Thousands of fake government websites and fraud campaigns targeting UK citizens have been thwarted by the NCSC Active Cyber Defence programme, a new report shows.
The report, ‘Active Cyber Defence – The Second Year’, details how cybercriminals and fraudsters are becoming increasingly aggressive in their tactics and emphasises the importance of the NCSC’s programme.
On one particular occasion, the NCSC stopped a scam that aimed to defraud thousands of UK citizens by using a fake email address to spoof a UK airport. The incident occurred in August 2018 and saw criminals try to send more than 200,000 emails claiming to be from the airport.
However, the emails failed to reach the intended recipients’ inboxes due to the NCSC’s Active Cyber Defence (ACD) system, which automatically detected the suspicious domain name. Recipients’ mail providers also never delivered the spoof messages and the real email account used by the criminals was taken down.
Recommended:
- Alan Turing chosen to feature on new £50 banknote
- Galileo satnav system suffers service outage
- Could Boris Johnson really give the UK full-fibre broadband by 2025?
The thwarting of the airport scam, NCSC claims, is just one example in 2019 of how its Active Cyber Defence programme protects the British public.
NCSC’s technical director, Dr Ian Levy, said: “These are just two examples of the value of ACD – the protected thousands of UK citizens and further reduced the criminal utility of UK brands. Concerted efforts can dissuade criminals and protect UK citizens.
“This second comprehensive analysis we have undertaken of the programme shows that this bold approach to preventing cyber attacks is continuing to deliver for the British public.”
Introduced in 2016, ACD includes programmes such as Web Check, Public Sector DNS and a takedown service and is defined as an “interventionist approach that stops millions of cyber attacks from ever happening”.
Other key findings of the NCSC’s report highlight ongoing efforts to tackle the growing threat of phishing attacks for people and organisations across the UK.
In 2018, the centre took down more than 22,000 phishing campaigns hosted in UK delegated IP space, totalling some 142,203 individual attacks. Similarly, around 14,000 UK Government-related phishing sites were also removed during this period.
Following the introduction of ACD, the number of phishing campaigns against HM Revenue & Customs fell dramatically, the report shows, with campaigns spoofing the tax office falling from 2,466 in 2017 to 1,332 in 2018.
In January 2016, the HMRC was the 16th most-popular choice of fraudulent email disguise. However, this phishing method has since fallen to a global ranking of 146th, according to the NCSC.
The total number of fraudulent website takedowns stands at approximately 192,256, and across 2018 around 64% of them were taken down within the space of 24-hours. This marks a drop on the year previous, which saw the NCSC perform a total of 219,992 takedowns.
The report added: “Interestingly, in 2017, these were distributed across 72,975 unique IP addresses and linked to 99,543 campaigns. In 2018, only 24,320 unique IP addresses hosted things we were interested in and there were only 51,569 campaigns.”
Moving forward, the report highlights a number of programmes and operations currently in development, with increased collaboration between NCSC and Action Fraud a key talking point. The two bodies will work together to design and build a new automated system which allows members of the public to report suspicious emails easily.
This new system could be launched and available for public use later in 2019, the report suggests.
Chancellor of the Duchy of Lancaster and minister for the cabinet office, David Lidington, added: “The UK is safer since the launch of our cyber strategy in 2016. The statistics and example in this report speak for themselves. They outline the tangible impact that Active Cyber Defence is having, and how it is a key building block in improving cybersecurity in the UK now, and in the future.”






