The event – revealed by analyst Arda Buyukkaya at cybersecurity firm EclecticIQ – used a previously unknown backdoor in a piece of software called SAP Netweaver, with a patch since released.
Cody Barrow is the chief executive of EclecticIQ and previously worked at the Pentagon, the NSA and US Cyber Command.
He told Sky News: “Governments should treat this as a critical national security threat”, adding that it is the kind of scenario that keeps people like him up at night.
Image: Cadent is said to be among the companies that were exploited. Pic: iStock
Mr Barrow said the exploitation of networks is “extensive and ongoing”, with more than 500 SAP customers affected and more potentially at risk. He urged users to update their software to the latest version.
Gas giant Cadent, publishers News UK, Euro Garages (EG) Group, Johnson Matthey and Ardagh Metal have been named as victims, with US and Saudi Arabian entities also targeted.
NHS England has posted a warning about the exploit on their website, although it is not clear if they are impacted.
The National Cyber Security Centre (NCSC), the UK government’s authority on cyber threats and part of GCHQ, are monitoring the situation.
Image: Government experts are monitoring the incident. Pic: PA
An NCSC spokesperson told Sky News: “We are monitoring for UK impact following reports of a critical vulnerability affecting SAP NetWeaver being actively exploited.
“The NCSC strongly encourages organisations to follow vendor best practice to mitigate the vulnerability and potential malicious activity.
“Vulnerabilities are a common aspect of cyber security, and all organisations must consider how to most effectively manage potential security issues.”
JP Perez-Etchegoyen, the chief technical officer of Onapsis – which specialises in the cybersecurity security of SAP – told Sky News that exploits of the backdoor were first observed at the start of this year, and began to increase in March.
Last week, Cabinet minister Pat McFadden warned companies that recent cyber attacks on M&S, Co-op and Harrods should be a “wake-up call” for businesses.
A spokesperson for Cadent declined to comment on the specific attack, but the company works with the NCSC on cyber security issues.
A spokesperson for News UK declined to comment.
EG Group, Johnson Matthey and Ardagh Metal have not responded to Sky News requests for comment.
According to the initial summary of the exploit, analysts linked the attacks to “Chinese cyber-espionage units”.
This was based on a variety of factors, including Chinese-named files identified as part of the hack, and the way the hackers operated.
The aim of the Chinese groups is to “operate strategically to compromise critical infrastructure, exfiltrate sensitive data, and maintain persistent access across high-value networks worldwide”, said the summary.
The targets in the UK were said to include critical gas distribution networks, and water and integrated waste management utilities.
Spreaker
This content is provided by Spreaker, which may be using cookies and other technologies.
To show you this content, we need your permission to use cookies.
You can use the buttons below to amend your preferences to enable Spreaker cookies or to allow those cookies just once.
You can change your settings at any time via the Privacy Options.
Unfortunately we have been unable to verify if you have consented to Spreaker cookies.
To view this content you can use the button below to allow Spreaker cookies for this session only.
A spokesperson for SAP said: “SAP is aware of and has been addressing vulnerabilities in SAP NETWEAVER Visual Composer. SAP issued a patch on 24 April, 2025.
“A second vulnerability has also been identified and a patch was released on 13 May, 2025.
“We ask all customers using SAP NETWEAVER to install these patches to protect themselves.”
The Chinese embassy in London has been approached for comment.
Donald Trump has announced he will impose a 30% tariff on imports from the European Union from 1 August.
The tariffs could make everything from French cheese and Italian leather goods to German electronics and Spanish pharmaceuticals more expensive in the US.
Mr Trump has also imposed a 30% tariff on goods from Mexico, according to a post from his Truth Social account.
Announcing the moves in separate letters on the account, the president said the US trade deficit was a national security threat.
In his letter to the EU, he wrote: “We have had years to discuss our trading relationship with The European Union, and we have concluded we must move away from these long-term, large, and persistent, trade Deficits, engendered by your tariff, and non-Tariff, policies, and trade barriers.
“Our relationship has been, unfortunately, far from reciprocal.”
In his letter to Mexico, Mr Trump said he did not think the country had done enough to stop the US from turning into a “narco-trafficking playground”.
The president of the European Commission, Ursula von der Leyen, said today that the EU could adopt “proportionate countermeasures” if the US proceeds with imposing the 30% tariff.
Ms von der Leyen, who heads the EU’s executive arm, said in a statement that the bloc remained ready “to continue working towards an agreement by Aug 1”.
“Few economies in the world match the European Union’s level of openness and adherence to fair trading practices,” she continued.
“We will take all necessary steps to safeguard EU interests, including the adoption of proportionate countermeasures if required.”
Ms von der Leyen has also said imposing tariffs on EU exports would “disrupt essential transatlantic supply chains”.
Meanwhile, Dutch Prime Minister Dick Schoof said on the X social media platform that Mr Trump’s announcement was “very concerning and not the way forward”.
He added: “The European Commission can count on our full support. As the EU we must remain united and resolute in pursuing an outcome with the United States that is mutually beneficial.”
Mexico’s economy ministry said a bilateral working group aims to reach an alternative to the 30% US tariffs before they are due to take effect.
The country was informed by the US that it would receive a letter about the tariffs, the ministry’s statement said, adding that Mexico was negotiating.
