Hacked Royal Navy site sinks

The Royal Navy website goes down after a hacker claims to breach site security and reveal usernames and passwords.

Navy

UPDATED The Royal Navy website is currently down after a hacker claimed to have successfully exploited the site and its underlying database.

An attacker going under the web pseudonym TinKode stated in a blog to have compromised the website with an SQL injection attack this weekend.

TinKode claimed to have accessed both usernames and passwords to different sections of the website, although the Royal Navy has refuted the suggestion any classified information was taken.

The Royal Navy admitted the site was compromised, but said no "malicious damage" was caused.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

The website has been suspended as a precaution while security teams investigated, a spokesperson added.

Visitors to www.royalnavy.mod.uk today were greeted by a message reading: "Unfortunately, the Royal Navy website is currently undergoing essential maintenance. Please visit again soon."

TinKode received praise on his blog for his efforts, with one post reading: "TinKode doesn't need sophisticated weapons to disarm an army. He just need a PC."

Another, going by the name Sirarcane, said: "Nice dude, really nice. Good job."

The news comes not long after the Government ranked cyber defence as one of the most important areas of national security, placing it alongside international terrorism and military crises.

The Coalition also recently announced an extra 500 million funding for cyber defence, along with 900 million to go on targeting tax evaders and fraud with better use of technology.

Advertisement - Article continues below

Jason Hart, senior vice president in Europe for two-factor authenticaton provider CRYPTOCard, said the hack had wider implications for the security sphere.

"The fact that a high profile military website can be targeted shows the underlining issues facing organisations and the threat of cyber crime," Hart told IT PRO.

"Fundamentally this shows that the basic forms of attack can still be executed successfully on very secure sites through the simple tools to obtain the username and password."

Graham Cluley, senior technology consultant for Sophos, labelled the hack "embarrassing."

Advertisement
Advertisement - Article continues below

"If someone with more malice in mind had hacked the site they could have used it to post malicious links on the Navy's JackSpeak blog, or embedded a Trojan horse into the site's main page," Cluley said in a blog.

"It is to be hoped that the extent of this attack will be egg on the face of the Ministry of Defence, rather than a more significant assault on a website presenting the public face of an important part of the armed forces."

Featured Resources

What you need to know about migrating to SAP S/4HANA

Factors to assess how and when to begin migration

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

Best practices for implementing security awareness training

How to develop a security awareness programme that will actually change behaviour

Download now
Advertisement

Recommended

Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/policy-legislation/data-governance/354496/brexit-security-talks-under-threat-after-uk-accused-of
data governance

Brexit security talks under threat after UK accused of illegally copying Schengen data

10 Jan 2020
Visit/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
Visit/operating-systems/microsoft-windows/354526/memes-and-viking-funerals-the-internet-reacts-to-the
Microsoft Windows

Memes and Viking funerals: The internet reacts to the death of Windows 7

14 Jan 2020
Visit/network-internet/broadband/354530/openreach-offers-free-full-fibre-installation-for-thousands-of
broadband

Openreach offers free full-fibre installation for thousands of homes

14 Jan 2020