Rishi Sunak ‘Confident’ He Was Not a Victim as UK Accuses Russia of Hacking MPs

The Russian ambassador to London has been summoned to explain why a group—believed to be a unit of the FSB—has tried to hack MPs and government officials.
Rishi Sunak ‘Confident’ He Was Not a Victim as UK Accuses Russia of Hacking MPs
An undated image of a man typing on a laptop. (Sora Shimazaki/Pexels)
Chris Summers
12/7/2023
Updated:
12/7/2023
0:00

Britain has accused Russia’s Federal Security Service (FSB) of trying to steal information and data from MPs, government officials and journalists over an eight-year period in an attempt to “interfere in UK political processes.”

The Russian ambassador was summoned to the Foreign Office to be told Russia’s “actions have consequences,” but he was not available and instead, officials met with a senior official in President Vladimir Putin’s government and warned him about attempts to usurp the democratic process.

Foreign Office minister Leo Docherty issued a statement in the House of Commons on Thursday in which he said a group of hackers known as Star Blizzard—which he said was “almost certainly” part of the FSB’s Centre 18 cyber unit—had “selectively leaked and amplified information” since 2015.

Mr. Docherty said Star Blizzard—who are sometimes referred to as Callisto Group, Cold River or Seaborgium—had carried out spear-phishing attacks on a “significant” number of MPs and peers from all the main political parties, as well as civil servants, journalists and representatives of various think tanks.

Russia Trying to ‘Meddle in British Politics’

He told MPs the FSB was behind a, “sustained effort to interfere in our democratic processes” and he added, “They have been targeting high-profile individuals and entities with a clear intent, using information they obtain to meddle in British politics.”

“We want to be as open as we can be with the House and the British public. Our commitment to transparency stands in sharp contrast to the efforts of the KGB successors to exert influence from the shadows,” added Mr. Docherty.

The Foreign Office says it has sanctioned two members of Star Blizzard following an investigation by the National Crime Agency and it named them as Andrey Stanislavovich Korinets, also known as Alexey Doguzhiev, and Ruslan Aleksandrovich Peretyatko, who is allegedly an FSB intelligence officer.

Asked at a press conference on Thursday if he himself had been hacked, Prime Minister Rishi Sunak said, “There are a range of protections that both parliamentarians and ministers have, and advice they follow and we get support from the National Cyber Security Centre, and I’m confident in the protections that I have.”

Star Blizzard is understood to have specialised in contacting MPs and other high-profile individuals through their personal email accounts and impersonating their friends or acquaintances using “false accounts” and then seeking to, “build a rapport before delivering a malicious link.”

In 2020, the British government accused Russia of trying to interfere in the 2019 general election after stealingCrop cyber spy documents on Anglo-American trade from Conservative MP Liam Fox, which were then leaked.

But at the time, the British authorities did not name Star Blizzard.

Other examples which were given on Thursday include the hacking, in 2018, of the Institute for Statecraft, a British think tank which works to, “defend democracy against disinformation”, and the compromising in Dec. 2021 of an email account belonging to the Institute for Statecraft’s founder, Christopher Donnelly.

Next year, Britain faces a general election, and there will also be a presidential election in the United States and intelligence agencies are acutely aware of the danger of Russia trying to sabotage the political process.

Britain’s support for the Ukrainian war effort is thought to be another reason why the UK has been targeted by Star Blizzard and the FSB.

The Foreign Secretary, David Cameron, said: “Russia’s attempts to interfere in UK politics are completely unacceptable and seek to threaten our democratic processes. Despite their repeated efforts, they have failed.”

“In sanctioning those responsible and summoning the Russian ambassador today, we are exposing their malign attempts at influence and shining a light on yet another example of how Russia chooses to operate on the global stage,” added Lord Cameron.

Deputy Prime Minister Oliver Dowden said: “As I warned earlier this year, state actors, and the ‘Wagner-style’ sub-state hackers they use to do their dirty work, will continue to target our public institutions and our democratic processes. We will continue to call this activity out, to raise our defences, and to take action against the perpetrators.”

‘Online is the new Frontline’

“Online is the new frontline. We are taking a whole-of-society approach to ensure we have the robust systems and cutting-edge skills needed to resist these attempts to undermine our democracy,” added Mr. Dowden.

The National Crime Agency’s director general for threats, James Babbage, said, “The sanctions announced today are the result of a lengthy and complex investigation by the NCA, demonstrating that hostile Russian cyber actors were behind repeated, targeted attacks designed to undermine the UK.”

“This action sends a clear message to criminals targeting the UK wherever in the world they may be. We know who they are, they are not immune to our action, and we will not stop in our efforts to disrupt them,” he added.

Foreign Office minister Leo Docherty (L) welcoming Prime Minister Rishi Sunak to the Ukraine Recovery Conference, in London on June 21, 2023. (Stefan Rousseau/PA Wire)
Foreign Office minister Leo Docherty (L) welcoming Prime Minister Rishi Sunak to the Ukraine Recovery Conference, in London on June 21, 2023. (Stefan Rousseau/PA Wire)
The National Cyber Security Centre published further details of the Russian cyber attacks on its website and said it would work with its Five Eyes partners—the United States, Canada, Australia and New Zealand—to inform network defenders of how to mitigate hostile activity.

On Thursday, Microsoft threat intelligence wrote on X, formerly known as Twitter, “Microsoft continues to track and disrupt activity attributed to a Russian state-sponsored actor we track as Star Blizzard (Seaborgium), who has improved their evasion capabilities since 2022 while remaining focused on email credential theft.”

PA Media contributed to this report.