Concern and controversy have arisen with recent news that the UK Armed Forces payment network has been involved in a cybersecurity incident. In his address to the House of Commons, UK Secretary of State for Defence, Grant Shapps, confirmed the incident. According to the Ministry of Defence (MoD), the breach resulted in the leakage of personal data belonging to about 272,000 UK Armed Forces personnel.
Shapps indicated that an external agency operates the compromised network but hesitated to attribute the attack to China. Nevertheless, subsequent developments forced him to reluctantly point fingers at the Asian powerhouse, following a denial from China in an official statement.
No data is thought to have been extracted from the system. However, the MoD has reached out to all affected personnel, and some retired veterans have received letters about the incident as a preventative measure. The Ministry is currently investigating any potential contract non-compliance. An 8-step plan has been rolled out by the MoD to strengthen the network’s security and safeguard personnel, including taking the system offline, establishing a support helpline, implementing data protection monitoring, and auditing all MoD personnel data security.
In his address, Shapps maintained that the compromised network was distinct from MoD systems. Despite this assurance, the incident has brought the ongoing cyber security threats against the UK into sharp focus. While making an apology to affected parties, Shapps vowed to prevent such a breach from happening again.
However, in the wake of this event, Opposition Labour Party member and Shadow Defence Minister John Healey publicly criticized the government’s handling of the affair, claiming that the MoD contractor responsible for the breach was Shared Services Connect Ltd. When questioned about the contractor’s identity, Shapps confirmed Healey’s claim.
In a bid to defend their position, the Chinese Embassy in London released a countering statement, accusing the UK of creating a political farce, and calling for an end to any unfounded accusations.
This issue crops up at a time when China’s involvement within the UK has become a hot button topic. Accusations of political meddling abound, following recent espionage charges against a parliamentary researcher by the Crown Prosecution Service. Moreover, cyber campaigns aimed at democratic institutions have been attributed to China-affiliated groups. As recently as August 2023, a cyber assault on the UK Electoral Commission led to “hostile actors” accessing electoral registers.
The full details of this cybersecurity incident involving the UK Armed Forces payment network can be found in this recent Jurist article.