NCSC CEO Richard Horne: Hostile States Linked to Three-Quarters of Cyber Attacks on UK Critical National Infrastructure
NCSC CEO Richard Horne (TL-2026-2239) is a medium-severity tracked intrusion set, first published 2026-06-17. It is attributed to China (Russia, China, Iran) with medium confidence, affects UK Critical National Infrastructure operators 20 CNI sectors, references 1 CVE (CVE-2021-22681), maps to 14 MITRE ATT&CK techniques (T0819, T1003, T1005), and is covered by 9 detection rules and 13 indicators of compromise.
Key facts for TL-2026-2239
- Threat ID
- TL-2026-2239
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-06-17
- Last reviewed
- 2026-06-17
- Attribution
- China
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia, China, Iran
- Motivation
- ESPIONAGE
- Target sectors
- manufacturing, water and wastewater, power generation, energy, communications, transport, government administration
- Target regions
- united kingdom, united states of america, ireland, canada, australia, Europe
- Detection rules
- 9
- Indicators of compromise
- 13
Malware and tooling in NCSC CEO Richard Horne
Malware and tooling: AnyDesk, Cyclops Blink, IOCONTROL, TeamViewer, AnyDesk, Mimikatz, TeamViewer
At the RUSI Annual Security Lecture on 17 June 2026, NCSC CEO Dr Richard Horne stated that 75% of the 200+ cyber incidents the NCSC managed against UK critical national infrastructure in the year to May 2026 were linked to hostile state actors (Russia, China, Iran), and warned that by 2028 AI-enabled capabilities will likely be used to exploit known vulnerabilities in legacy CNI technology at scale.
How NCSC CEO Richard Horne works
On 17 June 2026, NCSC CEO Dr Richard Horne delivered the RUSI Annual Security Lecture in London, marking the ten-year anniversary of the UK's National Cyber Security Centre. He disclosed that the NCSC managed over 200 cyber incidents affecting UK critical national infrastructure (CNI) and its supporting ecosystem in the year to May 2026, with roughly 75% linked back to hostile state actors. He explicitly named Russia, China, and Iran, framing cyber security not as a manageable risk but as "an ongoing contest with capable adversaries" in which "there are no spectators, we are all on the pitch." Manufacturing, water and wastewater, and power generation together accounted for over 40% of attacks recorded across the 20 UK CNI sectors.
The NCSC statement itself names no specific incident, CVE, or indicator, but each of the three named states has an independently attributed, technically documented campaign pattern against exactly this target set. China's Volt Typhoon has infiltrated US communications, energy, transportation, and water/wastewater networks using living-off-the-land techniques (LOLBins, valid-account abuse, minimal malware) to pre-position for disruptive access, per the CISA/NSA/FBI joint advisory AA24-038A. Iran's CyberAv3ngers (IRGC Cyber-Electronic Command, aka Storm-0784/Bauxite/UNC5691) has repeatedly compromised internet-exposed Unitronics Vision Series PLCs at water utilities across the US, UK, and Ireland via factory-default credentials since at least 2020, and is separately exploiting an unpatched authentication-bypass in Rockwell Automation Logix controllers (CVE-2021-22681, CVSS 9.8). In a near-contemporaneous, independently reported incident, a small UK power generator (a sub-50MW peaker plant) was suspected to have been taken offline for four days in July 2026 by an IRGC-linked actor after an internet-exposed PLC was reprogrammed and its credentials and IP address changed; the NCSC and the Department for Energy Security and Net Zero briefed UK energy CEOs in response. Russia's Sandworm (GRU Unit 74455 / APT44 / Seashell Blizzard), previously exposed by the NCSC and allies for the Cyclops Blink botnet malware and the attempted 2018 attack on the OPCW, has run the near-global "BadPilot" initial-access subgroup campaign since at least 2021, which by 2024 had honed its focus on US, UK, Canada, and Australian victims per Microsoft reporting.
Horne's AI warning ties directly to this pattern: the NCSC assesses it "highly likely" that by 2028, AI-enabled cyber capabilities will be used by attackers against known vulnerabilities in legacy CNI technology at scale, noting frontier AI models are already effective at discovering long-standing code vulnerabilities. Reporting on the suspected July 2026 UK power-generator intrusion described the attacker using AI-generated scripts to scan the internet for exposed PLCs before exploiting default credentials — an early real-world instance of the exact pattern Horne described five weeks earlier.
The speech landed alongside two UK policy developments: the Cyber Security and Resilience (Network and Information Systems) Bill, which reached report stage in the House of Commons by May 2026 and would update the NIS Regulations 2018 covering CNI operators, and the Government's National Cyber Action Plan, published 6 January 2026. It also follows the NCSC's own Annual Review 2025 baseline, which recorded 204 "nationally significant" incidents (up from 89 the prior year) — an average of four per week — out of 429 total incidents requiring NCSC support, with 18 categorised as "highly significant." Horne called on organisational leaders to build three capabilities: understand their threat exposure across new and legacy technology and supply chains, defend using security fundamentals (Cyber Essentials and beyond), and ensure operational continuity and rapid, at-scale recovery after an attack, warning that "many vulnerabilities that organizations tolerate today will be exploited in conflict tomorrow."
