Featured Article

Meet the prolific Russian espionage crew hacking spymasters and lawmakers

The hack-and-leak gang claims a British politician as its latest victim

Comment

a view through the tall black gates surrounding the U.K. Parliament with a shot of Elizabeth Tower (with the Big Ben bell inside) in the distance. A sign reads, "No entry for general public."
Image Credits: Scott Barbour (opens in a new window) / Getty Images

A notorious hacking group with alleged ties to Russian intelligence services has claimed its latest victim: British lawmaker Stewart McDonald.

McDonald, a member of Parliament for his constituency in Glasgow South, told BBC News that he fears he had been the victim of a “disinformation” campaign after his personal email account was “hacked by Russia.” McDonald said the hackers sent a document purporting to include a military update on Ukraine, but when opened contained a phishing page that tricked him into entering his email address and password.

The intrusion is believed to be linked to the prolific “Seaborgium” hacking group, also referred to as “Cold River” and “Calisto.”

Seaborgium may not be as well known as Russia’s Fancy Bear or Sandworm hackers, but it is rapidly making a name for itself. The U.K. government has warned of the group’s “ruthless” attempts to pursue its victims, and security researchers say the gang’s growing list of targets — including politicians, defense and government organizations — suggests Seaborgium is closely tied to the Russian state.

Who is Seaborgium?

The Seaborgium hacking group has been active since at least 2017 and is known for conducting long-running cyber espionage campaigns against NATO countries, particularly the U.S. and the United Kingdom, but also further afield as the Baltics, the Nordics and Eastern Europe.

Microsoft’s Threat Intelligence Center, or MSTIC, which has tracked the group since its inception, assesses that Seaborgium is a Russia-based group with “objectives and victimology” that align closely with Russian state interests.

“While we cannot rule out that supporting elements of the group may have current or prior affiliations with criminal or other non-state ecosystems, MSTIC assesses that information collected during Seaborgium intrusions likely supports traditional espionage objectives and information operations as opposed to financial motivations,” Microsoft researchers said.

French threat intelligence startup Sekoia.io, which tracks the group as “Calisto,” said in December that while there is an absence of technical evidence linking Seaborgium to known Russian hacking groups, it found that the hacking group “contributes to Russian intelligence collection about identified war crime-related evidence and/or international justice procedures.”

Who does Seaborgium target?

Seaborgium has historically targeted sectors including academia, defense, governmental organizations, NGOs and think tanks, as well as politicians, journalists and activists.

In May 2022, Google’s Threat Analysis Group, which tracks Seaborgium as “Cold River,” attributed a hack-and-leak operation that saw a trove of emails and documents stolen and leaked from high-level Brexit proponents, including Sir Richard Dearlove, the former head of the U.K. foreign intelligence service MI6. The stolen documents were spread on social media to amplify a false narrative that Brexit proponents were behind a conspiracy to oust a then-sitting prime minister.

In January, it was revealed that Seaborgium also targeted scientists at three U.S. nuclear research labs — Brookhaven, Argonne and Lawrence Livermore Laboratories — last year.

Microsoft’s threat intelligence unit MSTIC says it has also seen Seaborgium targeting Ukraine’s government sector in the months leading up to Russia’s invasion in February 2022, along with organizations involved in supporting roles for the war in Ukraine. Seaborgium has targeted former intelligence officials, experts in Russian affairs and Russian citizens abroad, suggesting the hacking group is also involved in domestic surveillance.

Microsoft said some 30% of Seaborgium activity targets personal email accounts.

What are Seaborgium’s motives?

The main goal of Seaborgium’s intrusions — which typically impersonate real people and use phishing lures with the aim of stealing a victim’s email account password — are for espionage and information operations. That’s when stolen information is strategically leaked to shape narratives in specific countries for certain reasons. Microsoft researchers say the group is unlikely to be financially motivated.

The U.K.’s National Cyber Security Center, which acts as the U.K.’s technical authority on cyber threats, said in a recent advisory that Seaborgium tends to select its targets based on the perceived level of their access to information of interest to the hackers, such as politicians, journalists and activists.

In a statement to TechCrunch, an NCSC spokesperson said it was investigating the incident involving the compromise of McDonald’s email account. “An incident has been reported to us and we are providing the individual with support,” said the spokesperson, who did not provide a name. “The NCSC regularly provides security briefings and guidance to parliamentarians to help them defend against the latest cyber threats. This includes expert advice for MPs and their staff available on the NCSC website.���

McDonald and the SNP did not respond to TechCrunch’s questions.

Read more:

More TechCrunch

Amazon has released an all-new version of its Echo Spot ahead of Prime Day, the company announced on Monday. The 2024 version of the Alexa-enabled smart alarm clock costs $79.99,…

Amazon revives its Echo Spot with an upgraded look and improved audio

One of the vendors to benefit from the database boom is Tembo, a startup creating a platform that lets developers deploy different flavors of Postgres.

Tembo capitalizes on the database boom and lands new cash to expand

TechCrunch Disrupt 2024 is set to welcome an impressive lineup of judges for the Startup Battlefield 200 competition, presented this year by Google Cloud. These judges will decide which company…

Mayfield’s Navin Chaddha is coming to TechCrunch Disrupt 2024

Numerous concerns are weighing on the minds of many, whether it’s current global conflicts, climate change or the precarious state of the economy, it is no surprise that the world…

Art therapy app Scribble Journey lets you express emotions through doodles

Pestle addresses the common problem of finding recipes on the web.

Pestle’s app can now save recipes from Reels using on-device AI

These efforts have come as Lucid is looking to start building its Gravity SUV by the end of this year.

