London Daily

Focus on the big picture.
Thursday, Jun 18, 2026

Suspected Russian hack is much worse than first feared: Here's what you need to know

Suspected Russian hack is much worse than first feared: Here's what you need to know

The scale of a sophisticated cyberattack on the U.S. government that was unearthed this week is much bigger than first anticipated.

The Cybersecurity and Infrastructure Security Agency said in a summary Thursday that the threat “poses a grave risk to the federal government.”

It added that “state, local, tribal, and territorial governments as well as critical infrastructure entities and other private sector organizations” are also at risk.

CISA believes the attack began at least as early as March. Since then, multiple government agencies have reportedly been targeted by the hackers, with confirmation from the Energy and Commerce departments so far.

“This threat actor has demonstrated sophistication and complex tradecraft in these intrusions,” CISA said. “Removing the threat actor from compromised environments will be highly complex and challenging.”

Russia accused


CISA has not said who it thinks is the “advanced persistent threat actor” behind the “significant and ongoing” campaign, but many experts are pointing to Russia.

“The magnitude of this ongoing attack is hard to overstate,” former Trump Homeland Security Advisor Thomas Bossert said in a piece for The New York Times on Thursday. “The Russians have had access to a considerable number of important and sensitive networks for six to nine months.”

Russian presidential spokesman Dmitry Peskov rejected the accusations, according to the Tass news agency.

“Even if it is true there have been some attacks over many months and the Americans managed to do nothing about them, possibly it is wrong to groundlessly blame Russians right away,” he told Tass. “We have nothing to do with this.”

The Russian Embassy in London did not immediately respond to CNBC’s request for comment.

The FBI said Wednesday it is “investigating and gathering intelligence in order to attribute, pursue, and disrupt the responsible threat actors.”

At this stage, it’s not clear what the hackers have done beyond accessing top-secret government networks and monitoring data.

Hackers also accessed systems at the National Nuclear Security Administration, which maintains the U.S. nuclear weapons stockpile, according to the Politico news site, citing officials familiar with the matter.

SolarWinds backdoor


CISA said those behind the attack used network management software made by SolarWinds, a Texas-headquartered IT firm, to breach the government networks.

As many as 18,000 SolarWinds Orion customers downloaded a software update that contained a backdoor, which the hackers used to gain access to the networks.


CISA issued an “emergency directive” this week instructing federal civilian agencies to “immediately disconnect or power down affected SolarWinds Orion products from their network.”

But the perpetrators may have used other means to access the networks. CISA said Thursday is investigating “evidence of additional access vectors, other than the SolarWinds Orion platform.”

Microsoft customers targeted


Microsoft was hacked in connection with the attack on SolarWinds’ widely used management software, Reuters reported Thursday.

Like with the cyberattack of SolarWinds, hackers infiltrated Microsoft products and then went after others, Reuters said, citing people familiar with the matter.

“We have been actively looking for indicators of this actor and can confirm that we detected malicious SolarWinds binaries in our environment, which we isolated and removed. We have not found evidence of access to production services or customer data,” a Microsoft spokesperson said in a statement shared with CNBC.

“Our investigations, which are ongoing, have found absolutely no indications that our systems were used to attack others,” they added.

Microsoft said that more than 40 client organizations were compromised in the attack.

“While roughly 80% of these customers are located in the United States, this work so far has also identified victims in seven additional countries,” Microsoft President Brad Smith said in a blog.

“This includes Canada and Mexico in North America; Belgium, Spain and the United Kingdom in Europe; and Israel and the UAE in the Middle East. It’s certain that the number and location of victims will keep growing.”

Smith added that “this is not espionage as usual” and “while governments have spied on each other for centuries, the recent attackers used a technique that has put at risk the technology supply chain for the broader economy.”


U.S. President-elect Joe Biden pledged Thursday to make cybersecurity a key area of focus for his administration.

“A good defense isn’t enough; We need to disrupt and deter our adversaries from undertaking significant cyberattacks in the first place,” Biden said in a statement issued by his transition team.

“We will do that by, among other things, imposing substantial costs on those responsible for such malicious attacks, including in coordination with our allies and partners. Our adversaries should know that, as President, I will not stand idly by in the face of cyber assaults on our nation.”

President Donald Trump, who has been silent about the hacking, threatened on Thursday to veto the National Defense Authorization Act, which includes money to help prevent such cyberattacks.

