CSIDB logo
Incident

Manchester, England, United Kingdom

Incident posture

Attack window
Apr 2025
Location
United Kingdom
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 11:15

Linked entities

Victim
Manchester, England, United Kingdom
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

On a Tuesday morning, cyber criminals hijacked the verified X account of a senior UK government minister based in Manchester Central, using it to promote a fraudulent "House of Commons" cryptocurrency token. The hackers posted misleading content featuring the official Parliament logo, describing the coin as a community-driven digital currency, before the posts were quickly deleted and the account secured. Security researchers identified the scheme as a classic pump-and-dump operation, noting roughly 34 transactions generated approximately £225 in profit before the token collapsed. The incident follows similar recent X account takeovers targeting high-profile public figures, including a BBC journalist whose account was compromised via a phishing email.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On the morning of Tuesday, 15 April 2025, the verified X account belonging to Lucy Powell, the Member of Parliament for Manchester Central and Leader of the House of Commons, was compromised by unknown attackers who used it to promote a fraudulent cryptocurrency. The account, which carried the blue verification mark and listed Powell's cabinet position in its biographical information, was used to publish a series of posts that have since been deleted. Those posts described a digital token called "$HCC" and presented it as "a community-driven digital currency bringing people's power to the blockchain," an apparent attempt to lend the scheme an air of official legitimacy by associating it with the House of Commons. At least some of the messages included an image of the House of Commons logo, reinforcing the false impression that the token was connected to Parliament itself. Powell, who was appointed to her government role after Labour came to power in the summer of 2024, has nearly 70,000 followers on the platform, giving the unauthorised posts significant reach before they were removed.

The posts represented a textbook example of the "pump and dump" model of cryptocurrency fraud. According to Luke Nolan, a senior research associate at the digital-asset management firm CoinShares, the people behind the coin sought to inflate its value, draw in outside buyers, and then sell off their holdings for profit, leaving later investors with worthless tokens. Nolan noted that only 34 transactions were recorded on the coin, generating an estimated profit of around £225 for those responsible, a relatively small return that nonetheless illustrated the mechanics of the scheme. Cyber criminals commonly carry out such attacks by taking over high-profile social media accounts through phishing emails containing malicious links that either harvest credentials directly or trick users into revealing their passwords, and they also frequently rely on credentials leaked in earlier data breaches. Once an account is in their control, the attackers can move quickly, drafting and publishing posts that promote hastily created crypto tokens that can be spun up and launched in only a couple of hours.

Powell's office confirmed the intrusion and stated that her account had been hacked on the Tuesday morning, adding that "steps were taken quickly to secure the account and remove misleading posts." The swift action limited the duration for which the fraudulent content remained visible to the public, though the posts had already circulated among her tens of thousands of followers before being taken down. A House of Commons spokesman responded to the incident by saying that "UK Parliament takes cyber security extremely seriously" and that the institution "provide[s] advice to users - including Members - to make them aware of the risks and how to manage their digital safety; however, we do not comment on specific details of our cyber security policies." The statement stopped short of describing any technical details of the breach or the specific measures used to restore control of the account.

The incident formed part of a broader pattern in which high-profile accounts belonging to public figures have been hijacked to advertise scam tokens. Earlier in 2025, BBC journalist Nick Robinson, who presents the Radio 4 Today programme, had his own X account compromised in a similar manner. Robinson later said that the breach occurred after he clicked on an email he had wrongly believed to have been sent by the social media platform itself, after which posts appeared on his account claiming that he was launching a cryptocurrency called "$Today." The recurrence of the tactic against figures in British politics and journalism underscored how account takeovers had become a favoured vector for this style of fraud. Action Fraud reported that 2024 saw a notable rise in reports of hacked social media and email accounts, with 35,343 such cases recorded over the year, reflecting the scale of the wider problem beyond the single incident involving Powell.

The Office of Lucy Powell, MP for Manchester Central, did not disclose publicly how the attackers obtained access to her credentials, and it is not known from the available reporting whether the compromise resulted from a phishing attempt, a reused password exposed in a prior data breach, or another method altogether. The episode nevertheless demonstrated the speed with which cyber criminals are able to weaponise trusted political platforms for financial fraud, and the reliance on the visibility and perceived authority of verified accounts to lure victims. The fraudulent posts were eventually removed, control of the account was restored, and normal use of the platform by Powell resumed, with no further unauthorised content reported in the immediate aftermath. The House of Commons maintained its general position that it does not comment on the specifics of its cyber security policies, even as the incident drew attention to the risks faced by senior public office holders and the continuing exploitation of social media accounts to push scam cryptocurrencies.

Sources

Sources available to members: 1 source.

CSIDB