The Guardian (USA)

UK security chiefs issue guidance to ministers over hackers on WhatsApp

- Rowena Mason Deputy political editor

Ministers and civil servants conducting “government by WhatsApp” have been at risk of being targeted by hackers, leading to new advice from security chiefs about how to improve their privacy.

The cabinet secretary, Simon Case, revealed that the Government Security Group had issued fresh guidance across government in a letter to Labour, which had raised questions about ministers using their personal phones to conduct official business.

The shadow chancellor of the Duchy of Lancaster, Angela Rayner, wrote to Case criticisin­g ministers’ use of WhatsApp and private email, which has emerged in relation to Covid contracts being discussed on personal digital devices.

The civil service chief said in his reply that the government took security seriously and highlighte­d the work done to improve it. It is understood the advice was issued in May after highprofil­e stories about hackers exploiting WhatsApp.

“The NCSC [National Cyber Security Centre] and the Government Security Group in the Cabinet Office may also issue guidance in response to specific threats,” he said. “For example, the Government Security Group recently provided advice on how to secure devices using two-factor authentica­tion in response to hackers using fake messages to access WhatsApp.”

His comments suggest such authentica­tion was not always used routinely.

Hackers are known to have targeted government officials across the globe through WhatsApp. Ministers in Australia, the Netherland­s and South Africa have suffered successful attacks on their digital devices.

The Guardian’s investigat­ion into a leak about Pegasus software revealed last month that clients of the Israeli-based cyber intelligen­ce firm NSO could in effect take control of a phone, enabling them to extract messages, calls, photos and emails, secretly activate cameras or microphone­s, and read the contents of encrypted messaging apps such as WhatsApp, Telegram and Signal.

The shadow security minister, Conor McGinn, said “conducting official government business via WhatsApp risks exposing potentiall­y critical informatio­n to hackers and cybercrimi­nals who seek to harm our country”.

He also highlighte­d Boris Johnson’s poor cybersecur­ity, after it was revealed last year that the prime minister was still using his personal mobile number that was widely available.

Rayner said: “Private WhatsApp messages avoid transparen­cy and scrutiny, and could easily be used to facilitate the waste of taxpayers’ money on contracts for mates of Conservati­ve ministers.

“We need a fully independen­t inquiry into the government contracts that have been handed out over private email and WhatsApp so we can get to the bottom of this scandal.

“We need all decisions and communicat­ions made during the pandemic to be made available to the public inquiry, including those held in private ministeria­l WhatsApp messages.”

A Cabinet Office spokespers­on said the government had sent the guidance to all department­al employees in May.

 ??  ?? Labour raised questions about ministers and civil servants using their personal phones to conduct official business. Photograph: Alex Segre/Alamy
Labour raised questions about ministers and civil servants using their personal phones to conduct official business. Photograph: Alex Segre/Alamy

Newspapers in English

Newspapers from United States