The septuagenarian Sellafield nuclear site is perhaps best remembered for producing the plutonium used to build nuclear weapons during the Cold War when it was still known as Windscale. These days, Sellafield has the biggest store of plutonium on the planet. Which is why reports that unnamed “cyber groups” that are “closely linked to Russia and China” have hacked into Sellafield IT systems across several years are alarming, to say the least. But are they accurate?
The Guardian has reported that breaches reach back to at least 2015 when “sleeper malware – software that can lurk and be used to spy or attack systems – had been embedded in Sellafield’s computer networks”. The report further reveals that the site was placed under special measures in 2022 for its cybersecurity failings, as confirmed by the Office for Nuclear Regulation.
Sellafield Ltd has posted a statement to the official GOV.UK site denying the hacking claims made in the report. “Our monitoring systems are robust and we have a high degree of confidence that no such malware exists on our system,” the statement reads, adding that “critical networks that enable us to operate safely are isolated from our general IT network, meaning an attack on our IT system would not penetrate these”.
Such air-gapping of the most sensitive systems is to be expected where critical national infrastructure (CNI) is concerned. However, as the Stuxnet attack against an Iranian nuclear plant more than a decade ago proves, such systems are not foolproof. Stuxnet was facilitated by a contractor using an infected memory stick. The Guardian report claims that Sellafield external contractors can “plug memory sticks into the system while unsupervised”.
Expert view on the Sellafield hack
So, has Sellafield been hacked or not?
In classic X-Files territory, the truth is no doubt out there, and the report by The Guardian will hopefully shine more light on the affair.
“This is not the first time we’ve observed cybersecurity vulnerabilities being downplayed or hidden by senior staff at nuclear facilities,” says Dr Klaus Schenk, Senior VP of Security and Threat Research at Verimatrix. “Sharing information about hacks and being transparent about the details is always challenging, but it’s the only way to improve security when done responsibly,” Schenk concludes.
If true, Fergal Lyons, Centripetal Cybersecurity Evangelist, is not impressed. “The lapse in cybersecurity measures at Sellafield, a high-security nuclear facility, represents a concerning oversight that persisted over an extended period,” he says. “This situation underscores the daunting task of safeguarding any high-value facility under constant siege by assailants globally.”
We will leave the last word to Jamie Akhtar, CEO and Co-Founder at CyberSmart, who comments: “Given that the site has faced several problems with its cybersecurity over the years, we hope this incident serves as a reminder, not just to Sellafield, but to all parts of the UK’s critical infrastructure and the small businesses that work in tandem with it to take cybersecurity seriously.”
Read next: Would you pass a Cyber Essentials audit? Here’s why hackers hope not