London Daily

Focus on the big picture.
Friday, Aug 07, 2026

Suspected Russian hack is much worse than first feared: Here's what you need to know

Suspected Russian hack is much worse than first feared: Here's what you need to know

The scale of a sophisticated cyberattack on the U.S. government that was unearthed this week is much bigger than first anticipated.

The Cybersecurity and Infrastructure Security Agency said in a summary Thursday that the threat “poses a grave risk to the federal government.”

It added that “state, local, tribal, and territorial governments as well as critical infrastructure entities and other private sector organizations” are also at risk.

CISA believes the attack began at least as early as March. Since then, multiple government agencies have reportedly been targeted by the hackers, with confirmation from the Energy and Commerce departments so far.

“This threat actor has demonstrated sophistication and complex tradecraft in these intrusions,” CISA said. “Removing the threat actor from compromised environments will be highly complex and challenging.”

Russia accused


CISA has not said who it thinks is the “advanced persistent threat actor” behind the “significant and ongoing” campaign, but many experts are pointing to Russia.

“The magnitude of this ongoing attack is hard to overstate,” former Trump Homeland Security Advisor Thomas Bossert said in a piece for The New York Times on Thursday. “The Russians have had access to a considerable number of important and sensitive networks for six to nine months.”

Russian presidential spokesman Dmitry Peskov rejected the accusations, according to the Tass news agency.

“Even if it is true there have been some attacks over many months and the Americans managed to do nothing about them, possibly it is wrong to groundlessly blame Russians right away,” he told Tass. “We have nothing to do with this.”

The Russian Embassy in London did not immediately respond to CNBC’s request for comment.

The FBI said Wednesday it is “investigating and gathering intelligence in order to attribute, pursue, and disrupt the responsible threat actors.”

At this stage, it’s not clear what the hackers have done beyond accessing top-secret government networks and monitoring data.

Hackers also accessed systems at the National Nuclear Security Administration, which maintains the U.S. nuclear weapons stockpile, according to the Politico news site, citing officials familiar with the matter.

SolarWinds backdoor


CISA said those behind the attack used network management software made by SolarWinds, a Texas-headquartered IT firm, to breach the government networks.

As many as 18,000 SolarWinds Orion customers downloaded a software update that contained a backdoor, which the hackers used to gain access to the networks.


CISA issued an “emergency directive” this week instructing federal civilian agencies to “immediately disconnect or power down affected SolarWinds Orion products from their network.”

But the perpetrators may have used other means to access the networks. CISA said Thursday is investigating “evidence of additional access vectors, other than the SolarWinds Orion platform.”

Microsoft customers targeted


Microsoft was hacked in connection with the attack on SolarWinds’ widely used management software, Reuters reported Thursday.

Like with the cyberattack of SolarWinds, hackers infiltrated Microsoft products and then went after others, Reuters said, citing people familiar with the matter.

“We have been actively looking for indicators of this actor and can confirm that we detected malicious SolarWinds binaries in our environment, which we isolated and removed. We have not found evidence of access to production services or customer data,” a Microsoft spokesperson said in a statement shared with CNBC.

“Our investigations, which are ongoing, have found absolutely no indications that our systems were used to attack others,” they added.

Microsoft said that more than 40 client organizations were compromised in the attack.

“While roughly 80% of these customers are located in the United States, this work so far has also identified victims in seven additional countries,” Microsoft President Brad Smith said in a blog.

“This includes Canada and Mexico in North America; Belgium, Spain and the United Kingdom in Europe; and Israel and the UAE in the Middle East. It’s certain that the number and location of victims will keep growing.”

Smith added that “this is not espionage as usual” and “while governments have spied on each other for centuries, the recent attackers used a technique that has put at risk the technology supply chain for the broader economy.”


U.S. President-elect Joe Biden pledged Thursday to make cybersecurity a key area of focus for his administration.

“A good defense isn’t enough; We need to disrupt and deter our adversaries from undertaking significant cyberattacks in the first place,” Biden said in a statement issued by his transition team.

“We will do that by, among other things, imposing substantial costs on those responsible for such malicious attacks, including in coordination with our allies and partners. Our adversaries should know that, as President, I will not stand idly by in the face of cyber assaults on our nation.”

President Donald Trump, who has been silent about the hacking, threatened on Thursday to veto the National Defense Authorization Act, which includes money to help prevent such cyberattacks.

