CSIDB logo
Incident

Scottish Parliament

Incident posture

Attack window
Aug 2017
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2025-12-01 00:00

Linked entities

Victim
Scottish Parliament
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2017
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Scottish Parliament was targeted by a brute force cyber attack originating from external sources, mirroring a similar incident that previously affected Westminster. Robust security measures enabled early detection, preventing operational disruptions to IT systems, though users experienced account lockouts and failed login attempts. Officials urged members and staff to strengthen passwords, with the IT team enforcing mandatory changes for weak credentials as an additional safeguard. This incident followed recent independent reviews affirming the parliament’s cybersecurity readiness and ongoing consultations with law enforcement and national security agencies to mitigate such threats.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Scottish Parliament experienced a brute force cyber attack on or around August 14, 2017, as confirmed by Chief Executive Sir Paul Grice in an email notification to Members of the Scottish Parliament (MSPs) and staff. The attack originated from external sources and targeted parliamentary IT accounts through repeated password guessing attempts, mirroring the method used against the Westminster Parliament in June 2017. Parliament monitoring systems detected the attack during its early stages, with symptoms including account lockouts and failed login attempts. Robust cybersecurity measures prevented system compromise, and no operational disruptions occurred. Officials invoked pre-established security protocols in response, while maintaining normal IT functionality throughout the incident.

The attack prompted immediate security advisories to parliamentary account holders, emphasizing password strength requirements. The IT team enforced mandatory password changes for weak credentials as an additional safeguard. This incident followed a May 2017 cyber attack affecting Scottish NHS boards, which had previously elevated cybersecurity discussions at Holyrood. Parliament officials cited a June 2017 independent review that validated existing cyber defenses, describing them as "sufficient and effective" for threat management. Regular consultations with law enforcement, security agencies, and the National Cyber Security Centre formed part of the institution's security framework. No data breaches or persistent system compromises were reported as direct consequences of this specific attack.

Sources

Sources available to members: 1 source.

CSIDB