Skip to main content

Cyber experts warn of rising threat from irresponsible use of commercial hacking tools over the next five years

New report from the NCSC assesses the threat to UK industry and society from the use of commercial cyber tools and services.
iStock.com/ArtemisDiana
  • Proliferation of commercial cyber tools will pose a growing threat to organisations and individuals globally, new report predicts
  • GCHQ’s National Cyber Security Centre warns of “unpredictable targeting or unintentional escalation” as demand for hackers-for-hire set to rise
  • New threat assessment, published on day one of CYBERUK 2023, provides insights into how lowering barrier for irresponsible cyber actors will transform threat landscape

THE marketplace for commercial hacking tools and services will almost certainly expand in the next five years leading to more victims of cyber attacks and a more unpredictable threat landscape, the UK’s cyber experts have warned.

Spyware, hackers for hire and access to other cyber capabilities are expected to be in growing demand globally, which will almost certainly lead to an increased threat to a wide range of industries, a new assessment, published today (Wednesday), has predicted.

The new report, released by the National Cyber Security Centre – a part of GCHQ – warns that the proliferation of cyber tools and services is already lowering the barrier to entry for state and non-state actors, transforming the threats that organisations and individuals face.

It highlights how over the past decade more than 80 countries have purchased cyber intrusion software, with some states almost certainly having irresponsibly used this to target journalists, human rights activists, political dissidents and opponents and foreign government officials.

The report warns that commercial capability development is likely to diversify to meet demand. And that a growing hackers-for-hire marketplace increases the risk of unpredictable targeting or unintentional escalation.

The assessment has been published on the first day of CYBERUK 2023, the UK’s flagship cyber security event, taking place in Belfast. A panel of experts will discuss the rise in commercially available spyware during a plenary session titled, ‘How do we want the cyber proliferation race to end?’.

The session is designed to meet with the conference’s overall theme of ‘securing an open and resilient digital future’.

Jonathon Ellison, NCSC Director of Resilience and Future Tech, said:

“Over the next five years, the proliferation of cyber tools and services will have a profound impact on the threat landscape, as more state and non-state actors obtain capabilities and intelligence not previously available to them.

“Our new assessment highlights that the threat will not only become greater but also less predictable as more hackers for hire are tasked with going after a wider range of targets and off-the-shelf products and exploits lower the barrier to entry for all.

“To maintain safety in cyberspace it is crucial these capabilities are managed with a responsible, proportionate and legally sound approach and working with international partners, the UK is determined to address this rising challenge.”

Over the last decade the NCSC has seen cyber intrusion grow into an industry offering increasing numbers of products and services to global customers. This includes off-the-shelf capability (Hacking-as-a-Service); bespoke hacking services (Hackers-for-Hire); and the sale of enabling capabilities such as zero-day exploits and tool frameworks.

According to the report the sophistication of some of these products and services is now at a stage to rival the equivalent capabilities of some state-linked Advanced Persistent Threat (APT) groups.

To tackle the threat from proliferation, the report suggests the commercial intrusion sector would benefit from a joined-up approach to international oversight over the next five years but acknowledges a lack of consensus could hinder efforts.

Last month, it was announced that the UK has committed to a number of initiatives to reaffirm our support for a free, open, peaceful and secure cyberspace, including efforts with 10 other countries to counter the proliferation and misuse of commercial spyware.

The new report says international consensus and norms on the development and sale of commercial cyber capabilities is likely to encourage commercial providers to vet and limit their customer bases.

The NCSC’s report also assesses that:

  • The irresponsible use of spyware against individuals is almost certainly happening at scale, with thousands of people targeted every year.
  • We should expect to see high-profile exposures of victims who have been targeted through unethical and illegal use of sophisticated and cost-effective commercial cyber tools or hackers for hire continue over the next five years.
  • Hackers for hire pose a potential corporate espionage threat to organisations or individuals across multiple sectors, and potentially significant financial rewards may incentivise state employees or contractors to become hackers for hire.

Read the full threat assessment of the commercial cyber intrusion sector