Newsletter

Related Articles

0:00
0:00
Close
Health Authorities Warn of Rising Cases of Seasonal Respiratory Illnesses
BAE Systems and Rolls-Royce Advance Multi-Nation Fighter Aircraft Programme
National Archives Publish Declassified Documents on Cold War Energy Security Planning
British Retail Spending Rises Despite Continuing Cost-of-Living Pressures
Wales Launches Social Housing Pilot to Address Affordability Pressures
British Energy Companies Commit £5 Billion to Geothermal and Hydrogen Projects
Northern Ireland Debates Cross-Border Healthcare Partnership With the Republic of Ireland
UK Establishes National Artificial Intelligence Safety Centre With Leading Universities
UK Reports Decline in Small Boat Crossings After Expanding Intelligence Cooperation With France
Scottish Parliament Launches Inquiry Into Delays to Renewable Energy Projects
National Crime Agency Dismantles Alleged Multi-Million-Pound Money Laundering Network in London
Transport Strikes Disrupt Rail and Bus Services Across Northern England
United Kingdom and European Union Open New Security Dialogue on Defense and Border Cooperation
Bank of England Holds Interest Rates at 5% as Services Inflation Remains Elevated
UK Government Unveils Major National Health Service Reform Focused on Decentralization and Performance Funding
Government Advances New Airport Slot Rules to Ease Airline Operating Constraints
BBC Opens Flagship Science-Fiction Franchise to Competitive Production Bids
Chancellor Meets City Leaders Amid Concerns Over Gilt Market Liquidity
Rathbones Shares Fall Seventeen Percent After Regulatory Review Reveals Compliance Failings
United Kingdom Joins Group of Seven Initiative Using Artificial Intelligence and Quantum Computing for Cancer Research
Parliament Debates Doubling Tax Allowance for Pensioners After Major Public Petition
Measles Cases Exceed Seven Hundred in London and the West Midlands
British Military Leadership Faces Parliamentary Scrutiny After Defence Secretary's Sudden Resignation
House of Lords Begins Debate on Steel Industry Nationalisation Legislation
Parliament Advances Bill to Abolish NHS England and Create Single Patient Records
Parliament Fast-Tracks National Security Bill to Expand Powers Against Foreign Threats
United Kingdom and European Union Set July Summit to Deepen Post-Brexit Cooperation
United Kingdom Imposes Seventy New Sanctions on Russia and Expands Support for Ukraine's Nuclear Sector
United Kingdom Announces Social Media Ban for Children Under Sixteen
0British Government Investigates Reports of Russian Warship Firing Warning Shots Near Isle of Wight
UK Supreme Court Revises Legal Definition of Deprivation of Liberty
King’s Birthday Honours Recognise Contributions Across Science, Culture and Public Service
UK Ministry of Defence Reports Interdiction of Russian Shadow Fleet Vessel
UK and US Launch Joint Regulatory Programme for Medicines and Healthcare Products
Solicitor General Refers Murder Sentence to Court of Appeal Under Unduly Lenient Scheme
UK Launches £1.6 Million Mobile Museum Initiative to Expand Cultural Access
Judicial Pay Structure Undergoes Government Review Following Senior Recommendations
Government Confirms Nearly 180 New Youth Hubs Across the United Kingdom
UK Government Expands Careers Support Through Partnership with LinkedIn
Digital News Report Highlights Growing Global Concern Over AI and Information Overload
UK Chancellor Reaffirms Fiscal Discipline and Borrowing Reduction Strategy
UK Government Invests £219 Million in Sustainable Aviation Fuel Development
Rolls-Royce Small Modular Reactors Secures Major Swedish Export Contract
Government Confirms Locations for Nearly 180 Youth Hubs Across Great Britain
UK Government Partners with LinkedIn to Expand Employment Support Services
Reuters Institute Report Flags Rising Public Anxiety Over News and Information Overload
UK Government Commits £219 Million to Expand Sustainable Aviation Fuel Industry
Chancellor Convenes Market Engagement Group to Assess UK Economic Outlook and Productivity Risks
Rolls-Royce Wins Multibillion-Pound Swedish Contract for Small Modular Nuclear Reactors
Government to Ban Social Media Access for Under-Sixteens Across the United Kingdom
×