NCSC CEO Richard Horne: Hostile States Linked to Three-Quarters of Cyber Attacks on UK Critical National Infrastructure

NCSC CEO Richard Horne (TL-2026-2239) is a medium-severity tracked intrusion set, first published 2026-06-17. It is attributed to China (Russia, China, Iran) with medium confidence, affects UK Critical National Infrastructure operators 20 CNI sectors, references 1 CVE (CVE-2021-22681), maps to 14 MITRE ATT&CK techniques (T0819, T1003, T1005), and is covered by 9 detection rules and 13 indicators of compromise.

Key facts for TL-2026-2239

Threat ID
TL-2026-2239
Severity
MEDIUM
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-06-17
Last reviewed
2026-06-17
Attribution
China
Attribution confidence
MEDIUM
Nation-state nexus
Russia, China, Iran
Motivation
ESPIONAGE
Target sectors
manufacturing, water and wastewater, power generation, energy, communications, transport, government administration
Target regions
united kingdom, united states of america, ireland, canada, australia, Europe
Detection rules
9
Indicators of compromise
13

Malware and tooling in NCSC CEO Richard Horne

Malware and tooling: AnyDesk, Cyclops Blink, IOCONTROL, TeamViewer, AnyDesk, Mimikatz, TeamViewer

At the RUSI Annual Security Lecture on 17 June 2026, NCSC CEO Dr Richard Horne stated that 75% of the 200+ cyber incidents the NCSC managed against UK critical national infrastructure in the year to May 2026 were linked to hostile state actors (Russia, China, Iran), and warned that by 2028 AI-enabled capabilities will likely be used to exploit known vulnerabilities in legacy CNI technology at scale.

How NCSC CEO Richard Horne works

On 17 June 2026, NCSC CEO Dr Richard Horne delivered the RUSI Annual Security Lecture in London, marking the ten-year anniversary of the UK's National Cyber Security Centre. He disclosed that the NCSC managed over 200 cyber incidents affecting UK critical national infrastructure (CNI) and its supporting ecosystem in the year to May 2026, with roughly 75% linked back to hostile state actors. He explicitly named Russia, China, and Iran, framing cyber security not as a manageable risk but as "an ongoing contest with capable adversaries" in which "there are no spectators, we are all on the pitch." Manufacturing, water and wastewater, and power generation together accounted for over 40% of attacks recorded across the 20 UK CNI sectors.

The NCSC statement itself names no specific incident, CVE, or indicator, but each of the three named states has an independently attributed, technically documented campaign pattern against exactly this target set. China's Volt Typhoon has infiltrated US communications, energy, transportation, and water/wastewater networks using living-off-the-land techniques (LOLBins, valid-account abuse, minimal malware) to pre-position for disruptive access, per the CISA/NSA/FBI joint advisory AA24-038A. Iran's CyberAv3ngers (IRGC Cyber-Electronic Command, aka Storm-0784/Bauxite/UNC5691) has repeatedly compromised internet-exposed Unitronics Vision Series PLCs at water utilities across the US, UK, and Ireland via factory-default credentials since at least 2020, and is separately exploiting an unpatched authentication-bypass in Rockwell Automation Logix controllers (CVE-2021-22681, CVSS 9.8). In a near-contemporaneous, independently reported incident, a small UK power generator (a sub-50MW peaker plant) was suspected to have been taken offline for four days in July 2026 by an IRGC-linked actor after an internet-exposed PLC was reprogrammed and its credentials and IP address changed; the NCSC and the Department for Energy Security and Net Zero briefed UK energy CEOs in response. Russia's Sandworm (GRU Unit 74455 / APT44 / Seashell Blizzard), previously exposed by the NCSC and allies for the Cyclops Blink botnet malware and the attempted 2018 attack on the OPCW, has run the near-global "BadPilot" initial-access subgroup campaign since at least 2021, which by 2024 had honed its focus on US, UK, Canada, and Australian victims per Microsoft reporting.

Horne's AI warning ties directly to this pattern: the NCSC assesses it "highly likely" that by 2028, AI-enabled cyber capabilities will be used by attackers against known vulnerabilities in legacy CNI technology at scale, noting frontier AI models are already effective at discovering long-standing code vulnerabilities. Reporting on the suspected July 2026 UK power-generator intrusion described the attacker using AI-generated scripts to scan the internet for exposed PLCs before exploiting default credentials — an early real-world instance of the exact pattern Horne described five weeks earlier.

The speech landed alongside two UK policy developments: the Cyber Security and Resilience (Network and Information Systems) Bill, which reached report stage in the House of Commons by May 2026 and would update the NIS Regulations 2018 covering CNI operators, and the Government's National Cyber Action Plan, published 6 January 2026. It also follows the NCSC's own Annual Review 2025 baseline, which recorded 204 "nationally significant" incidents (up from 89 the prior year) — an average of four per week — out of 429 total incidents requiring NCSC support, with 18 categorised as "highly significant." Horne called on organisational leaders to build three capabilities: understand their threat exposure across new and legacy technology and supply chains, defend using security fundamentals (Cyber Essentials and beyond), and ensure operational continuity and rapid, at-scale recovery after an attack, warning that "many vulnerabilities that organizations tolerate today will be exploited in conflict tomorrow."

