Hague: UK government fell victim to Zeus attack

NEWS

The UK government fell victim to a cyberattack that infected systems, foreign secretary William Hague has admitted.

William Hague foreign secretary

Foreign secretary William Hague has confirmed that UK government systems fell victim to a Zeus Trojan attack. Photo credit: Foreign and Commonwealth Office

In late December, spoofed emails claiming to come from the White House bypassed government filters and infected systems with a variant of the Zeus information-stealing Trojan, Hague told the Munich Security Conference on Friday.

"The UK Government was targeted in this attack and a large number of emails bypassed some of our filters," said Hague. "Our experts were able to clear up the infection, but more sophisticated attacks such as these are becoming more common."

The emails directed users to click on a link, which downloaded a variant of the Zeus Trojan, said Hague. MessageLabs, which filters emails for the UK government, had not responded to a request for comment at the time of writing. The Cabinet Office, which oversees government cybersecurity efforts, had also not responded to a request for comment.

Peter Sommer, a cybersecurity expert with the London School of Economics, told ZDNet UK that attribution of cyberattacks was difficult, so governments should focus more on defence than attacks.

Our experts were able to clear up the infection, but more sophisticated attacks such as these are becoming more common.

– William Hague, foreign secretary

"Nations still need to focus their cyber-defence policies on resilience — hardening the protection of computer systems and having detailed contingency plans to enable them to recover from an attack," Sommer said.

In his speech, Hague called for new rules to establish how countries should behave in cyberspace.

"In Britain, we believe that the time has come to seek international agreement about norms in cyberspace," Hague said. "We believe there is a need for a more comprehensive, structured dialogue to begin to build consensus among like-minded countries and to lay the basis for agreement on a set of standards on how countries should act in cyberspace."

Hague said the UK government wanted to host a cybersecurity conference in the summer "to explore mechanisms for giving [cyber] standards real political and diplomatic weight."

The UK government will push for agreements that aim for "governments to act proportionately in cyberspace and in accordance with national and international law", Hague said. Additional aims include more accessibility, tolerance, open flow of ideas, privacy, protection of intellectual property, collective action against criminals, and the promotion of competition, he added.

Think tank report

A report issued by US think tank the EastWest Institute on Thursday also called for "rules of the road", to be agreed between the US, Russia and other countries.

"Cybersecurity has quickly emerged as the linchpin of our mutual safety, stability and security," the report stated. "Yet the 'rules of the road' for cyber-conflict, or even the norms for behaviour, are blatantly absent."

Read this

ITU head: Cyberwar could be 'worse than tsunami'

Hamadoun Toure, the UN agency's secretary-general, has called for a global 'cyber peace treaty' in the context of the 'new world order' of cyberspace

Read more+

The report said that countries need to establish whether humanitarian critical infrastructure should be disentangled from 'non-protected' infrastructures. Russia and the US need to examine whether humanitarian infrastructure, such as medical systems, needs to be clearly marked in cyberspace to avoid fallout, in a similar way to physical infrastructure being marked with a red cross or crescent.

A cyber-war convention should recognise that 'non-state actors' such as individuals or groups of citizens have more power in cyberspace than in the physical world, the report said, and that governments should be open to new levels of co-operation with non-state actors, non-governmental organisations and corporations.

Cyber-weaponry needs to be examined to see if any attack tools or methods have attributes that are proscribed under the Geneva Protocol, the report added, noting that Russia, the US and other countries should examine 'cyber-war' to see if a third state other than 'war' or 'peace' is applicable to cyberattacks.

The report was overseen by Karl Rauscher, who used to work for Bell Labs as executive director of network reliability and security, and Andrey Korotkov, a former Russian deputy 'informatisation' minister.


Get the latest technology news and analysis, blogs and reviews delivered directly to your inbox with ZDNet UK's newsletters.

Talkback

The lower levels of the Civil service have machines totally locked down. The idiots in Whitehall who did this are the least tech savvy people on the planet, they have been Administrator rights over there own machines and allowed emails from external sources which are not security properly cleared or spam/virus filtered.

The emails should be encrypted at all levels between staff/departments and governments anyway - that would be a dead give away - ones which are plain text or cannot be decrypted go into spam. Even Churchill and Roosevelt spoke across an encrypted line. You have to ask why give the top Echelons of the Civil Service internet access anyway when it is proven that it is they the user who are the weakest security link, losing laptops with millions of records, pendrives, documents etc.

GCHQ is sitting on its hands when it should be taking charge.

L1ma 4 February, 2011 19:08
Reply

we need to be a lot more proactive in measures introduced in our country, innovative methods to deal with incoming/outgoing traffic

OT : Phone hacking ... its so easy to precisely locate a mobile phone over compromised networks, now why isn't the possible hacking of senior politicians mobile phones as a matter of national security instead of a police / privacy matter ?

GCHQ / MI5, the other organs of national security and the MoD need to be far more involved with these issues - i can guarantee that their counterparts abroad are involved

wid0wmaker 8 February, 2011 22:28
Reply

So long as our national (security) IT infrastructure is based on inherently insecure operating systems such as Windows we'll always live in fear.

AndyPagin 9 February, 2011 11:10
Reply

I have to agree with Andy, it all starts with the operating system. And since you can't buy a PC without windows pre-installed, and then add IE, you start without security.

ator1940 9 February, 2011 13:00
Reply

There are no simple answers to this. The most difficult and complicated answer of all is that of educating the people using the systems. This a serious uphill battle as I know from direct experience. However there are measures that could be taken that would go a long way towards reducing the risk - regardless of what operating system was in use. Unfortunately all of then cost money and everyone (who is a bean counter) knows that bean counting is more important that security!