Newsletter

Related Articles

0:00
0:00
Close
HMRC’s 2029 Tax Shift Could Overlap Old and New Self-Assessment Bills
Thetford Disorder Prompts Expanded Police Powers Amid Asylum-Housing Protests
Cambridge Faces Calls for Independent Review of Jason Arday Appointment
Scotland’s ‘Cock of the North’ Woodland Is Being Felled After Wind Damage
Reform UK and Greens Unite Against Vast Solar Plans for Kent Marshland
New Zealand Draws Wealthy Americans With Revamped Investor Visa
Senate Panel Votes to Hold Anthony Fauci in Contempt After Fifth Amendment Testimony
Cambridge Professor Jason Arday Resigns as University Opens Inquiry Into His Credentials
Manchester Power Failure Disrupts Trains Across North West Into Friday
UK Fashion and Tourism Sectors Prepare for Strong Summer and Autumn Activity
London Residents Seek Appeal Against Approval for Chinese Super-Embassy Development
UK Environment Officials Issue Biosecurity Alert Over Rising Bluetongue Cases in Livestock
UK Charity Regulator Opens Investigations Into Donations Linked to Israeli Settlements
Gatwick Expansion and Chinese Embassy Plans Highlight Growing UK Infrastructure Disputes
UK Agriculture Authorities Warn of Rising Bluetongue Virus Cases Among Sheep Farms
UK Watchdog Finds Electronic Monitoring Failures Leaving Some Offenders Without Timely Alerts
Metropolitan Police Investigate Covent Garden Knife Attack That Injured Four Men
UK Government Confirms Severe Terror Threat Level as Prevent Programme Expands
Diageo Plans Guinness Expansion While Cutting Jobs Through Global Restructuring Programme
Bank of England Keeps UK Borrowing Costs Stable While Markets Await Future Rate Cuts
Gatwick Airport Wins Approval for Second Runway Expansion After Legal Challenges Fail
Apple Challenges UK Government Over Demand for Access to Encrypted iCloud Data
London Approves First Autonomous Taxi Licences for Wayve and Uber Passenger Trials
UK Artificial Intelligence Safety Institute Finds Advanced AI Models Showing Deceptive Behaviour in Security Tests
UK Small Boat Channel Crossings Fall Forty-Three Percent as Government Highlights France Cooperation
UK Government Plans Procurement Reforms to Boost British Jobs and Domestic Steel Supply Chains
Bank of England Holds Interest Rates at Three Point Seven Percent as Inflation Stays Above Target
EY Raises UK 2026 Growth Forecast to Zero Point Nine Percent as Energy Risks Remain a Concern
UK Artificial Intelligence Regulation and Public Infrastructure Investment Remain Key Policy Focus Areas
Kemi Badenoch Faces Criticism Over Appointment of Former Neo-Nazi Linked Figure to Advisory Role
AG Barr Reports £10 Million Sales Loss After Supply Chain and Planning Failures
UK Government Fast-Tracks Specialist Care Pathways for Motor Neurone Disease Patients
UK Government Connects More Than 60,000 Rural Homes and Businesses to Gigabit Broadband
Next Raises Full-Year Profit Forecast After Strong Summer Sales
Metropolitan Police Arrest Woman After Four Men Stabbed in Central London’s Covent Garden Area
UK Procurement Reform and Infrastructure Spending Signal New Focus on Regional Economic Growth
UK Government Expands Global Talent Visa Access for International Researchers and Innovators
NHS Launches £343 Million Expansion of Community Mental Health Centres Across England
UK Treasury Explores Higher Borrowing Capacity for Infrastructure and Housing Investment
UK Cabinet Office Reforms Procurement Rules to Direct £90 Billion of Public Spending Toward Jobs and Skills
UK Government Considers Public Inquiry Into Jeffrey Epstein’s Activities and Possible Institutional Failures
Britain’s AI Safety Institute Finds Advanced Models Creating Fake Identities and Malicious Code During Tests
Lightning Strike Kills Yala FC Player During Match in Southern Thailand
Senate Scrutinises AI-Driven Personalised Pricing
Spain Seeks Mainland Transfers for 1,100 Children Stranded in Ceuta
UK Government Pushes New Procurement, Skills and Technology Policies Amid Economic Pressure
UK Charity Commission Investigates Donations Linked to Israeli Settlement Groups
UK Government Faces Pressure Over Possible Windfall Tax on Bank Profits
South East Water Provides Emergency Support After Kent Supply Disruptions
UK Defence Supports US Operation to Seize Russian-Flagged Oil Tanker in North Atlantic
×