MP Stewart McDonald, from Glasgow South, has revealed his personal email account has been hacked by suspected Russian threat actors.

A representative of the Scottish National Party (SNP), Stewart McDonald announced the breach in a tweet published on the 8th of February.

The tweet read:

Over the past couple of weeks I have been dealing with a sophisticated and targeted spear phishing hack of my personal email account, and the personal email account belonging to one of my staff. These hacks are a criminal offence“.

Although attempts to hack my parliamentary account are continuous – as is the case for all MPs – these have not been successful. I want to assure constituents that their information is secure. My private account is not used for constituency or parliamentary business“.

 

The Spear-Phishing attack

Stewart McDonald disclosed further details about the attack in an interview with the BBC.

McDonald stated that he first received the spear-phishing email in January 2023, which came from the real email address of a member of his staff.

The email stated that there was a password-protected document attached containing an update on the military situation in Ukraine. McDonald said this wasn’t unusual given his previous position as the SNP defence spokesperson, and also because he had taken an active interest in Ukraine in the past, even receiving the order of merit from the Ukrainian government.

Due to the highly-targeted nature of the document, McDonald was encouraged to open the attachment, and was then directed to what appeared to be the login page for his email account (believed to have been Gmail).

McDonald then entered his details into the login page, only to be greeted with a blank page, and not the military update he was expecting.

A few days later, the member of staff who McDonald had received the spear-phishing email from informed him that he was locked out of his personal email due to suspicious activity. The MP then asked about the military update email that he received, to which the staff member replied that they didn’t send it.

 

Aftermath

McDonald was advised to contact the NCSC about this suspicious activity, who worked with the parliamentary security team to examine the cyber attack. They currently suspect that a Russian state-backed group was behind the attack.

McDonald stated further in his interview that: “I can expect them to manipulate and fake some of that content, and I want to get out ahead of that to ensure any disinformation attack against me is discredited before it’s even published.

Further in McDonald’s twitter thread, he stated that he wanted to raise awareness around phishing threats, “As was the case here, these attempts are highly sophisticated and deeply convincing. Having spoken with others who this has also happened to – most of who have a heightened sense of cyber security and good practice – it’s easy to see how anyone can fall victim.

 

Phishing attacks on the rise

This attack displays the affects of the Ukraine war, described by many as the first hybrid-war, combining both military and cyber attacks.

In an advisory issued by the NCSC in January 2023, around the time the attack took place, the public organisation warned about the dangers of spear phishing attacks by Russian and Iranian threat actors targeting specific sectors and individuals in public positions, including politicians, journalists and activists.

The NCSC’s advisory warned that Russian base threat actor SEABORGIUM and Iran-based group TA453 were launching highly targeted phishing attacks to steal log-in credentials to access and steal sensitive data.

 

The UK and US crackdown on ransomware operations

This cyber attack against a British MP comes just as the UK and US begin coordinated action against international cyber crime.

On the 9th of February seven Russian cyber criminals were sanctioned by having their assets frozen and travel bans imposed.

Foreign Secretary James Cleverly said of the sanctions:

By sanctioning these cyber criminals, we are sending a clear signal to them and others involved in ransomware that they will be held to account. These cynical cyber attacks cause real damage to people’s lives and livelihoods. We will always put our national security first by protecting the UK and our allies from serious organised crime – whatever its form and wherever it originates.

The individual designated by the sanctions were:

  • Vitaliy Kovalev
  • Valery Sedletski
  • Valentin Karyagin
  • Maksim Mikhailov
  • Dmitry Pleshvskiy
  • Mikhail Iskritskiy
  • Ivan Vakhromeyev

Making funds available to these individuals, such as by paying ransomware, including in crypto assets, is prohibited under these sanctions. 

 

 
TecSec Services Ltd is an IT Support and Risk Management provider.
We have achieved Cyber Essentials, Cyber Essentials +, IASME Gold, and are an official IASME certification body.
We have also achieved ISO 2701:2013, a substantial certification for our Information Security Management system.
We are currently offering a free service that will help to identify if your organisation is at risk of being exploited by cybercriminals.
Our Free Cyber Security Training helps protect your staff against phishing attacks, by providing the current best methods of identifying phishing emails: