Don’t do SECURITY. Do business SECURELY.

UK Parliament email system hit by cyber attack

Attackers tried to break into MPs' and staff email accounts, compromising a small number with weak passwords.

The UK Parliament was hit by a sustained cyber attack that targeted the email accounts of MPs and their staff. The House of Commons restricted remote access to its network while it worked with the National Cyber Security Centre.

What happened

  • The attack was disclosed on 24 June 2017, and attackers attempted to access accounts by trying weak passwords.
  • Parliamentary officials said fewer than 1% of around 9,000 accounts had been compromised.
  • Some MPs and staff were unable to access their email remotely over the weekend while the network was secured.
  • Later press reports cited officials who blamed Iran, although this was not formally confirmed by the UK government.

Why it mattered

The incident, weeks after WannaCry, showed that the UK’s democratic institutions were targets and that weak passwords remained an easy route in. It also raised concerns that sensitive constituent correspondence could be exposed.

Lessons for organisations

Enforce strong passwords, block commonly used ones, and require multi-factor authentication for remote access to email. These are simple controls that Cyber Essentials expects. Monitoring for repeated failed log-ins can also give early warning of password-guessing attacks.

Source: Euronews

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights