UK says defence ministry targeted in cyberattack

A senior British lawmaker said on Tuesday that China was probably behind a massive cyberattack on the names and banking details of UK armed forces personnel, prompting a furious denial by Beijing.

Prime Minister Rishi Sunak said there were indications that a "malign actor has compromised the armed forces payment network" but stopped short of naming China.

His comments came after MP and former minister Tobias Ellwood said a contractor's payroll system used by the defence ministry was targeted, adding that it had the hallmarks of a Chinese operation.

"Targeting the names of the payroll system and service personnel's bank details -- this does point to China because it can be as part of a plan, a strategy to see who might be coerced," the ex-soldier and former chairman of a parliamentary defence committee, told BBC radio.

Defence Secretary Grant Shapps was due to give details of the data breach to parliament later on Tuesday.

The leak is believed to have also included a small number of personal addresses of serving and former armed forces members.

Cabinet minister Mel Stride told Sky News television, which first reported the breach, the government was not currently pointing the finger at Beijing. 

"That is an assumption... We are not saying that at this precise moment," he said.

Prime Minister Rishi Sunak blamed a 'malign actor' but stopped short of naming China
POOL/AFP | Kin Cheung

But he said that the government viewed Beijing's government as an "epoch-defining challenge. Our eyes are wide open when it comes to China." 

Sunak, speaking on a visit to southeast London, added that the government had set out a "robust policy" towards China, which was becoming increasingly "authoritarian" at home and "more assertive" abroad.

- 'Utter nonsense' -

Beijing hit back at the claims from Ellwood, a China hawk who has publicly criticised Beijing's crackdown on rights in Hong Kong.

"The remarks by relevant British politicians are utter nonsense," foreign ministry spokesman Lin Jian said.

"China has always firmly opposed and cracked down on all types of cyberattacks."

British MP Tobias Ellwood alleged the attack bore the hallmarks of China
AFP | Justin TALLIS

The UK and the United States in March accused China of a global campaign of "malicious" cyberattacks in an unprecedented joint operation.

Britain accused China of targeting the Electoral Commission watchdog and the email accounts of parliamentarians.

The Electoral Commission attack was identified in October 2022 but the hackers had been able to access the commission’s systems for more than a year.

China called that accusation "malicious slander".

In June 2023, Google subsidiary Mandiant said online attackers with clear links to China were behind a vast cyberespionage campaign targeting government agencies of interest to Beijing.

Washington has also frequently accused Beijing of cyberattacks against US targets.

Last month two British men, including a former UK parliamentary researcher, appeared in court in London accused of spying for China.

Sunak's government has come under pressure to take a tougher line on China, and last month announced a hike in the country's defence budget to guard against new and emerging threats.

On a visit to Poland, Sunak singled out China, alongside Russia, Iran and North Korea, describing them as "an axis of authoritarian states".

By Helen Rowe

Paid Content