MITRE ATT&CK techniques used in TL-2026-2239
Initial Access
T0819 Exploit Public-Facing Application; T1133 External Remote Services; T1190 Exploit Public-Facing Application
Credential Access
T1003 OS Credential Dumping; T1110 Brute Force
Collection
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information
Discovery
T1046 Network Service Discovery
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol
Impact
T1485 Data Destruction; T1561 Disk Wipe
Persistence
Affected products and versions in NCSC CEO Richard Horne
- UK Critical National Infrastructure operators — 20 CNI sectors, concentrated in Manufacturing, Water and Wastewater, and Power Generation (>40% of recorded attacks)
Vulnerable versions: all - Unitronics — Vision Series PLC
Vulnerable versions: internet-exposed units with factory-default credentials - Rockwell Automation — RSLogix 5000 / Studio 5000 Logix Designer (CompactLogix, ControlLogix, GuardLogix, DriveLogix, SoftLogix)
Vulnerable versions: RSLogix 5000 v16-20; Studio 5000 Logix Designer v21.0+; FactoryTalk Services Platform v2.10+
Remediation for NCSC CEO Richard Horne
Patches
- No vendor patch is available for Rockwell Automation RSLogix 5000 (v16-20) / Studio 5000 Logix Designer (v21+) credential-verification bypass (CVE-2021-22681); apply vendor-recommended compensating controls and network isolation.
- Apply firmware/credential updates to internet-exposed Unitronics Vision Series PLCs and disable default administrative accounts.
Immediate actions
- Inventory and remove internet-facing exposure of PLCs, HMIs, and OT management interfaces (Unitronics Vision, Rockwell Logix, and similar controllers) — the recurring initial-access vector across the named campaigns.
- Rotate all factory-default and unchanged administrative credentials on OT/ICS devices and remote-access tools (TeamViewer, AnyDesk) that face the internet.
- Deploy phishing-resistant MFA on all remote access and management-plane accounts.
Workarounds
- Where patching or credential rotation is not immediately possible, remove the device from direct internet exposure and require VPN + MFA for any remote OT access.
Longer-term hardening
- Segment OT/ICS networks from corporate IT with default-deny access control lists and out-of-band management paths.
- Build sustained network visibility and internal threat-intelligence generation rather than treating detection/response as a project with an end date.
- Establish rapid at-scale recovery capability (backups, rebuild playbooks) for CNI operational technology, not just IT systems.
- Track and remediate legacy/unsupported CNI technology on a fixed cadence ahead of the NCSC's AI-enabled exploitation-at-scale timeline (2028).
CVEs associated with NCSC CEO Richard Horne
Weaknesses (CWE) in NCSC CEO Richard Horne
CWE-522
Timeline of NCSC CEO Richard Horne
- Sandworm (GRU Unit 74455) attempts a cyber attack against the Organisation for the Prohibition of Chemical Weapons in The Hague; later exposed jointly by the UK and allies.
- CyberAv3ngers (IRGC Cyber-Electronic Command) begins operating, specializing in breaching internet-exposed industrial PLCs.
- CyberAv3ngers compromises at least 75 internet-exposed Unitronics Vision Series PLCs across the US, UK, and Ireland by exploiting factory-default passwords, including the Municipal Water Authority of Aliquippa, Pennsylvania.
- US Treasury sanctions six IRGC Cyber-Electronic Command officials, including Hamid Lashgarian, for the CyberAv3ngers PLC intrusion campaign.
- Microsoft reports Sandworm's 'BadPilot' initial-access subgroup (Seashell Blizzard) has honed its focus onto US, UK, Canada, and Australian victims after running a near-global campaign since 2021.
- NCSC Annual Review 2025 reports 204 'nationally significant' cyber incidents in the 12 months to August 2025 (up from 89 the prior year), an average of four per week, out of 429 total incidents requiring NCSC support.
- UK Government publishes its National Cyber Action Plan alongside the second reading of the Cyber Security and Resilience (Network and Information Systems) Bill.
- A joint advisory from six US agencies confirms Iranian-affiliated actors are actively exploiting internet-facing PLCs across water and wastewater, energy, and government facility networks.
- NCSC CEO Dr Richard Horne states at the RUSI Annual Security Lecture that 75% of 200+ CNI-affecting incidents managed in the year to May 2026 are linked to hostile states (Russia, China, Iran), and warns AI will likely enable exploitation of legacy CNI vulnerabilities at scale by 2028.
- A small UK power generator (sub-50MW peaker plant) is suspected to be taken offline for four days after an internet-exposed PLC is reprogrammed by a suspected IRGC-linked actor; NCSC and DESNZ brief UK energy company CEOs.
- The National and Security Magazine report publicly on the suspected July 2026 Iranian-linked UK power-generator intrusion, noting reported use of AI-generated scripts to scan for exposed PLCs.
Sources cited for NCSC CEO Richard Horne
- NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems
- Richard Horne speaking at the RUSI Annual Security Lecture
- Annual Security Lecture 2026 by Richard Horne, CEO, NCSC
- Hostile States Behind 75% of Cyber-Attacks on UK CNI, NCSC Warns
- Hostile states behind three-quarters of attacks on Britain's critical infrastructure, cyber chief warns
- RUSI Annual Security Lecture 2026, comment
- UK energy alert issued after Iranian cyber attack on power plant
- Iranian Cyberattack Shuts Down UK Power Generator
- PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure (AA24-038A)
- IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities (AA23-335A)
- Iran-Linked CyberAv3ngers Sets Sights on Water Utilities and Industrial Controllers
- Volt Typhoon Explained: Living Off the Land Tactics for Cyber Espionage
- Sandworm Team, ELECTRUM, Telebots, IRON VIKING, BlackEnergy, Voodoo Bear, Seashell Blizzard, APT44 (G0034)
- UK and allies uncover Russian military unit carrying out cyber attacks and digital sabotage for the first time
- UK experiencing four 'nationally significant' cyber attacks every week
More in threat intel
- Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C Domains Surge +771%
- Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass
- China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models
- Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence Group Q3 2026 AI Threat Tracker)
- ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport Manager 12.44 (UAT-10820)
Detection coverage for TL-2026-2239
As of 2026-06-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2239 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.