China “state-affiliated actors” have been blamed by the government for two cyber attack campaigns in the UK.
Making a speech in the Commons, Deputy Prime Minister Oliver Dowden revealed the two incidents involved an attack on the Electoral Commission – responsible for overseeing elections and political finance – in 2021, and targeted attacks against China-sceptic MPs.
He confirmed the Foreign Office would be summoning the Chinese ambassador “to account for China’s conduct in these incidents”, and that the UK, alongside international partners such as the US, would be issuing sanctions.
Mr Dowden told MPs: “The cyber threat posed by China affiliated actors is real and it is serious, but it is more than equalled by our determination and resolve to resist it.
“That is how we defend ourselves and our precious democracy.”
Politics live: PM issues nuclear warning
According to the National Cyber Security Centre, the incident at the commission, discovered in 2022, saw the Electoral Roll compromised, including the names and addresses of tens of millions of voters.
Deputy PM Oliver Dowden to warn of China cyber threats as ‘senior UK politicians targeted’
China ‘trying to undermine our democracy’ – as MPs set to be warned about new cyber attacks
Former Yoozoo Games executive sentenced to death over fatal poisoning of one of richest men in China
But “reconnaissance activity” in 2021, targeting the accounts of former Tory leader Sir Iain Duncan Smith, former Conservative education minister Tim Loughton, crossbench peer Lord Alton of Liverpool and SNP MP Stewart McDonald was unsuccessful.
The latter of the campaigns was blamed on the APT31 group, also known as Judgement Panda or Zirconium, but a specific entity has not been named for the Electoral Commission attack.
However, the Foreign Office has confirmed it is placing sanctions on a front company, the Wuhan Xiaoruizhi Science and Technology Company, and two actors involved in the operations of APT31, Zhao Guangzong and Ni Gaobin – a move echoed by the US government.
Keep up with all the latest news from the UK and around the world by following Sky News
A statement from the Foreign Office said there was a “clear pattern of malicious cyber activity by China state-affiliated organisations and individuals targeting democratic institutions and parliamentarians in the UK and beyond”.
It called on the Chinese government to “call out and take tough action against malicious cyber activity that infringes on our national security and democracy”.
But earlier on Monday, China’s ministry of foreign affairs spokesman Lin Jian hit out at what he called “smearing without factual basis”, claiming China was one of the “major victims of cyber attacks, and has always been resolute in stopping and cracking down on all kinds of malicious cyber activities, according to the law”.
Please use Chrome browser for a more accessible video player
Those MPs targeted by the attacks – all members of the Inter-Parliamentary Alliance on China (IPAC) who probe Beijing’s activities – were briefed by parliament’s director of security on Monday.
Speaking at a press conference afterwards, Sir Iain said the group had been “subjected to harassment, impersonation and attempted hacking from China for some time”, but insisted MPs would not be “bullied into silence by Beijing”.
He called for a “watershed moment” from the government that would see the UK “take a stand for values of human rights and the international rules-based system on which we all depend”.
Foreign Secretary Lord Cameron is also set to brief the 1922 Committee of backbench Conservative MPs later, where the topic is likely to be top of the agenda.
Science and technology editor
The fact China is attempting to spy on the UK and others online should come as no surprise.
This latest announcement from government is more of reminder that the activity is constant, and increasingly sophisticated.
The UK’s National Cyber Security Centre has now implicated a Chinese-backed hacking group APT31 of attempting to target a group of MPs.
There’s a clue in the name: Advanced Persistent Threat is cybersecurity speak for groups usually backed by governments.
A long list From APT16 to APT 41 are hacking groups each with their own techniques and target areas suspected of being run by the Chinese state.
It’s suggested APT 31 used “spear phishing” to attempt to spy on members of the Inter Parliamentary Alliance on China. The same as phishing – in which a malicious file, usually typically embedded in an innocent-looking link in a email – spear phishing is targeted at a specific individual or group.
We have less information on the hack of the Electoral Commission back in 2021, which has now also been attributed to China. In this instance the hackers are believed to have had persistent access to the Electoral Commission’s systems for months.
In response, the NCSC has updated guidance for political organisations and other institutions who could be at threat from such attacks, including updated guidance on sophisticated threat called “living off the land”.
This is a type of “fileless” attack that exploits native code used to manage server networks operated by large providers like Microsoft. Via an intrusion like a phishing attack, malicious code, disguised to look normal, is inserted straight into the target system’s operating instructions bypassing virus scanning software.
The danger of this type of attack is that it’s hard for online security teams to spot that an intrusion has happened, or to monitor the activity of hackers. Without very vigilant cybersecurity, hacks like this have been found to have persisted for long periods of time.
Last year Microsoft announced a “living off the land” attack by Chinese-backed hacker group Volt Typhoon had been used to infiltrate US utilities and critical infrastructure companies from 2021 onwards.
It comes amid growing pressure on Prime Minister Rishi Sunak from within his own party to take a tougher stance on China, having so far refused to brand the country a threat.
Speaking ahead of Mr Dowden’s statement, the prime minister said: “We’ve been very clear that the situation now is that China is behaving in an increasingly assertive way abroad, authoritarian at home and it represents an epoch-defining challenge, and also the greatest state-based threat to our economic security.
Be the first to get Breaking News
Install the Sky News app for free
“So, it’s right that we take measures to protect ourselves, which is what we are doing.”
A Downing Street source also told Sky News that Mr Sunak had “always had a robust position on China”, but it would “not be a sensible thing to do” to “cut all links” with Beijing, and instead the government took a “eyes wide open approach” to its activities.