Scottish Parliament cyber-attack ongoing but defences not breached
A cyber-attack on IT systems at the Scottish Parliament remains ongoing and could last several days, officials have said.
The “brute force cyber-attack” involving hackers systematically attempting to crack passwords was identified early on Tuesday, 15 August.
Parliament chief executive Sir Paul Grice told MSPs and staff on Wednesday, 16 August, that the systems remain under attack but there is no indication that defences have been breached. Parliamentary staff are currently working with the National Cyber Security Centre (NCSC) to contain the attack and security measures put in place so far have seen account lock-outs decrease.
“At this point there is no evidence to suggest that the attack has breached our defences and our IT systems continue to be fully operational,” Grice said in an email to staff. “Users should be aware, however, that this attack remains ongoing. It is not uncommon for brute force attacks to be sustained over a period of days.
“Staff from the BIT (Business Information Technology) Office are working closely with the NCSC and our suppliers to put in place additional security measures to continue to contain the incident and mitigate against any future attacks. In addition, analysis is taking place to better understand the origin of the attack and to assess its overall impact.”
Countries in Europe and elsewhere where the attack was routed through have been identified but the Parliament has declined to release any specifics as they have been unable to confirm where it originated.
The campaign is thought to be similar to an attack on Westminster in June, which lasted four days.