‘China-based’ hack targets UK companies in ‘critical national security threat’, says analyst

UK Companies Targeted by Chinese Hackers via SAP Vulnerability, Experts Warn
Photo: Sky News

UK Companies Targeted by Chinese Hackers via SAP Vulnerability, Experts Warn

A significant cyberattack originating from China has compromised hundreds of UK companies, according to cybersecurity firm EclecticIQ. Unlike recent ransomware incidents targeting M&S, Co-op, and Harrods, this attack utilized remote code execution via a previously unknown vulnerability in SAP NetWeaver software. The vulnerability allowed attackers to remotely run malicious programs and potentially exfiltrate sensitive data. Over 500 SAP customers worldwide have been affected, including UK companies like Cadent, News UK, Johnson Matthey, and Ardagh Metal. Entities in the US and Saudi Arabia were also targeted.

EclecticIQ CEO Cody Barrow, a former Pentagon and NSA official, described the situation as a ‘critical national security threat’ and emphasized the need for immediate software updates. The UK’s National Cyber Security Centre (NCSC) is actively monitoring the situation and urges organizations to apply SAP’s patches released on April 24 and May 13, 2025.

The cyberattack is believed to be linked to Chinese cyber-espionage units, based on forensic evidence such as file names and operational patterns. The attackers are suspected of aiming to access critical infrastructure systems and maintain long-term access to sensitive networks. NHS England issued a general warning, although its systems have not been confirmed as affected.

Leave a Reply

Your email address will not be published. Required fields are marked *