US and UK say state-backed Russian hacking group APT29 is responsible for ongoing cyberattacks against orgs involved in the development of coronavirus vaccines
This July 2020 announcement is the first public joint attribution in the corpus: Washington and London name APT29 as the actor behind ongoing intrusions at organizations developing coronavirus vaccines, converting what had been quiet incident response into a diplomatic signal. It matters because the same unit stays in the headlines — sources later tie APT29, aka Cozy Bear, to the breaches of the US Treasury, NTIA, and FireEye, making this vaccine-developer campaign an early data point on a group that becomes the most consequential Russian cyber actor of the period.
The targeting also proved not to be Moscow's alone: months after this attribution, [[a:959989|Microsoft detected three APTs from Russia and North Korea hitting at least seven COVID-19 vaccine or treatment developers]], confirming that pandemic-era biomedical IP had become contested ground for multiple state-backed adversaries at once.
First-order effects
Vaccine-development organizations named in the campaign must now assume active intrusion rather than opportunistic scanning, forcing immediate security reviews and government liaison with the US and UK agencies behind the attribution.
APT29's cover is partially blown: defenders can pivot from generic threat hunting to Cozy Bear-specific indicators, raising the cost of each subsequent operation against the same targets.
Second-order effects
Pharma and biotech firms adjacent to the named developers face pressure to harden research networks and share indicators, since the campaign targets a whole development ecosystem rather than single companies — a pattern Microsoft's multi-APT findings reinforced.
The joint US-UK attribution establishes a template for coordinated public naming of Russian operations, which recurs when sources link the same group to the Treasury and FireEye hacks and when both governments later sanction entities tied to Chinese state-backed group APT31.
Third-order effects
If the pattern holds, state espionage migrates from government networks toward scientific and health infrastructure — vaccine labs, treatment developers, research consortia — because pandemic-era IP carries geopolitical value comparable to classified material.
Public attribution by allied governments hardens into standard statecraft, pairing every major intrusion with a named adversary and setting up the sanctions track visible in the 2024 action against an APT31-linked company.
The trend: State-backed hacking groups are shifting priority targets from government networks to scientific and health research, while the US and UK respond with coordinated public attribution that feeds a growing sanctions pipeline.
Russia has used this pandemic to cause more chaos around the world. They have been spreading endless disinfo and countless cyber attacks. All while Putin hid the severity of coronavirus in Russia and silenced medical professionals who tried to get the word out. https://twitter.co…
Wouldn't it be nice if the US, Russia, China, EU, India, Brazil, and others were cooperating to find a vaccine? I know. Naive thought. “Russia Is Trying to Steal Virus Vaccine Data, Western Nations Say.” https://www.nytimes.com/...
I'm confused. If the Russians are interested in our #COVID19 vaccine they can just send us an email and we can set up a call? The RNA DNA vaccine deliveries not necessarily the best for inducing virus neutralizing antibodies or protection. https://www.bbc.com/...
Dominic Raab, UK foreign secretary, said it was “completely unacceptable that the Russian intelligence services are targeting those working to combat the coronavirus pandemic”. No confirmation that attempts to steal Covid-19 info were successful. https://www.ft.com/...
The 🇬🇧 stands with 🇺🇸 & 🇨🇦 against the reckless actions of Russia's intelligence services, who we have exposed today for committing cyber attacks against those working on a #Covid19 vaccine - undermining vital 🌎 cooperation to defeat this pandemic https://www.gov.uk/...
Coronavirus: Russian hackers target coronavirus vaccine research. The hackers are part of a group called APT29, also known as “the Dukes” or “Cozy Bear”. https://www.bbc.co.uk/...
The U.S., the U.K., and Canada say that Russia's “Cozy Bear” (APT29) hackers have been using custom malware to target organizations that are developing coronavirus vaccines. https://www.ncsc.gov.uk/... https://us-cert.cisa.gov/...
In March, HHS was hit by a cyber attack, while not attributed to Russia at the time, Russia was a likely suspect. Today's attack is part of a pattern. The fact that APT29 is still carrying out such brazen attacks is testament to our tepid response https://www.nytimes.com/... http…
Shouldn't we just assume that US / Chinese spooks are vacuuming up every byte of coronavirus vaccine research from around the world? This seems like a you-only-had-one-job kind of situation for intel agencies https://twitter.com/...
New: U.S., British and Canadian security officials blame Russia (APT 29/Cozy Bear) for attempting to hack vaccine research. “We encourage everyone to take this threat seriously,” Anne Neuberger, NSA's director of cybersecurity, said. https://www.wsj.com/...
U. S. and U.K. government officials said a prominent state-backed Russian hacking group is responsible for ongoing cyberattacks against organizations involved in the development of coronavirus vaccines and other healthcare-related work. https://www.wsj.com/...