The US imposed a 20% tariff on imported goods from the EU in April but it was later paused and the bloc has since been paying a baseline tariff of 10% on goods it exports to the US.
In May, while the US and EU where holding trade negotiations, Mr Trump threated to impose a 50% tariff on the bloc as talks didn’t progress as he would have liked.
However, he later announced he was delaying the imposition of that tariff while negotiations over a trade deal took place.
As of earlier this week, the EU’s executive commission, which handles trade issues for the bloc’s 27-member nations, said its leaders were still hoping to strike a trade deal with the Trump administration.
Without one, the EU said it was prepared to retaliate with tariffs on hundreds of American products, ranging from beef and auto parts to beer and Boeing airplanes.
At least 798 people in Gaza have reportedly been killed while receiving aid in the past six weeks – while acute malnutrition is said to have reached an all-time high.
The UN human rights office said 615 of the deaths – between 27 May and 7 July – were “in the vicinity” of sites run by the controversial US and Israel-backed Gaza Humanitarian Foundation (GHF).
A further 183 people killed were “presumably on the route of aid convoys,” said Ravina Shamdasani, from the Office of the UN High Commissioner for Human Rights.
Its figures are based on a range of sources, including hospitals, cemeteries, and families in the Gaza Strip, as well as non-governmental organisations (NGOs), its partners on the ground, and Hamas-run health authorities.
Image: Ten children were reportedly killed when Israel attacked near a clinic on Thursday. Pic: AP
The GHF has claimed the UN figures are “false and misleading” and has repeatedly denied any violence at or around its sites.
Meanwhile, Medecins Sans Frontieres (MSF) – also known as Doctors Without Borders – said two of its sites were seeing their worst-ever levels of severe malnutrition.
Cases at its Gaza City clinic are said to have tripled from 293 in May to 983 in early July.
“Over 700 pregnant or breastfeeding women and nearly 500 children are now receiving emergency nutritional care,” MSF said.
The humanitarian medical charity said food prices were at extreme levels, with sugar at $766 (£567) per kilo and flour $30 (£22) per kilo, and many families surviving on one meal of rice or lentils a day.
It’s a major concern for the estimated 55,000 pregnant women in Gaza, who risk miscarriage, stillbirth and malnourished infants because of the shortages.
The GHF began distributing food packages in Gaza at the end of May, after Israel eased its 11-week blockade of aid into the coastal territory.
Please use Chrome browser for a more accessible video player
1:01
US aid contractors claim live ammo fired at Palestinians
It has four distribution centres, three of which are in the southern Gaza Strip.
The sites, kept off-limits to independent media, are guarded by private security contractors and located in zones where the Israeli military operates.
Palestinian witnesses say Israeli forces have repeatedly opened fire towards crowds of people going to receive aid.
The Israeli military says it has fired warning shots at people who have behaved in what it says is a suspicious manner.
It says its forces operate near the aid sites to stop supplies from falling into the hands of militants.
After the deaths of hundreds of Palestinians trying to reach the aid hubs, the United Nations has called the GHF’s aid model “inherently unsafe” and a violation of humanitarian impartiality standards.
Follow The World
Listen to The World with Richard Engel and Yalda Hakim every Wednesday
In response, a GHF spokesperson said: “The fact is the most deadly attacks on aid sites have been linked to UN convoys.”
The GHF says it has delivered more than 70 million meals to Gazans in five weeks and claims other humanitarian groups had “nearly all of their aid looted” by Hamas or criminal gangs.
At least 798 people in Gaza have been killed while receiving aid in six weeks, the UN human rights office has said.
A spokesperson for the Office of the United Nations High Commissioner for Human Rights said 615 of the killings were “in the vicinity” of sites run by the controversial US and Israel-backed Gaza Humanitarian Foundation (GHF).
A further 183 people killed were “presumably on the route of aid convoys,” Ravina Shamdasani told reporters in Geneva.
The office said its figures are based on numbers from a range of sources, including hospitals, cemeteries and families in the Gaza Strip, as well as NGOs, its partners on the ground and the Hamas-run health authorities.
The GHF has claimed the figures are “false and misleading”. It has repeatedly denied there has been any violence at or around its sites.
The organisation began distributing food packages in Gaza at the end of May, after Israel eased its 11-week blockade of aid into the enclave.
It has four distribution centres, three of which are in the southern Gaza Strip. The sites, kept off-limits to independent media, are guarded by private security contractors and located in zones where the Israeli military operates.
Palestinian witnesses say Israeli forces have repeatedly opened fire towards crowds of people going to receive aid.
Please use Chrome browser for a more accessible video player
1:01
US aid contractors claim live ammo fired at Palestinians
The Israeli military says it has fired warning shots at people who have behaved in what they say is a suspicious manner.
It says its forces operate near the aid sites to stop supplies falling into the hands of militants.
After the deaths of hundreds of Palestinians trying to reach the aid hubs, the United Nations has called the GHF’s aid model “inherently unsafe” and a violation of humanitarian impartiality standards.
Follow The World
Listen to The World with Richard Engel and Yalda Hakim every Wednesday
In response, a GHF spokesperson told the Reuters news agency: “The fact is the most deadly attacks on aid sites have been linked to UN convoys.”
The GHF says it has delivered more than 70 million meals to Gazans in five weeks and claims other humanitarian groups had “nearly all of their aid looted” by Hamas or criminal gangs.