Sellafield Concedes Major Cybersecurity Lapses in Nuclear Operations

The operator of the Sellafield nuclear site has issued an apology for severe lapses in cybersecurity, which potentially endangered national security. The firm overseeing the UK’s largest nuclear complex has acknowledged significant mistakes and admitted guilt in response to multiple criminal charges related to its cybersecurity failings. An investigation revealed that 75% of the facility’s servers were exposed to cyber threats. These findings were presented during a court session at Westminster Magistrates’ Court in London. The Sellafield Group, supported by the Nuclear Decommissioning Authority (NDA)—the UK’s body responsible for overseeing the decommissioning and dismantling of nuclear plants—confessed that these vulnerabilities could have compromised national security.

The Guardian reports, citing the NDA, that sensitive data remained inadequately protected for a period of four years. The Sellafield Group falsely claimed that essential IT security measures had been performed. Additional concerns were raised about the lack of supervision over external contractors who could plug USB devices into the site’s IT infrastructure. The facility’s internal security was so weak that the issue was even nicknamed after the villain Voldemort from the Harry Potter series.

In a recent court session, an official from the Office for Nuclear Regulation (ONR) explained how a test revealed the ability to download and execute harmful files on Sellafield’s networks through a phishing attack without triggering any security alarms. The ONR initiated legal action in June. The court also learned that a subcontractor mistakenly received 4,000 files, including 13 marked as “official/sensitive”. The breach of other sensitive nuclear data was partly due to the use of outdated technology such as Windows 7 and Windows Server 2008.

A spokesperson for Sellafield stated that substantial improvements have been made to enhance system, network, and structural security. The facility has also agreed to cover legal expenses amounting to £53,000 (approximately €62,000). The court is set to establish new precedents with its penalties. Last year, it was reported that cyberattacks linked to Russian and Chinese actors had targeted the facility’s IT systems, a claim the British government had denied at that time.

The Sellafield site encompasses not only a nuclear power plant and a reprocessing facility but also the world’s largest plutonium storage and a nuclear waste disposal site. The facility has experienced several incidents since the 1950s.

More Articles & Posts