Members of the Scottish Parliament staff at Holyrood were warned on Tuesday that a cyber attack was attempting to access email accounts by systematically and repeatedly trying to crack their passwords.
Holyrood has said it is not aware of any compromised email accounts, but MSPs and staff were warned the attack could mean some accounts would be locked or unavailable.
On Tuesday afternoon Sir Paul Grice, Holyrood’s chief executive, told MSPs and staff: “The parliament’s monitoring systems have identified that we are currently the subject of a brute force cyber-attack from external sources.
“This attack appears to be targeting parliamentary IT accounts in a similar way to that which affected the Westminster parliament in June. Symptoms of the attack include account lockouts or failed log-ins.
“The parliament’s robust cybersecurity measures identified this attack at an early stage and the additional security measures which we have in readiness for such situations have already been invoked. Our IT systems remain fully operational.”
The e-mail urged MSPs and staff to secure their passwords, stating the parliament’s IT team would “force a change to weak passwords as an additional security measure”.
The e-mail also noted that Holyrood’s IT staff investigated current passwords used and found too many were weak and easily cracked. It stated the investigation: “has highlighted a much higher than expected level of ‘simple’ passwords which would be easy to guess/crack using software which can be easily obtained. The number of simple passwords identified is too high for us to contact each individual personally.”
In June 2017, parliamentary corporate body member David Stewart told MSPs a review of “cyber security maturity” had been carried out, and had “offered assurance that sufficient and effective arrangements are in place to manage cyber threats and risks”.
He added that parliament regularly takes advice from the police, the security services and the national cyber security centre.





