CSIDB logo
Incident

UK Cabinet Ministers

Incident posture

Attack window
Sep 2015
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2026-08-28 15:04

Linked entities

Victim
UK Cabinet Ministers
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2015
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

British intelligence uncovered an Islamic State espionage operation targeting email accounts of senior government ministers, including the Home Secretary, aiming to access sensitive information about official and Royal family events. The GCHQ investigation revealed ISIS-linked extremists attempted to compromise private ministerial communications, prompting tightened security protocols such as password changes and leading to a drone strike that killed one plot leader. The incident demonstrated the group's evolving cyber capabilities, including recruitment of hackers to target Western entities, consistent with prior breaches of US military social media accounts.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In September 2015, British intelligence agencies revealed that Islamic State (IS) extremists had conducted a cyber espionage campaign targeting the private email accounts of senior UK government ministers. Government Communications Headquarters (GCHQ) investigators discovered that hackers linked to the Islamic State of Iraq and Syria (ISIS) specifically attempted to compromise accounts belonging to high-ranking officials, including then-Home Secretary Theresa May. The operation aimed to access sensitive information about scheduled events involving government figures and members of the British Royal Family. Intelligence indicated that successful breaches could have provided terrorists with details about ministerial movements and public appearances, creating potential physical security risks. The cyber threat first surfaced in security alerts issued to Whitehall officials in May 2015, prompting the GCHQ-led investigation.

The investigation exposed IS plans to attack Britain through cyber infiltration, leading to counterterrorism operations that included a drone strike eliminating at least one plot ringleader. Prime Minister David Cameron publicly referenced this military action shortly before the cyber targeting became public. Security officials mandated enhanced protective measures across government systems, including compulsory password changes for affected accounts. Media outlets had known about the operation months earlier but delayed publication at the government's request while the probe continued. The incident demonstrated IS's development of offensive cyber capabilities, with the group actively recruiting hackers to target Western governments, as evidenced by the January 2015 compromise of US Central Command's social media accounts by a group identifying as the 'CyberCaliphate'.

Sources

Sources available to members: 1 source.

CSIDB