Connect with us

Infosecurity

Britain wants new powers to quietly blacklist tech suppliers — here’s what it means

Published

on

tech supplier ban

A quiet shift in how Britain polices its tech supply chain

London is moving to give ministers a blunt new tool: the power to quietly cut risky technology vendors out of the country’s most vital industries. And in some cases, the public may never know which company got the boot.

The changes, tucked into amendments to the Cyber Security and Resilience Bill published on Monday, borrow heavily from the legal playbook used to push Huawei out of Britain’s 5G networks. But they strip away several of the transparency safeguards that came with that earlier regime.

Under the current telecoms law, the government must publicly designate a vendor as a security threat before it can act. Not so with these new proposals. Ministers would be able to issue a so-called “vendor-related direction” without naming the supplier publicly, and without even sending the vendor a copy of the order. The company on the receiving end could also be barred from talking about it.

Beyond telecoms: who’s in the crosshairs?

The scope is what makes this different. The powers wouldn’t stop at phone networks. They’d extend to managed service providers, data centers, digital infrastructure, and the energy, water, transport and health sectors.

A senior minister could order a company in any of those areas to stop buying from a specific supplier, restrict how its products are used, or even force the removal of equipment that’s already installed. Think of it as a national security off-switch for the supply chain.

What the government says — and what critics worry about

Liz Lloyd, the recently reappointed cybersecurity minister, framed the powers as a preventive measure. “We can act before a threat materialises, not just after the damage is done,” she said, adding that the goal is to put “national security at the heart of how essential services choose their suppliers.”

But the secrecy provisions are raising eyebrows. While the government would have to publish a notice that a direction had been issued, only the recipient company would be named. The vendor itself could stay anonymous. Details could be withheld on national security or commercial grounds, and anyone consulted before the order — including the vendor — could be gagged from even acknowledging the consultation took place.

Security officials have previously pushed back against similar secret powers in other high-profile cases. When Apple sought to introduce end-to-end encryption for iCloud, officials reportedly described such covert measures as unsustainable and unjustifiable. This new bill seems to lean in the opposite direction.

How it mirrors the Huawei 5G ban — and where it breaks from it

The mechanics will feel familiar to anyone who followed the Huawei saga. The Telecommunications (Security) Act 2021 gave ministers the authority to intervene on national security grounds, which they used to force the Chinese equipment maker out of UK 5G infrastructure.

Both laws share that core premise. But the new bill goes further by allowing ministers to skip the usual step of giving both the affected company and the supplier a chance to respond before an order is issued — if national security demands it.

A partial transparency compromise

There is one nod to openness: the amendments add a publication duty that the telecoms act lacks. The government would have to announce publicly that an order had been issued and identify the recipient. But that notice wouldn’t necessarily reveal which vendor was targeted, and details could still be withheld.

So a water utility, a hospital trust, or a data center operator could be named as having received a direction, while the public is left guessing which supplier triggered the alarm.

The government would also have to report annually to Parliament on how many directions were issued, which sectors were affected, and how many were later varied or revoked. That’s a small accountability window, but it’s something.

Who else could get caught up in this?

Here’s a wrinkle: the powers wouldn’t just apply to companies already regulated as part of critical national infrastructure. Ministers could use regulations to sweep in any person or business they deem to be engaged in essential activity in the UK, or providing essential goods or services. That’s a broad net.

There’s also a layer of bureaucratic control. A company issued a direction would need written government approval before hiring an outside specialist to help it comply. And in deciding whether to grant that approval, ministers could rely on a list of pre-approved specialists published by GCHQ. That’s a notable expansion of the intelligence agency’s role in commercial decisions.

What happens next

The amendments are scheduled for committee stage in the House of Lords in September. That’s where the details will get picked apart — and where critics will likely push for more transparency.

The bill’s trajectory is worth watching. If it passes as drafted, Britain will have a powerful new way to quietly sever ties with risky tech suppliers, but at the cost of a more opaque decision-making process.

For companies operating in critical sectors, the takeaway is clear: supplier choices could soon carry national security implications, and the government may not always tell you why.

For a deeper look at how the UK has handled similar threats, check out our coverage of Huawei’s removal from UK 5G networks and the broader debate over national security and technology supply chains.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

US Sanctions Mabna Institute Hackers as New Iran Crackdown Targets Crypto Wallets

Published

on

Mabna Institute sanctions

Washington Turns the Screws on Tehran’s Cyber Mercenaries

The US Treasury has slapped sanctions on nearly 60 individuals and entities tied to Iran, including five members of the Mabna Institute — a shadowy hacking-for-hire outfit accused of running cyber-espionage campaigns for the regime for over a decade.

The move, announced on August 24 under the banner Operation Economic Outcast, is part of a broader push by Treasury Secretary Scott Bessent to choke off the financial flows that keep Tehran’s destabilizing activities afloat.

These Mabna Institute sanctions are the latest salvo in a long-running cat-and-mouse game between US authorities and Iranian cyber operatives. But this time, there’s a twist: the Treasury’s Office of Foreign Assets Control (OFAC) didn’t just name names. It also froze 30 cryptocurrency addresses linked to four of the defendants, spanning Bitcoin, Ethereum, and TRON.

That’s a significant escalation, and it’s sending ripples through the compliance departments of crypto exchanges worldwide.

The Indictment Behind the Sanctions

Just days earlier, on August 18, the Department of Justice (DoJ) unsealed an indictment against 17 members of the Mabna Institute. The charges paint a picture of a sprawling operation that, since at least 2013, targeted:

  • 144 US-based universities
  • 178 foreign universities
  • At least 42 US-based private sector companies
  • 11 foreign private sector companies
  • Five US federal and state government agencies
  • At least two non-governmental organizations (NGOs)

The scale is staggering. We’re talking about a hacking operation that systematically pillaged intellectual property and sensitive data from over 380 academic institutions across the globe. The DoJ alleges the group worked at the behest of Iran’s Islamic Revolutionary Guard Corps (IRGC), stealing research and credentials to advance the regime’s military and technological ambitions.

Follow the Crypto Trail

Here’s where it gets interesting for the blockchain world. TRM Labs, a blockchain forensics firm, dug into the 30 designated crypto addresses and found roughly $16.8 million sitting in them, dating back to 2018.

Most of that — about $15.5 million — is concentrated in 10 addresses tied to Keyvan Fayaz, also known by aliases like “Achilles,” “The Joker,” and “bc.monster.” TRM Labs suggests Fayaz “may have acted as a treasury of sorts for Mabna’s hacking-for-hire operations.”

Another $1.2 million is linked to 15 addresses associated with Behzad Mesri, a defendant separately charged with hacking HBO. TRM Labs noted that Mesri’s addresses show “a pattern of layered transactions” — hundreds of thousands of dollars ultimately funneled to a deposit address at a large centralized exchange, likely to be cashed out.

“On-chain behavior commonly used to obfuscate source of funds,” the firm observed. In plain English: these guys were trying to wash their crypto, and the blockchain left a trail.

Operation Economic Outcast: A Sector-Wide Blow

But the Mabna Institute sanctions are just one piece of a much larger puzzle. Operation Economic Outcast doesn’t stop at individuals. It also targets entire sectors of the Iranian economy: digital assets, technology, gold, aviation, and shipping.

This is a big deal. The Treasury’s new sectoral determinations expand the categories of Iran-related conduct that can trigger secondary sanctions. In practical terms, OFAC can now go after any person or entity providing services in support of these five sectors.

TRM Labs put it bluntly: “Under the new sectoral determination, any institution that processes a significant transaction for an Iranian exchange or digital assets business in turn risks its access to the US financial system.”

That’s not a threat to be taken lightly. For crypto exchanges, fintechs, and even traditional banks with digital asset exposure, the message is clear: if you touch Iranian money, you’re in the crosshairs.

What This Means for Compliance Teams

For cryptocurrency compliance teams, the immediate takeaway is that screening just for OFAC’s Specially Designated Nationals (SDN) list isn’t enough anymore. The sectoral designations create a web of indirect exposure that requires a more nuanced approach.

TRM Labs advises that compliance teams should be ready to screen for secondary sanctions risk and flag incoming transactions from any wallets with exposure to Mabna Institute wallets. That means monitoring not just the sanctioned addresses themselves, but also any addresses that interact with them.

This is a reminder that the crypto industry’s era of lax oversight is over. The tools exist to trace these funds, and US authorities are using them aggressively. If your exchange processes a transaction from an Iranian entity — even unknowingly — you could lose access to the US financial system.

The Bigger Picture

The timing of these sanctions is no accident. The US has been ratcheting up pressure on Iran across multiple fronts, from nuclear negotiations to regional military posture. Cyber operations against Iran have been a persistent headache for Washington, and this latest move signals that the financial angle is now a primary weapon.

For the Mabna Institute, the sanctions and indictments effectively put a bounty on the heads of its members. They’re now cut off from the global financial system, their crypto wallets frozen, and their ability to operate internationally severely constrained.

Whether that will actually deter Iran’s cyber activities is another question. Hacking-for-hire operations like Mabna are often seen as a low-cost, high-reward tool for state actors. Sanctions can make life difficult, but they rarely stop determined adversaries.

Still, the message from Washington is unmistakable: if you’re going to hack for Iran, you’ll pay a price. And if you’re in the crypto business, you’d better be paying attention.

Continue Reading

Infosecurity

ReliaQuest Fires Back at ShinyHunters: ‘Compromise Claims Are False’

Published

on

ShinyHunters compromise claims

ReliaQuest Denies ShinyHunters Compromise Claims

ReliaQuest has pushed back hard against suggestions that it was breached or hit with ransomware, calling such claims “false.” The threat intelligence firm says a social engineering attack on August 22 briefly exposed its identity dashboard — but nothing more.

The drama began when a member of the notorious ShinyHunters group replied to a ReliaQuest post on X with screenshots of what appeared to be its Okta dashboard, alongside the taunt: “Who’s hunting who?” The exchange was quickly deleted, but the screenshots resurfaced on a ShinyHunters-linked leak site on August 23, according to SOCRadar.

ReliaQuest didn’t stay quiet. In a detailed write-up, the company stated: “Claims that ReliaQuest was compromised or targeted by ransomware are false.”

Anatomy of a Social Engineering Attack

The attack was classic social engineering, the kind that targets people, not firewalls. The threat actor registered a lookalike domain and set up a fake ReliaQuest single sign-on (SSO) page behind a content delivery network. Then came the phone calls.

“The threat actor called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page,” the company explained. “One teammate entered their password and approved the push notification on their phone. That handed the attacker a brief session on our identity dashboard.”

That’s a scary moment for any security team. But ReliaQuest insists the access was “view only.” No applications, systems, or customer data were touched, despite the attacker’s efforts.

Defense in Depth: Why It Worked

ReliaQuest’s response is a masterclass in defense in depth. The company starts from the assumption that someone will eventually get phished. “Phishing works. Even well-trained people can be deceived by a convincing caller who knows a teammate’s name,” the post continued.

Their controls include device trust, which blocks non-ReliaQuest devices from accessing anything, and containment actions that terminated the attacker’s sessions, expired the password, and reset every authentication factor. In other words, the attacker got a glimpse of a dashboard and nothing else.

ShinyHunters: Pressure Tactics or Real Breach?

ShinyHunters is no stranger to high-profile incidents. The group has been linked to major data breaches, including the Ticketmaster data breach and the AT&T data breach. This time, they were the subject of ReliaQuest’s investigation into a new campaign using .claims domains in social engineering attacks.

When ReliaQuest published its findings on August 17, a group member fired back with the dashboard screenshots. But SOCRadar’s analysis backs ReliaQuest’s version of events. “These exchanges illustrate the actor’s pressure tactics and public taunting, but they do not substantiate the breach claim or demonstrate access to ReliaQuest networks,” SOCRadar said.

That’s a key distinction. ShinyHunters is known for turning small wins into big headlines. A brief session on an identity dashboard is not the same as a breach — and it’s certainly not ransomware.

What This Means for Security Teams

This incident is a reminder that social engineering remains one of the most effective attack vectors. A convincing caller, a lookalike domain, and a single password entry — that’s all it takes to get a foothold. The fact that ReliaQuest caught it and contained it quickly is a testament to their controls, but it also shows how easily even security professionals can be fooled.

For organizations, the takeaways are clear:

  • Assume phishing will succeed. Build controls that limit what a compromised account can do.
  • Use device trust and conditional access to block unauthorized devices.
  • Have a rapid containment plan. ReliaQuest terminated sessions and reset credentials immediately.
  • Don’t rely on training alone. Even well-trained employees can be deceived.

ReliaQuest’s response also highlights the importance of transparency. Instead of staying silent, they published a detailed account of what happened, what was accessed, and what wasn’t. That’s the kind of honesty that builds trust — even in the middle of a public spat with a notorious threat group.

The Bottom Line

ShinyHunters may have scored a small victory by getting a teammate to enter a password. But the company’s defenses held. No data was stolen, no systems were accessed, and no ransomware was deployed. The claims of a compromise are, in ReliaQuest’s words, “false.”

Still, this incident is a valuable case study. It shows how social engineering works in practice, and how a well-designed security posture can turn a potential disaster into a minor incident. For anyone in cybersecurity, it’s a reminder that the human element is often the weakest link — and the most important one to protect.

Continue Reading

Infosecurity

Hackers turn Android car head units into proxy botnet nodes

Published

on

Android car systems malware

First documented attack on car head units

Security researchers have uncovered a new malware campaign that targets Android-based car systems, turning them into nodes of a proxy botnet. The discovery, detailed in a report by Kaspersky on Friday, marks the first documented case of malware infecting a car head unit through an attack specifically designed for this type of device.

Head units are the computers and screens built into cars that control navigation, music, Bluetooth, and other features. Previous attacks against such systems typically relied on physical access to the vehicle or vulnerabilities in the operating system.

How the infection works

The malware was found on head units made by DoFun, a Chinese automotive software and hardware provider. Kaspersky traced the infections to TWCore, a legitimate system application installed on DoFun devices that collects analytics and handles software updates. TWCore can also download and install new Android applications.

Attackers abused that functionality to push a malicious app called JarService onto affected devices. The attack requires no action from the driver — no clicking a link, visiting a malicious website, or installing anything manually. JarService has no visible user interface, making it difficult for drivers to notice their devices have been compromised.

Malware’s purpose: building a proxy botnet

JarService acts as a downloader for additional malicious code. The malware can display advertisements and generate fraudulent ad clicks, but Kaspersky said its ultimate purpose appears to be expanding a botnet — networks of infected devices that criminals can remotely use for cyberattacks, fraud, and traffic routing.

One of the malware modules observed by researchers turns infected head units into reverse proxies. This allows other people’s internet traffic to be routed through the infected device, making the activity appear to originate from the car’s internet connection. That’s a powerful tool for hiding criminal activity.

Kaspersky attributes campaign to MoYu Group

Kaspersky attributed the campaign with high confidence to MoYu Group, a threat actor linked to the BadBox malware operation. BadBox has previously compromised Android smartphones, tablets, streaming devices, and other internet-connected products.

“Despite efforts by cybersecurity professionals and law enforcement to shut down the BadBox botnet, individual actors linked to it continue their malicious activity, infecting devices worldwide,” Kaspersky researchers said.

BadBox has a history of pre-installed malware. In 2023, cybersecurity company HUMAN Security discovered more than 70,000 Android smartphones, connected TV boxes, and tablets from at least one Chinese manufacturer that had been shipped with malware linked to the operation.

BadBox’s persistence and evolution

In December 2024, German authorities disrupted the original BadBox botnet by cutting off communications between infected devices and the hackers’ command-and-control infrastructure. However, the hackers quickly resurfaced with an updated version of the botnet.

The FBI also warned last year that BadBox 2.0 was targeting internet-of-things devices, including TV streaming boxes, digital projectors, digital picture frames, and aftermarket vehicle infotainment systems. The new campaign against DoFun head units fits that pattern.

Kaspersky said it notified DoFun about the distribution scheme, and the vendor subsequently reported fixing the security issues. Still, the incident highlights a growing concern: as cars become more connected, they also become more attractive targets for cybercriminals. For related context, see our coverage of Android malware trends and botnet takedown efforts.

The discovery serves as a reminder that the internet of things extends to the vehicle in your driveway. Drivers should keep their car’s software updated and be aware that even legitimate-looking components can be exploited.

Continue Reading

Trending