included APT31 and Russian FSB threat actors ‘Star Blizzard’.
Ransomware
Ransomware remains one of the most pervasive cyber threats to UK organisations.
Ransomware is a type of malware which prevents organisations from accessing their systems or data, usually by encrypting files. More recently, threat actors are choosing not to encrypt systems and simply threatening to publish sensitive data, using the potential reputational and financial damage to leverage a ransom payment.
The nature of modern supply chains means that a ransomware attack on one organisation can have a significant impact on many others. In June 2024, the financially motivated ransomware attack on Synnovis, a pathology laboratory supplier to the NHS, had significant impact on citizens, delaying elective procedures and outpatient appointments.
The NCSC provides guidance to help reduce the risk of ransomware attacks (and how to recover if you’ve been infected), whilst our Cyber Incident Response scheme helps victims to identify trusted providers of commercial incident response services should the worst happen.
In addition:
-
the NCSC’s Cyber Essentials scheme has been proven to reduce an organisation's vulnerability to cyber attacks (including ransomware)
-
the NCSC’s Cyber Advisor scheme can provide cyber security consultancy tailored to small and medium-sized organisations
Disrupting global ransomware operators
The NCSC and the National Crime Agency (NCA) assessed that the cyber crime group LockBit was the leading global ransomware threat since the demise of the Conti ransomware strain in mid 2022. In 2024, the NCA, alongside international law enforcement partners, led activity against the LockBit group, including taking control of their infrastructure and naming the primary operator. The NCSC works with government, law enforcement and international partners to disrupt and impose costs on high harm cyber criminals with targeted sanctions. In October, the UK sanctioned 16 members of the Russian cyber crime gang 'Evil Corp' alongside coordinated action taken by the US and Australia. The NCSC is also an active participant in the multilateral body, the Counter Ransomware Initiative.
Artificial intelligence
Many nation-state threat actors and cyber criminals are already using artificial intelligence (AI) to increase the volume and heighten the impact of cyber attacks. In January 2024, the NCSC released an assessment of the near-term impact of AI on the cyber threat, highlighting how it can be used for reconnaissance, social engineering and analysis of exfiltrated data.
Generative AI (that is, AI tools that can produce different types of content, including text, images and video) will make it harder for defenders to identify social engineering attacks without the development of new mitigations. At the same time, the shrinking time between the exploitation of certain unpatched software vulnerabilities and the release of security updates to patch systems, is already challenging network managers. AI is expected to further narrow this interval, as reconnaissance to identify vulnerable devices becomes more precise.
Highly capable state actors, in terms of both AI and cyber operations, will most likely be able to exploit the potential of AI to create more advanced cyber attacks. The NCSC continues to work closely with government, international, industry and academic partners to understand the impact on cyber threat to inform the UK’s response.
Cyber proliferation
Over the next five years, expected increased demand for commercial cyber tools and services, coupled with a permissive operating environment in less-regulated regimes, will almost certainly result in an expansion of the global commercial cyber intrusion sector. The real-world effect of this will be an expanding range and number of victims to manage, with attacks coming from less-predictable types of threat actor. Many of these will have access to commodity cyber tools that require low skill to weaponise, and will be operating from countries with scant regard for international norms and regulations.
The Pall Mall Process declaration
In February 2024, the UK and France hosted the first, dedicated conference on tackling the threat from commercial cyber proliferation. It brought together a wide range of organisations and views – states, tech companies, civil society representatives, academia, cyber security, investors, researchers and private industry – to establish guiding principles for the legitimate development, facilitation, purchase, and use of commercially available cyber intrusion capabilities.
The result was the signing of the Pall Mall Process declaration; a new international initiative across governments, industry and civil society to address the proliferation and irresponsible use of commercial cyber intrusion tools and services, providing consensus on what constitutes responsible behaviour in cyberspace. The NCSC supported the Foreign, Commonwealth and Development Office (FCDO) led initiative through robust assessment of the threat, technical expertise, engaging closely with industry, civil society groups and think tanks.
Incident management
The NCSC’s Incident Management (IM) team responds to serious cyber incidents impacting UK organisations. The IM team is responsible for triaging incidents, providing support to impacted organisations, and coordinating the NCSC and cross-government response.
This year the IM team received 1,957 reports of cyber attacks covering a range of sectors. These were triaged into 430 incidents requiring support from the IM team, an increase on the 371 last year. Of these incidents, 89 were nationally significant, 12 of which were at the top end of the scale and more severe in nature (which is a three-fold increase on last year).
Table shows yearly breakdown of tips, incidents handled, highly significant and significant, and data exfiltration.
| Sep 2021 - Aug 2022 | Sept 2022 - Aug 2023 | Sep 2023 - Aug 2024 | |
|---|---|---|---|
| Total tips | 1,226 | 2,005* | 1,957 |
| Incidents handled | 355 | 371 | 430 |
| Highly significant and significant incidents | 62 | 62 | 89 |
| Data exfiltration | 276 | 327 | 347 |
Highly significant incident: A cyber attack which has a serious impact on central government, UK essential services, a large proportion of the UK population, or the UK economy. Significant incidents: A cyber attack which has a serious impact on a large organisation or on wider/local government, or which poses a considerable risk to central government or UK essential services. *Increase in reports attributed to change in data collection and cannot be compared directly to previous years. | |||
The IM team issued 542 bespoke notifications informing organisations to a cyber incident impacting them and providing advice and guidance on how to mitigate it. This was more than double the 258 bespoke notifications issued last year. Almost half of the bespoke notifications sent this year related to pre-ransomware activity, enabling organisations to detect and remove precursor malware before ransomware was deployed.
The top sectors reporting ransomware activity into the NCSC this year were academia, manufacturing, IT, legal, charities and construction. We received 317 reports of ransomware activity, either directly from impacted organisations, or from our partners (an increase on 297 last year). These were triaged into 20 NCSC-managed incidents, of which 13 were nationally significant. These included high-profile incidents impacting the British Library and NHS trusts.
Commercial and sensitive data continues to be attractive to threat actors, hoping to extort victims or use the data for other criminal or espionage activities. This year, the NCSC was made aware of 347 reports of activity that involved the exfiltration/extortion of data.
Vulnerabilities continue to pose a cyber security risk to organisations. This includes known vulnerabilities, for which a mitigation exists, and newly discovered/zero-day vulnerabilities. Over the last year, the IM team issued approximately 12,000 alerts about vulnerable services through its Early Warning service (a free, automated NCSC threat notification service). Exploitation of zero-days CVE-2023-20198 (Cisco IOS XE) and CVE-2024-3400 (Palo Alto Networks PAN OS) also resulted in six nationally significant incidents for the IM team to manage.