MITRE ATT&CK techniques used in TL-2026-2239

Initial Access

T0819 Exploit Public-Facing Application; T1133 External Remote Services; T1190 Exploit Public-Facing Application

Credential Access

T1003 OS Credential Dumping; T1110 Brute Force

Collection

T1005 Data from Local System

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information

Discovery

T1046 Network Service Discovery

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol

Impact

T1485 Data Destruction; T1561 Disk Wipe

Persistence

T1543.002 Systemd Service

Affected products and versions in NCSC CEO Richard Horne

  • UK Critical National Infrastructure operators — 20 CNI sectors, concentrated in Manufacturing, Water and Wastewater, and Power Generation (>40% of recorded attacks)
    Vulnerable versions: all
  • Unitronics — Vision Series PLC
    Vulnerable versions: internet-exposed units with factory-default credentials
  • Rockwell Automation — RSLogix 5000 / Studio 5000 Logix Designer (CompactLogix, ControlLogix, GuardLogix, DriveLogix, SoftLogix)
    Vulnerable versions: RSLogix 5000 v16-20; Studio 5000 Logix Designer v21.0+; FactoryTalk Services Platform v2.10+

Remediation for NCSC CEO Richard Horne

Patches

  • No vendor patch is available for Rockwell Automation RSLogix 5000 (v16-20) / Studio 5000 Logix Designer (v21+) credential-verification bypass (CVE-2021-22681); apply vendor-recommended compensating controls and network isolation.
  • Apply firmware/credential updates to internet-exposed Unitronics Vision Series PLCs and disable default administrative accounts.

Immediate actions

  • Inventory and remove internet-facing exposure of PLCs, HMIs, and OT management interfaces (Unitronics Vision, Rockwell Logix, and similar controllers) — the recurring initial-access vector across the named campaigns.
  • Rotate all factory-default and unchanged administrative credentials on OT/ICS devices and remote-access tools (TeamViewer, AnyDesk) that face the internet.
  • Deploy phishing-resistant MFA on all remote access and management-plane accounts.

Workarounds

  • Where patching or credential rotation is not immediately possible, remove the device from direct internet exposure and require VPN + MFA for any remote OT access.

Longer-term hardening

  • Segment OT/ICS networks from corporate IT with default-deny access control lists and out-of-band management paths.
  • Build sustained network visibility and internal threat-intelligence generation rather than treating detection/response as a project with an end date.
  • Establish rapid at-scale recovery capability (backups, rebuild playbooks) for CNI operational technology, not just IT systems.
  • Track and remediate legacy/unsupported CNI technology on a fixed cadence ahead of the NCSC's AI-enabled exploitation-at-scale timeline (2028).

CVEs associated with NCSC CEO Richard Horne

CVE-2021-22681

Weaknesses (CWE) in NCSC CEO Richard Horne

CWE-522

Timeline of NCSC CEO Richard Horne

  • Sandworm (GRU Unit 74455) attempts a cyber attack against the Organisation for the Prohibition of Chemical Weapons in The Hague; later exposed jointly by the UK and allies.
  • CyberAv3ngers (IRGC Cyber-Electronic Command) begins operating, specializing in breaching internet-exposed industrial PLCs.
  • CyberAv3ngers compromises at least 75 internet-exposed Unitronics Vision Series PLCs across the US, UK, and Ireland by exploiting factory-default passwords, including the Municipal Water Authority of Aliquippa, Pennsylvania.
  • US Treasury sanctions six IRGC Cyber-Electronic Command officials, including Hamid Lashgarian, for the CyberAv3ngers PLC intrusion campaign.
  • Microsoft reports Sandworm's 'BadPilot' initial-access subgroup (Seashell Blizzard) has honed its focus onto US, UK, Canada, and Australian victims after running a near-global campaign since 2021.
  • NCSC Annual Review 2025 reports 204 'nationally significant' cyber incidents in the 12 months to August 2025 (up from 89 the prior year), an average of four per week, out of 429 total incidents requiring NCSC support.
  • UK Government publishes its National Cyber Action Plan alongside the second reading of the Cyber Security and Resilience (Network and Information Systems) Bill.
  • A joint advisory from six US agencies confirms Iranian-affiliated actors are actively exploiting internet-facing PLCs across water and wastewater, energy, and government facility networks.
  • NCSC CEO Dr Richard Horne states at the RUSI Annual Security Lecture that 75% of 200+ CNI-affecting incidents managed in the year to May 2026 are linked to hostile states (Russia, China, Iran), and warns AI will likely enable exploitation of legacy CNI vulnerabilities at scale by 2028.
  • A small UK power generator (sub-50MW peaker plant) is suspected to be taken offline for four days after an internet-exposed PLC is reprogrammed by a suspected IRGC-linked actor; NCSC and DESNZ brief UK energy company CEOs.
  • The National and Security Magazine report publicly on the suspected July 2026 Iranian-linked UK power-generator intrusion, noting reported use of AI-generated scripts to scan for exposed PLCs.

Sources cited for NCSC CEO Richard Horne

More in threat intel

Detection coverage for TL-2026-2239

As of 2026-06-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2239 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats