No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

UK Military Data Breach a Reminder of Third-Party Risk

May 9, 2024
in Protection
0
UK Military Data Breach a Reminder of Third-Party Risk


The disclosure of a breach exposing data on over 225,000 UK military personnel underscores the global security risks associated with external contractors to defense entities.

The exposure, which came to light just this week, stemmed from a threat actor accessing the names, bank account details, and other information for current, former, and reserve members of the British Army, Naval Service, and Royal Air Force from a company handling payroll services for the UK Ministry of Defence (MoD).

External Contractor at Fault

The BBC and other UK media outlets identified the external contractor as Shared Services Connected Ltd and say the breached payroll system contains information on military personnel going back several years. In comments to Members of Parliament, the UK’s Secretary of State for Defence Grant Shapps identified the attack as the work of a “malign actor” that was very likely nation-state backed. While some senior government officials pointed to China as the most likely suspect, Shapps himself stopped short of pinning the attack on anyone by name.

Instead, he blamed the third-party contractor for not doing enough to protect its systems against attack. Malign actors gained access to a part of the armed forces payment network via an external system that is completely separate from the MoD core network and not connected to the main military HR system, Shapps said. “It is operated by a contractor, and there is evidence of potential failings by them which may have made it easier for the malign actor to gain entry,” he emphasized. Shapps added that the UK government has initiated a special security review of the contractor and their operations.

The latest incident marks the second time in less than one year that an external contractor was responsible for exposing data related to the UK military. Last August, the LockBit ransomware gang managed to steal some 10GB of data from Zaun, a company that provides mesh-fencing services for UK military facilities. Zaun described the breach as the result of a rogue Windows 7 system on its network. The company claimed LockBit actors accessed a system that contained “historic emails, orders, drawings, and project files” but no classified information or military secrets.

Supply Chain Risks in the Defense Sector

Breaches like these highlight the vulnerable underbelly that external contractors present to attackers who want to target military and defense data and systems. In June 2023, Adlumin reported on a threat actor dropping a novel backdoor called PowerDrop on systems belonging to at least one US defense contractor. And last month, the US government released details on a multiyear effort by Iranian cyberspies to steal US military secrets by targeting employees at defense contracting firms who have high-level security clearances.

Eric Noonan, CEO of CyberSheath, says third-party contractors that work with the military are an attractive target because these organizations often overlook vital security measures. “In the US, there has been over a decade-long fight by the DoD to force minimum security standards on third-party contractors through its [Cybersecurity Maturity Model Certification] program,” he says. “But until contractors are faced with losing out on contracts due to poor security, I don’t expect much will change.”

Noonan points to research CyberSheath conducted last year that showed a high percentage of the Defense Industrial Base not having basic cybersecurity controls in place and putting the entire Pentagon supply chain at risk. For instance, 81% of the contractors in CyberSheath’s study did not have a formal vulnerability management system; 75% did not implement multifactor authentication; and 75% did not have a back-up plan.

A May 2022 study by Black Kite of the top 100 US defense contractors uncovered similar issues: 72%, for instance. had experienced at least one leaked credential in the preceding 90 days; 32% were vulnerable to ransomware attacks; and 17% were using out-of-date — and therefore unsupported — systems.

Time for Mandatory Minimum Standards?

“Industries like defense and other critical infrastructure sectors must be regulated to implement mandatory minimum cybersecurity standards,” Noonan says. “The private companies operating in these sectors haven’t made the required investments in cybersecurity, and they won’t, unless it’s forced through regulation like CMMC.”

Stephen Gates, principal security SME at Horizon3.ai, says third-party cyber risk has generally never been higher. “It’s one of the reasons why organizations are now nearly mandating their third-party suppliers perform continuous cyber-risk assessments of their own infrastructures to ensure they are not transferring their risk to others — especially their buyers.”

The challenge for organizations is how to execute continuous cyber assessments. Checkbox self-assessment exercises and external penetration testing that test merely a small portion of the network have been largely unsuccessful, Gates says. “Therefore, initiatives are surfacing, which are all calling for increases in continuously assessing cyber risk,” he says.

As examples, Gates points to an initiative the US Navy launched in November 2023 to provide realistic cyber assessments via automated and manual testing of security protections, and another from the US DoD called the Cyber Operational Readiness Assessment (CORA) program.



Editorial Team

Editorial Team

Related Posts

Shows and Movies Like 'Disclosure Day' You Should Watch Next
Protection

Shows and Movies Like ‘Disclosure Day’ You Should Watch Next

June 15, 2026
This Philips Keyless Entry Electronic Deadbolt Is on Sale for Just $68 Right Now
Protection

This Philips Keyless Entry Electronic Deadbolt Is on Sale for Just $68 Right Now

June 15, 2026
You Can Get the Full Office 2024 Suite With Structured Lessons for Just $114 Right Now
Protection

You Can Get the Full Office 2024 Suite With Structured Lessons for Just $114 Right Now

June 15, 2026
This Eufy Omni C20 Robot Vacuum Is Over $100 Off Right Now
Protection

This Eufy Omni C20 Robot Vacuum Is Over $100 Off Right Now

June 15, 2026
All the New Features Coming to Messages in iOS 27
Protection

All the New Features Coming to Messages in iOS 27

June 12, 2026
30 of the Gayest Straight Movies Ever Made
Protection

30 of the Gayest Straight Movies Ever Made

June 12, 2026
Load More
Next Post
IBM’s Red Hat Sued by Stephen Miller’s Legal Group for Anti-White Male Bias

IBM’s Red Hat Sued by Stephen Miller’s Legal Group for Anti-White Male Bias

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Solana price could revisit June lows as recovery runs out of steam

    0 shares
    Share 0 Tweet 0
  • I Used Monarch Money for 30 Days: Here’s What Happened

    0 shares
    Share 0 Tweet 0
  • EWC: I Still Like Canada Going Forward (NYSEARCA:EWC)

    0 shares
    Share 0 Tweet 0
  • Demand for protection insurance expected to rise in 2025, survey finds

    0 shares
    Share 0 Tweet 0

Latest News

The chip-stock rally is back in full force — thanks to two big geopolitical developments

The chip-stock rally is back in full force — thanks to two big geopolitical developments

June 15, 2026
0

Iran peace prospects are spurring gains for riskier stocks, and Anthropic’s battle with the U.S. government could prompt a broadening...

Ethereum Quantum-Proof Account Proposal Could Make Wallet Protection Cheap

Ethereum Quantum-Proof Account Proposal Could Make Wallet Protection Cheap

June 15, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure Ethereum’s quantum-security debate has taken a more...

Anthropic and US officials meeting Monday to resolve dispute over export curbs, administration official says

Anthropic and US officials meeting Monday to resolve dispute over export curbs, administration official says

June 15, 2026
0

Anthropic and US officials meeting Monday to resolve dispute over export curbs, administration official says

Shows and Movies Like 'Disclosure Day' You Should Watch Next

Shows and Movies Like ‘Disclosure Day’ You Should Watch Next

June 15, 2026
0

We may earn a commission from links on this page. Steven Spielberg's latest has done some very respectable business at...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.