Leaked U.S.-UK Trade Documents Show How Devastating Compromised Email Can Be



iStock-1148931787An ongoing criminal investigation highlights how classified documents stolen by Russian hackers from former U.K. trade minister Liam Fox may have been used to impact the British 2019 election.

Late last year, these trade documents were leaked and disseminated online by a Russian disinformation campaign. The new addition to this story, according to Reuters, is that then-trade minister Fox’s email account had been hacked as part of that campaign. According to sources, state-run Russian hackers accessed Fox’s email account “multiple time between July 12 and Oct. 21 last year.”

There are no formal details on how his email account was compromised (although one anonymous source points towards a spear phishing attack), but I can take a few guesses:

  1. He was the victim of a credential theft attack where the impersonation of his email platform was used to obtain his logon credentials.
  2. He was the victim of a malware attack (usually via phishing) where a remote access trojan was installed on one of his devices to monitor keystrokes (which would include logging onto his email)
  3. His email account credentials are known to members of his staff and they were the victim of either 1 or 2 above.

The impact of the data theft that resulted from the compromised email account included Britain’s opposition Labour Party using details within the leaked documents during the election campaign. The documents reportedly showed a government plan to sell the U.K. National Health Service to the United States, which has been denied repeatedly by Prime Minister Boris Johnson.

A simple phishing campaign targeting the right person can have adverse effects beyond the individual, hurting the organization and, in this case, well-beyond.

It’s imperative that organizations look to shore up email and web-based security, as well as utilize Security Awareness Training as a means of educating the everyday user (all the way up to trade ministers, CEOs, etc.) on how to spot phishing and social engineering attacks in order to keep something far more malicious from happening.


Find out which of your users' emails are exposed before bad actors do.

Many of the email addresses and identities of your organization are exposed on the internet and easy to find for cybercriminals. With that email attack surface, they can launch social engineering, spear phishing and ransomware attacks on your organization. KnowBe4's Email Exposure Check Pro (EEC) identifies the at-risk users in your organization by crawling business social media information and now thousands of breach databases.

EECPro-1Here's how it works:

  • The first stage does deep web searches to find any publicly available organizational data
  • The second stage finds any users that have had their account information exposed in any of several thousand breaches
  • You will get a summary report PDF as well as a link to the full detailed report
  • Results in minutes!

Get Your Free Report

PS: Don't like to click on redirected buttons? Cut & Paste this link in your browser:

https://www.knowbe4.com/email-exposure-check/



Subscribe to Our Blog


Comprehensive Anti-Phishing Guide




Get the latest about social engineering

Subscribe to CyberheistNews