March rundown: The return of state-backed hacking campaigns
A major attack on the electoral commission raised concerns for the security capabilities of public and private organizations
March has been a month of concern for those in the cyber security community following revelations of extensive hacking campaigns carried out by state-backed groups.
In the latter part of the month, it was reported that APT 31, a Chinese state-backed threat group, had accessed information on tens of millions of UK voters in a breach of the Electoral Commission. Threat actors had also targeted US politicians and businesses.
What can we learn from the breach and how can organizations protect themselves against future state-backed threats?
In this episode, Jane and Rory welcome back Ross Kelly, ITPro’s news and analysis editor, to explore the month’s cyber security developments.
Highlights
“APT31 is a Chinese state-linked threat group, it's highly active, highly aggressive in its tactics, and it's been known to target a wide variety of public and private sector organizations.”
RELATED WEBINAR
“It's very much indicative of the increasingly interwoven nature of public sector and private sector, third-sector, government, in terms of how our economies work today. If you have an attack on, say, a private enterprise how many times have we seen government departments in the US, for example, impacted by that, and vice versa? It's both a political and financial minefield for governments and private enterprises themselves.”
“[Phishing] is still something that threat actors are using extensively, because it's so effective. That's where education comes into the equation: enterprises, whether in the public sector or private sector, educating and informing staff, to be able to look out for telltale signs is critical. ”
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Footnotes
- Security experts raise questions about UK cyber funding in wake of Electoral Commission hack
- Microsoft: The UK is woefully unprepared for future AI cyber threats
- Five Eyes advisory raises alarm over state-backed 'living off the land' attacks
- State-sponsored hackers are diversifying tactics, targeting small businesses
- Should your business worry about Chinese cyber attacks?
- Should your business worry about Russian cyber attacks?
- NCSC: “New class” of Russian cyber attackers seek to destroy critical infrastructure
Subscribe
- Subscribe to The IT Pro Podcast on Apple Podcasts
- Subscribe to The IT Pro Podcast on Spotify
- Subscribe to the IT Pro newsletter
- Join us on LinkedIn

Rory Bathgate is Features and Multimedia Editor at ITPro, overseeing all in-depth content and case studies. He can also be found co-hosting the ITPro Podcast with Jane McCallion, swapping a keyboard for a microphone to discuss the latest learnings with thought leaders from across the tech sector.
In his free time, Rory enjoys photography, video editing, and good science fiction. After graduating from the University of Kent with a BA in English and American Literature, Rory undertook an MA in Eighteenth-Century Studies at King’s College London. He joined ITPro in 2022 as a graduate, following four years in student journalism. You can contact Rory at rory.bathgate@futurenet.com or on LinkedIn.
-
Accenture to roll-out Copilot to 700,000+ staffNews Accenture will roll out Microsoft Copilot to nearly three quarters of a million employees after years of testing
-
Compromised open source package pushed malicious Elementary CLI release to developersNews The open source Elementary CLI tool has more than one million monthly downloads
-
The race to become quantum-safeITPro Podcast Efforts to run AI in trusted regions can clash with access to frontier model updates, business scalability
-
March rundown: RSAC warnings and Arm's AGI CPUITPro Podcast AI agents are complicating the jobs of cyber professionals, with broken permissions and a lack of oversight posing major risks
-
SPECIAL EDITION: How AI is changing educationSponsored Podcast With the right support and communication, educational organizations can use AI to empower teachers and students alike
-
Tomorrow's fraud techniquesITPro Podcast Leaders need to proactive as attackers launch more consistent, sophisticated attacks
-
Redefining risk managementSponsored Podcast With a Risk Operations Center (ROC), leaders can proactively crack down on cyber risks instead of simply reacting to them
-
Are AI cyber threats overhyped?ITPro Podcast As cyber teams turn to the threats posed by AI, rising attacks by state-sponsored groups and ransomware gangs remain the biggest threat
-
The future of threat detectionITPro Podcast To fight sophisticated threats, cybersecurity teams will need to unify data like never before
-
November rundown: CrowdStrike's insider threatITPro Podcast As CrowdStrike grappled with a malicious employee, Cloudflare suffered a major outage