One of the first things that could be done (which would of course raise howls of protest) would be to supply an e-mail program that would display nothing but plain text. For real day-to-day information exchange nothing else is necessary.

There should be no possibility of in-line display of any other media, although a download option should be available, and the system fitted with read-only programs for relevant media, such as a dedicated PDF viewer that will NOT recognise any executable code.

Almost all web browsers are full of security holes, so again, at risk of having the poor users rolling around the floor in an agony of withdrawal symptoms. any organisation working in a supposedly secure environment needs to consider whether that can actually manage without - hint: they did previously.

The current situation didn't go 'Splot' on the pavement one dark stormy night. It developed over the last 20 years, with plenty of warning on the way. Maybe if organisations actually listened to their IT people things could improve - although of course most IT has been outsourced so there aren't many people with a real interest in doing anything other than making money out of the existing system.

I guess we're stuck with it indefinitely then :(

Tezzer 9 February, 2011 13:28
Reply

@ator1940
> And since you can't buy a PC without windows pre-installed

Not true, obviously. Even if you were by some happy accident correct, the operating system as shipped wouldn't usually be the one installed by a large company or government department: they have disk images for that.

@Tezzer
> Almost all web browsers are full of security holes

But it's not rocket science to run the browser in a sandbox, and Google Chrome does that without even asking you.

> Maybe if organisations actually listened to their IT people things could improve

I agree with most of your comment, but their IT people are the ones who coded stuff for IE6 (preventing the use of a modern browser) and who still install an insecure 10 year old operating system when far better options are available, even from Microsoft ;-)

Jack Schofield 9 February, 2011 14:23
Reply

The fact that the UK government, NASDAQ and London Stock Exchange have alll experienced targetted attacks demonstrates how cybercriminals are evolving their tactics to specify certain organisations. As a result, organisations need to look to invest in the defence and protection of their assets http://bit.ly/fSPDJS, rather than trying to source the attackers, which is almost impossible.

Juliette_msc 11 February, 2011 14:49
Reply

This post has been removed by a moderator.

This post has been removed by a moderator.

You have gotta be kidding. Here in " aussieland " or 'downunder', we are still in the stoneage of computer development. Our much flaunted Federal NBB which cost $ 64B is still being rolled out, and by the time it finally gets to major cities, the final cost will be prohibitive, and by Law will ban local ISP's ( inevitably cheaper ) from the market. 4G is the way to go, but try telling it to the Politicians in Canberra.
Disillusioned !

dalma01 3 March, 2011 21:26
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

dede0202

Hello ALL USERS OF THE PIRATE BAY I WOULD PUT AN EXPLANATION ON PIRACY Story Idea ILLIGALE AND SHARING THOSE THAT NET Dissent NOT WELL BUT TO CA...

4 hours ago by dede0202 on The Pirate Bay infringes copyright, High Court decides
Sungwoo

do You know that? it can install 4G Ram. So i buy 4g and install It work! I can run call of duty 4,6,7 [Modern war... 1,2,3] Call of duty 1 was...

5 hours ago by Sungwoo on Loose Ends - Upgrading the Aspire One 522
itsajob

2. Bad idea. Making up patch cables loses you your commission from the cable supplier. 3. If you tidy up, other people can understand where the...

11 hours ago by itsajob on Ten IT jobs to save up for those rare lulls
Roberto_Store

Now On Sale, Unlocked iPhone 4S / Galaxy Note In Factory Box. Roberto-Techie(UK) ”Now on Sales” Smartphone, Android,Tablets,Gadget &...

15 hours ago by Roberto_Store on Samsung Galaxy S III lined up for sale
Paul Smyth

Is this classic FUD? One thing I would definitely have notice is a Mozilla threat to stop supporting GNU/Linux.

17 hours ago by Paul Smyth via Facebook on Firefox rapid release improves Fedora Linux
UnderINK

I agree with the previous commenter wholeheartedly. I couldn't say it better myself. This is very 'Big Brother'. And while I agree with protecting...

21 hours ago by UnderINK on European e-identity plan to be unveiled this month
Simon Bisson and Mary Branscombe

Nice to see that Turing's idea of a general purpose computer doing once-hardware-powered tasks in software is now universal ;-) Mary

1 day ago by Simon Bisson and Mary Branscombe on Software with everything
Jason Burchell

seriously now. I've only bothered to read a small bit of the comments. do me and the rest of the world a favour. stop saying it does not work or...

1 day ago by Jason Burchell via Facebook on Music industry negotiating over 24-bit downloads
Philip Charles Cohen

Read about it and weep, John Donahoe ... In addition to Visa’s V.me, there is now MasterCard’s PayPass digital wallet soon to arrive; another...

1 day ago by Philip Charles Cohen via Facebook on PayPal takes phone-based payments to the high street
apexwm

Leslie Satenstein : Where have you ever seen Mozilla even mention this? Firefox is the most popular browser in the GNU/Linux OS, so I don't see...

1 day ago by apexwm on Firefox rapid release improves Fedora Linux
songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

2 days ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

2 days ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

2 days ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

2 days ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

2 days ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

2 days ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

2 days ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

2 days ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

2 days ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

3 days ago by apexwm on Windows 8 start-up speed forces USB boot workaround