Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • UK cyber experts warn of targeted phishing attacks

Security

UK cyber experts warn of targeted phishing attacks

The UK has today warned of the threat from targeted spear-phishing campaigns against organisations and individuals carried out by cyber actors based in Russia and Iran.

Above: The National Cyber Security Centre (NCSC), Nova South, London.
Image by Simone Flamigni / copyright Shutterstock

In an advisory published today, the National Cyber Security Centre (NCSC) – a part of GCHQ – shared details about the techniques and tactics used by the attackers as well as mitigation advice to combat the continuing threat.

Advertisement
Security & Policing Rectangle

Spear-phishing involves an attacker sending malicious links, for example via email, to specific targets in order to try to induce them to share sensitive information.

The advisory highlights that throughout 2022 separate malicious campaigns were conducted by Russia-based group SEABORGIUM and Iran-based group TA453, also known as APT42, to target a range of organisations and individuals in the UK and elsewhere for information-gathering purposes.

The attacks are not aimed at the general public but targets in specified sectors, including academia, defence, government organisations, NGOs, think-tanks, as well as politicians, journalists and activists.

The advisory, based on NCSC understanding and extensive industry reporting, recommends organisations and individuals remain vigilant to approaches and follow the mitigation advice to protect their online accounts from compromise.

Paul Chichester, NCSC Director of Operations, said: “The UK is committed to exposing malicious cyber activity alongside our industry partners and this advisory raises awareness of the persistent threat posed by spear-phishing attacks.

“These campaigns by threat actors based in Russia and Iran continue to ruthlessly pursue their targets in an attempt to steal online credentials and compromise potentially sensitive systems.

“We strongly encourage organisations and individuals to remain vigilant to potential approaches and follow the mitigation advice in the advisory to protect themselves online.”

This activity is typical of spear-phishing attacks, where the actor undertakes reconnaissance activity around their target to tailor their content before making an approach.

Contact may initially appear benign as the attacker looks to gain targets’ trust and build a rapport, before using typical phishing tradecraft to share malicious links that can lead to credential theft and onward compromise.

The advisory describes how approaches have been made via email, social media and professional networking platforms, with attackers impersonating real-world contacts of their targets, sending false invitations to conferences and events, and sharing malicious links disguised as Zoom meeting URLs.

Advertisement
ODU RT

While the malicious campaigns use similar techniques and have similar targets, the campaigns are separate and the two actors are not collaborating.

If individuals or organisations in the identified sectors recognise the specific and targeted activity described in the advisory, they should report this to the NCSC.

The advisory includes the following advice to mitigate the spear-phishing activity:

  • Use strong and separate passwords for your email account
  • Turn on multi-factor authentication (also known as 2-step verification, or 2SV)
  • Protect your devices and networks by keeping them up to date
  • Exercise vigilance
  • Enable your email providers’ automated email scanning features
  • Disable mail-forwarding

The ‘Think Before You Link’ app, from the Centre for the Protection of National Infrastructure (CPNI), is also designed to help individuals identify malicious online profiles and reduce the risk of being targeted.

The NCSC is committed to raising awareness of the latest cyber threats and provides a range of practical guidance on its website to help public sector organisations, critical national infrastructure, businesses of all sizes, and individuals protect themselves online.

View the advisory: www.ncsc.gov.uk/news/spear-phishing-campaigns-targets-of-interest

 

Advertisement
General Atomics LB
Farnborough International Airshow 2026 unveils new features

Aerospace Defence Security Space Events

Farnborough International Airshow 2026 unveils new features

22 January 2026

The Farnborough International Airshow 2026, returning from 20th to 24th July, will be the largest and most ambitious event in its 78-year history, following record-breaking demand and the addition of a brand-new sixth exhibition hall.

SatVu appoints Scott Herman as CTO

Defence Security Space

SatVu appoints Scott Herman as CTO

22 January 2026

UK based high resolution thermal intelligence company SatVu, that reveals operational activity and infrastructure performance from space, today announced the appointment of Scott Herman as Chief Technology Officer (CTO).

Smiths Detection delivers automated IRBS between South Korea and US

Aerospace Security

Smiths Detection delivers automated IRBS between South Korea and US

21 January 2026

Smiths Detection has enabled the launch of a fully automated International Remote Baggage Screening System (IRBS), setting a new global standard for cross-border aviation security and passenger processing between South Korea and the United States.

Amentum and Rolls-Royce SMR partner on small modular reactors

Security

Amentum and Rolls-Royce SMR partner on small modular reactors

20 January 2026

Amentum has been selected as the programme delivery partner for the first deployments of the Rolls-Royce Small Modular Reactor (SMR) in the UK and Czech Republic.

Advertisement
Security & Policing Rectangle
NCSC issues hacktivist warning

Security

NCSC issues hacktivist warning

20 January 2026

The National Cyber Security Centre (NCSC) – a part of GCHQ – has issued an alert highlighting the persistent targeting of UK organisations by Russian state-aligned hacktivist groups aiming to disrupt networks.

GeoCue partners with Coptrz to expand TrueView LiDAR in UK drone market

Aerospace Defence Security

GeoCue partners with Coptrz to expand TrueView LiDAR in UK drone market

20 January 2026

UK drone specialists Coptrz have joined forces with GeoCue to offer the complete TrueView LiDAR product range, from entry-level to engineering-grade solutions.

Advertisement
ODU RT
Advertisement
General Atomics LB