Scottish Parliament hit with 'brute force' cyber attack
The attack is thought to mirror the hack on Westminster in June

The Scottish parliament has been hit by a "brute force" cyber attack according to an internal memo, an attack that was almost identical to the one that hit Westminster's email system in June.
Holyrood officials were warned on Tuesday that hackers had repeatedly tried to break past authentication screens to internal accounts by entering random passwords, although there has been no evidence that the attack succeeded.
An internal memo, issued by Holyrood chief executive Sir Paul Grice and seen by the Guardian, warned that the attack may have resulted in MPs and staff being locked out of their email accounts.
"This attack appears to be targeting parliamentary IT accounts in a similar way to that which affected the Westminster parliament in June. Symptoms of the attack include account lockouts or failed log-ins," wrote Grice.
He added that the parliament's "robust cyber security measures" were able to identify the attack early, and that additional security safeguards were deployed before accounts were compromised.
However, he also said that a sweep of email accounts found that many officials were using passwords that were too weak and easily bypassed.
Following the cyber attack against Westminster email accounts in June, in which only 1% of accounts were reportedly accessed, it is likely Holyrood was on high alert in the event of a similar attack.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Jon Geater, CTO of Thales E-security, said that public bodies need to be treating cyber security as something more than a box-ticking exercise. "This latest brazen attempt to access sensitive information shows that no holds are barred in this fight: even guessing of information is on the table, and, if it fails, it will still lock out users and cause havoc."
"With such crippling effects to a government's bottom line and public reputation, the risk of falling victim to a severe cyber attack is without doubt depriving today's business leaders of much-needed sleep," added Geater. "A watertight data security and encryption strategy to ensure data privacy is now an indispensable element of an organisation's wider cyber security strategy."
Early investigation reports suggested that Russia could have been behind the attack on the UK Parliament, and although it is currently unclear who was responsible for yesterday's attempted hack, it deployed the exact same brute force methods to bypass weak passwords.
Image: Bigstock
Dale Walker is a contributor specializing in cybersecurity, data protection, and IT regulations. He was the former managing editor at ITPro, as well as its sibling sites CloudPro and ChannelPro. He spent a number of years reporting for ITPro from numerous domestic and international events, including IBM, Red Hat, Google, and has been a regular reporter for Microsoft's various yearly showcases, including Ignite.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
JD Sports details cyber security revamp following January attack
News It hopes a multi-vendor approach will substantially improve its cyber resilience
By Connor Jones Published
-
96% of CISOs without necessary support to maintain cyber security
News Security professionals are leaving due to stress, and called out lack of understanding from co-workers
By Rory Bathgate Published
-
Employees behaving badly?
Whitepaper Why awareness training matters
By ITPro Published
-
Freshworks CISO Jason Loomis embraces the ‘shift left’ amid surging supply chain threats
Case Studies Fewer than 100 days in the role, Jason Loomis reveals his plans for the future of security at Freshworks, and discusses the rising threat of API vulnerablities
By Ross Kelly Published
-
CISOs reveal secrets to pandemic success in critical organisations
News The pandemic presented unique challenges for every business, but organisations tasked with delivering critical services may have worked the hardest
By Connor Jones Published
-
Almost 70% of CISOs expect a ransomware attack
News Many companies are willing to make ransomware payments in the face of the growing threat
By Danny Bradbury Published
-
CISOs aren’t leading by example when it comes to cyber security
News Cyber security leaders engage in risky online behavior, according to a survey
By Rene Millman Published
-
Panel Profile: Moonpig head of cyber security Tash Norris
IT Pro Panel We get face-to-face with one of the IT Pro Panellists
By IT Pro Published