HomeTopics 2Cyberespionage SpyingRoyal Navy Sailor Charged Over Alleged Spying for Foreign Power, UK Police...

Royal Navy Sailor Charged Over Alleged Spying for Foreign Power, UK Police Say

Date:

Related stories

spot_imgspot_imgspot_imgspot_img

Questions over the security of sensitive military information have emerged in the UK after a 24-year-old Royal Navy sailor was taken into custody in connection with alleged activity benefiting a foreign power.

According to BBC, Teddy Young, 24, from Bedfordshire, was arrested at his home on Tuesday, 6 October, following an investigation led by Counter Terrorism Policing London. He has since been charged with two offences under the National Security Act 2023 and is due to appear at Westminster Magistrates’ Court.

The case places the spotlight once again on one of the most difficult security problems facing governments and critical organisations: the insider who already has legitimate access.

What the police allege

According to the Metropolitan Police, Young is accused of conduct between 26 November 2024 and 21 May 2025.

The first charge alleges that he engaged in conduct in preparation for committing an offence involving the disclosure of protected information.

The second alleges that he obtained, copied, recorded or retained protected information with the intention of benefiting a foreign power, while knowing, or reasonably expected to know, that the conduct was prejudicial to the safety or interests of the United Kingdom.

The police have not publicly identified the foreign power involved.

Under Section 1 of the National Security Act 2023, obtaining, copying, recording or retaining protected information can constitute an offence when the conduct is prejudicial to the safety or interests of the UK and the foreign-power condition is met. Section 18 separately covers preparatory conduct connected to offences including the obtaining or disclosure of protected information.

It is important to stress that these are allegations. Young has been charged but has not been convicted.

Commander Helen Flanagan, Head of Counter Terrorism Policing London, described the allegations as “very serious charges” against a serving member of the armed forces.

Police said investigators worked closely with operational colleagues within the Ministry of Defence during the investigation so that measures could be taken to mitigate any potential risks.

The Royal Navy has confirmed that a service member has been charged but declined to comment further while legal proceedings are ongoing.

Not connected to RAF Fairford investigation

The timing of the arrest could easily lead to confusion with another national-security investigation involving suspicious activity around RAF Fairford.

The Metropolitan Police has specifically stated that Young’s arrest and the charges against him are not connected to that investigation.

Counter-terrorism officers continue to investigate the separate RAF Fairford incident, in which several people have been arrested.

The distinction matters because national-security investigations can quickly become surrounded by speculation, particularly when multiple incidents occur around sensitive military facilities at the same time.

For now, authorities have provided no indication that the two cases are linked.

The insider threat problem

The significance of this case extends beyond the military.

Security teams have spent years building defences against external attackers — phishing campaigns, ransomware groups, malicious websites, stolen credentials and exploitation of vulnerable systems. But an individual who already has legitimate access presents a different challenge.

An insider may not need to break through a firewall or exploit a software vulnerability. They may already possess the credentials, permissions, physical access or institutional knowledge required to reach sensitive information.

That makes identity and access management, monitoring and security awareness particularly important for organisations handling classified, commercially sensitive or strategically important information.

The risk is also broader than deliberate espionage.

Employees and contractors can unintentionally expose sensitive information through poor security practices, insecure devices, unauthorised cloud services, weak authentication or careless handling of documents.

The lesson for organisations is therefore not to treat every employee as a potential adversary. It is to build systems in which legitimate access is controlled, monitored and continuously reviewed.

Why this matters to organisations in the Middle East and Africa

Although the investigation is taking place in the UK, the underlying security challenge is global.

Across the Middle East and Africa, governments, banks, telecom operators, energy companies, mining organisations, defence suppliers and critical infrastructure providers increasingly depend on digital systems and large volumes of sensitive information.

As organisations expand cloud adoption, remote access, third-party outsourcing and digital transformation programmes, the number of people and systems capable of reaching sensitive information also grows.

That creates a wider identity and insider-risk management problem.

For organisations operating in highly regulated sectors, cybersecurity cannot stop at perimeter protection. Security leaders need visibility into who can access sensitive information, why they have that access, what they do with it and whether their behaviour changes over time.

This is particularly important for organisations managing national-security information, financial data, intellectual property, industrial systems or critical infrastructure.

10 Actions Security Teams Should Take

  1. Apply least privilege

Employees, contractors and service accounts should receive only the access necessary to perform their responsibilities. Privileges should not remain permanently elevated simply because they were once required.

  1. Review access to sensitive information

Conduct regular access reviews for classified, confidential and business-critical information. Remove dormant accounts and permissions that no longer have a clear business justification.

  1. Strengthen identity security

Use multi-factor authentication, privileged access management and strong identity controls for sensitive systems. Shared accounts should be eliminated wherever possible.

  1. Monitor unusual user behaviour

Security teams should establish a baseline for normal activity and investigate unusual access patterns, unexpected downloads, abnormal working hours, unusual geographic activity or attempts to access information outside an employee’s role.

  1. Deploy data loss prevention controls

DLP technologies can help organisations identify and control attempts to move sensitive information through email, cloud storage, removable media and other channels.

  1. Separate sensitive environments

Highly sensitive information should not be unnecessarily accessible from ordinary corporate environments. Network segmentation and appropriate security boundaries can limit the impact of compromised or misused accounts.

  1. Strengthen security awareness and training

Employees need to understand how sensitive information should be handled, stored and shared. Regular cybersecurity training and awareness programmes should include insider-risk scenarios rather than focusing exclusively on phishing.

  1. Establish clear reporting channels

Employees should have a safe and confidential way to report suspicious activity, accidental disclosure or concerns about security without fear of unnecessary retaliation.

  1. Continuously assess third-party access

Contractors, consultants, suppliers and partners can sometimes have access to sensitive environments. Their accounts should be subject to the same principles of least privilege, monitoring and periodic review.

  1. Build an insider-threat response plan

Organisations should define what happens when suspicious internal activity is detected. Security, HR, legal, compliance and senior management should understand their respective responsibilities before an incident occurs.

The bigger security lesson

The alleged conduct in this case highlights a fundamental principle of modern cybersecurity: trust should never mean unrestricted access.

An employee may be legitimate. A contractor may be legitimate. A privileged account may be legitimate. But legitimate identity does not automatically make every action legitimate.

That is why modern cybersecurity programmes increasingly combine identity security, access governance, behavioural monitoring, data protection, cybersecurity awareness and incident response.

The objective is not simply to watch employees. It is to create a security architecture in which sensitive information is protected even when someone with legitimate access behaves unexpectedly.

For organisations operating critical infrastructure or handling sensitive information, this is becoming a core part of cyber resilience.

As the UK investigation moves through the courts, many details surrounding the allegations will remain confidential. What is already clear, however, is that insider risk remains a serious national-security and cybersecurity concern — one that cannot be solved by firewalls and endpoint protection alone.

Organisations need to understand their people, identities, permissions, data and trust relationships just as carefully as they understand their external attack surface.

Cybersecurity is ultimately about controlling access to what matters most — and knowing when that access is being used in a way that it should not be.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img