Lucid Motors sets new record for EV deliveries as it seeks ‘escape velocity’

Berlin-based food delivery giant Delivery Hero has warned investors it may “ultimately” face an antitrust fine of up to €400 million. The development, reported earlier by Reuters, follows unannounced raids…

Delivery Hero warns it could face €400M antitrust fine

Featured Article

Investors chase wealth tech startups in India as affluent class grows

The high-net-worth and ultra-high-net-worth segments are booming in India, prompting some wealth management firms to aggressively expand their relationship manager networks to capture this market.

16 hours ago
Investors chase wealth tech startups in India as affluent class grows

Featured Article

Seed VCs are turning to new ‘pro rata’ funds that help them compete with the big firms

Three companies with new funds deploy capital to support seed and Series A VCs looking to exercise their pro rata rights.

21 hours ago
Seed VCs are turning to new ‘pro rata’ funds that help them compete with the big firms

Here are the latest companies venturing into the gaming scene and details about each offering, including pricing, examples of titles and supported devices. 

YouTube and LinkedIn have games now, and here’s how you can play them

Featured Article

CIOs’ concerns over generative AI echo those of the early days of cloud computing

CIOs trying to govern generative AI have the same concerns they had about cloud computing 15 years ago, but they’ve learned some things along the way.

1 day ago
CIOs’ concerns over generative AI echo those of the early days of cloud computing

It sounds like the latest dispute between Apple and Fortnite-maker Epic Games isn’t over. Epic has been fighting Apple for years over the company’s revenue-sharing requirements in the App Store.…

Epic Games CEO promises to ‘fight’ Apple over ‘absurd’ changes

As deep-pocketed companies like Amazon, Google and Walmart invest in and experiment with drone delivery, a phenomenon reflective of this modern era has emerged. Drones, carrying snacks and other sundries,…

What happens if you shoot down a delivery drone?

A police officer pulled over a self-driving Waymo vehicle in Phoenix after it ran a red light and pulled into a lane of oncoming traffic, according to dispatch records. The…

Waymo robotaxi pulled over by Phoenix police after driving into the wrong lane

Welcome back to TechCrunch’s Week in Review — TechCrunch’s newsletter recapping the week’s biggest news. Want it in your inbox every Saturday? Sign up here. This week, Figma CEO Dylan…

Figma pauses its new AI feature after Apple controversy

We’ve created this guide to help parents navigate the controls offered by popular social media companies.

How to set up parental controls on Facebook, Snapchat, TikTok and more popular sites

Featured Article

You could learn a lot from a CIO with a $17B IT budget

Lori Beer’s work is a case study for every CIO out there, most of whom will never come close to JP Morgan Chase’s scale, but who can still learn from how it goes about its business.

2 days ago
You could learn a lot from a CIO with a $17B IT budget

For the first time, Chinese government workers will be able to purchase Tesla’s Model Y for official use. Specifically, officials in eastern China’s Jiangsu province included the Model Y in…

Tesla makes it onto Chinese government purchase list

Generative AI models don’t process text the same way humans do. Understanding their “token”-based internal environments may help explain some of their strange behaviors — and stubborn limitations. Most models,…

Tokens are a big reason today’s generative AI falls short

After multiple rejections, Apple has approved Fortnite maker Epic Games’ third-party app marketplace for launch in the EU. As now permitted by the EU’s Digital Markets Act (DMA), Epic announced…

Apple approves Epic Games’ marketplace app after initial rejections

There’s no need to worry that your secret ChatGPT conversations were obtained in a recently reported breach of OpenAI’s systems. The hack itself, while troubling, appears to have been superficial…

OpenAI breach is a reminder that AI companies are treasure troves for hackers

Welcome to Startups Weekly — TechCrunch’s weekly recap of everything you can’t miss from the world of startups. Sign up here to get it in your inbox every Friday. Most…

Space for newcomers, biotech going mainstream, and more

Elon Musk’s X is exploring more ways to integrate xAI’s Grok into the social networking app. According to a series of recent discoveries, X is developing new features like the…

X plans to more deeply integrate Grok’s AI, app researcher finds

We’re about four months away from TechCrunch Disrupt 2024, taking place October 28 to 30 in San Francisco! We could not bring you this world-class event without our world-class partners…

Meet Brex, Google Cloud, Aerospace and more at Disrupt 2024

In its latest step targeting a major marketplace, the European Commission sent Amazon another request for information (RFI) Friday in relation to its compliance under the bloc’s rulebook for digital…

Amazon faces more EU scrutiny over recommender algorithms and ads transparency

Quantum Rise, a Chicago-based startup that does AI-driven automation for companies like dunnhumby (a retail analytics platform for the grocery industry), has raised a $15 million seed round from Erie…

Quantum Rise grabs $15M seed for its AI-driven ‘Consulting 2.0’ startup

On July 4, YouTube released an updated eraser tool for creators so they can easily remove any copyrighted music from their videos without affecting any other audio such as dialog…

YouTube’s updated eraser tool removes copyrighted music without impacting other audio

Airtel, India’s second-largest telecom operator, on Friday denied any breach of its systems following reports of an alleged security lapse that has caused concern among its customers. The telecom group,…

India’s Airtel dismisses data breach reports amid customer concerns

According to a recent Dealroom report on the Spanish tech ecosystem, the combined enterprise value of Spanish startups surpassed €100 billion in 2023. In the latest confirmation of this upward trend, Madrid-based…

Spain’s exposure to climate change helps Madrid-based VC Seaya close €300M climate tech fund

Forestay, an emerging VC based out of Geneva, Switzerland, has been busy. This week it closed its second fund, Forestay Capital II, at a hard cap of $220 million. The…

Forestay, Europe’s newest $220M growth-stage VC fund, will focus on AI