Hackers targeted Covid-19 vaccine 'cold supply' chain network

3 December 2020, 12:14 | Updated: 3 December 2020, 14:56

The cyber attack targeted the vaccine 'cold chain'
The cyber attack targeted the vaccine 'cold chain'. Picture: PA

By Maddie Goodfellow

Hackers have targeted companies vital to the 'cold chain' distribution of the Covid-19 vaccine.

According to an alert issued by the US government and a research blog published by IBM, the campaign to attack the companies started in September.

Organisations associated with the 'cold chain' including governments, energy companies and the IT sector have all been targeted.

The 'cold chain' is an essential part of distributing vaccines manufactured by Pfizer/BioNTech, which was approved for use in the UK on Tuesday, as they needs to be stored at -70C to avoid spoiling before being administered.

Although it has not been announced if the sophisticated phishing emails were successful, IBM warned that the campaign bore "the potential hallmarks of nation-state tradecraft" rather than an attack by cyber criminals.

"Without a clear path to a cash-out, cyber criminals are unlikely to devote the time and resources required to execute such a calculated operation with so many interlinked and globally distributed targets," said IBM.

Lorries packed with coronavirus vaccine leave Pfizer's factory

The emails were sent to 10 organisations, including the European Commission's Directorate-General for Taxation and Customs Union, which handles tax and customs issues across the EU, a South Korean software-development company and a German website-development company.

Claire Zaboeva, an IBM analyst involved in the detection, said the agency "would be a gold mine" for hackers seeking to access other organisations.

The hackers sent phishing emails impersonating a business executive from the Chinese company Haier Biomedical, which is "a credible and legitimate member company of the COVID-19 vaccine supply chain" according to IBM.

The intention of the campaign "was to harvest credentials possibly to gain future unauthorised access to corporate networks and sensitive information relating to the COVID-19 vaccine distribution", IBM said.

IBM says it has notified those targeted as well as law-enforcement authorities.

Pfizer UK boss: Vaccine approval 'incredible moment'

The US's Cybersecurity and Infrastructure Security Agency (Cisa) has issued an alert encouraging organisations associated with the storage and transport of a vaccine to be on guard for the kind of attacks linked to IBM's report.

It comes after the UK warned Russian intelligence had targeted UK vaccine research, including at Oxford, back in July.

The US also warned of Chinese hacking, while, more recently, Microsoft said it had seen North Korean and Russian hackers targeting vaccine research.

Officials suggested the activity so far had been about intelligence gathering rather than disruption of any research.

Covid Vaccine: Your Questions Answered 2

Dr Daniel Prince, Senior Lecturer in Cyber Security at Lancaster University, told LBC that we don't know the exact motives of this attack yet but it shows the UK "needs to be able to defend itself in cyber space".

"Effectively, it’s a fraud, somebody has pretended to be from a very large Chinese company that works within the cold store supply chain and has sent phishing emails out to suppliers," he explained.

"In the emails, there is a malicious piece of software that captures the usernames and passwords on those systems. The person who has sent those original emails can then harvest the emails and access the company remotely."

Speaking about the impact this kind of attack could have on the vaccine supply, Dr Prince said: "In terms of specifically on the vaccine at this initial stage there is not a lot of risk, but depending on the companies that are targeted, hackers could potentially steal information about the vaccine.

"This targeted the supply chain, such as companies making solar panels and supplying website services, but governments have previously said that groups have been targeting the manufacturers of the vaccine.

"Their systems could therefore be compromised if the hackers get access to other companies in the supply chain."

Asked about the motives behind this attack, Dr Prince explained: "If it is a criminal gang, they will want financial rewards and could pretend to be someone in the company to get this.

"This is thy they are presenting the email as being from a company that people trust, it puts pressure on people.

"Hackers know everyone is concerned about Covid, so it gives a pressure point for hackers to exploit by pretending to do something good for the supply chain. People's guard may be down and they may not do the proper checks - giving hackers a way in."

He continued: "If it was a Nation State, as has been suggested, those type of attacks usually use the company as a stepping stone to get into interesting areas.

"Hackers will see supply chain as one of the weakest links and outside of the control of the vaccine companies, so if the supply chain is not very secure and interacts with these companies then that increases the risk to the vaccine.

"In effect, targeting the supply chain and support services could be seen as a mechanism to get hold of the vaccine."

However, Dr Prince did explain that there is no concrete evidence that this attack was conducted by a nation state or is connected to the Russian attack in July.

Asked what the aim of this attack could be, Dr Prince said: "At this stage we don’t know what the ultimate goal is but it provides clear rationale for the UK's national cyber force which the government has set up.

"We need to defend ourselves in cyber space and online security needs to be embedded in company policy as it is such a fundamental part of day to day life now."

More Latest News

See more More Latest News

England fans reported a 'heavy-handed' approach from Greek police.

FA launches investigation as England fans report 'heavy-handed policing and tear gas' before Greece clash

Prince William was met with boos as he left Ulster University on Thursday.

Prince William booed by 'pro-Palestine' protestors during Belfast visit

The grandmother said she was hauled off a flight after a row over a sandwich

Grandmother, 79, 'hauled off a Jet2 flight by armed officers for refusing to pay £9 for a frozen tuna bap'

Exclusive
Sam Eljamel's victims have called for justice

'There has to be a day of reckoning': Patients left disabled and injured by rogue surgeon demand extradition from Libya

The fire broke out at a nursing home

At least ten dead and more injured in fire at Spanish nursing home

Exclusive
Feargal Sharkey and LBC tested the River Colwill

UK's biggest water company fails three environmental tests carried out by Feargal Sharkey and LBC

Rachel Reeves confirmed the tax hike in her autumn Budget

Rachel Reeves 'not satisfied' as UK growth slows between July and September

Trump continues to name his cabinet

Trump’s controversial Cabinet - Anti-vax RFK Jr nominated as health chief as defence figures ‘alarmed’ by Gabbard

Portrait Of Shel Talmy

Music producer Shel Talmy, who worked with The Who and David Bowie, dies aged 87

Exclusive
Lillington Gardens in Pimlico has won multiple awards for its design but residents' lives are being affected by damp and mould

Mould, leaks and collapsing roofs: Inside Britain’s ‘best council estate’

Metropolitan Police officers walking a beat on patrol in Fulham, London

Child, 9, among kids investigated by police for hate ‘incidents’ after calling classmate ‘r****d’

South Yorkshire Police Headline Image

Elderly woman in life-threatening condition after prison transport vehicle collides with pedestrians

c

Chancellor sets out financial reforms in key speech as she criticises measures brought in after 2008 economic crash

Holidaymakers Begin Christmas Getaway

More than 700,000 passengers suffered delays after password of engineer allowed to work remotely didn't work

Weather maps show areas of the UK which could be hit by snow

UK weather maps show regions expected to see heavy snowfall as cold and wintry spell on the way

Cynthia Erivo

Wicked star Cynthia Erivo says feeling like an outsider and 'not fitting in' drew her to role of Elphaba