Czech Republic

Country

Widespread Fallout after Cyberattack hits Italy’s National Railway Company

March 23, 2022

Italian State Railways (FS) and its subsidiaries Trenitalia and Italian Rail Network (RFI) suffered a major ransomware attack on March 23 . The attack severely impacted ticketing systems, passenger information displays, and internal communications.

FS implemented emergency measures, allowing passengers to purchase tickets on trains without penalties. The primary focus was on restoring critical systems and minimizing further disruption to passenger services. Freight transport by rail was temporarily suspended for 24 hours. Reportedly affecting FS, Metrans Rail of Czech Republic, HUPAC of Switzerland and Lineas of Belgium.

Metrans Rail of Czech Republic shutdown their Italian operations for 24 hours the following day. They stated it was temporarily not possible to cross the border at Austria and Slovenia. Marc Jansen, director of operations at carrier Hupac, said trains have been standing still for 24 hours. Arno van Deursen, Country Manager Lineas NL said “Our trains to and from Italy have been standing still for about 15 hours”.

Elements were found on the computer network of Trenitalia and RFI that could be linked to a cryptolocker infection. Italian authorities, including the Postal Police’s National Cybercrime Center (Cnaipic) and the National Cybersecurity Agency (Acn), launched a joint investigation.

read more

Hackers Post Fabricated Statements on Czech Press Agency (ÄŒTK) News Site

April 23, 2024

An unknown attacker posted fabricated texts that were not produced by ČTK on the news website Česká noviny (ČN), which is operated by the Czech Press Agency (ČTK).

It was a text with the headline “BIS prevented an assassination attempt on newly elected Slovak President Petr Pelligrini” and a fabricated extraordinary statement by Foreign Minister Jan Lipavský on the same. The attacker placed it on the ÄŒN website in Czech and English. The disinformation was also published with relevant notifications in the ÄŒN mobile application.

The news was removed from the České noviny website and access was blocked.

read more

Czech Railways Website and App Hacked

January 3, 2023

The website and application of the state railway carrier České dráhy were attacked by hackers. The website and the booking application may therefore be unavailable according to the carrier. Passengers will be checked in without surcharge. The spokeswoman did not want to give details about the beginning of the attack and the type of attack for security reasons. [machine translated].

read more

Cyberattack at Czech Institute of Nuclear Research Did Not Threaten Reactor Operations

December 12, 2022

The Institute of Nuclear Research Řež was attacked by a hacker group. It only attacked economic systems, which caused, for example, a delay in sending wages. The technological systems remained intact, the operation of the reactors was not threatened by the attack.

Hackers penetrated the institute’s internal system using the Ransomware program, which blocks the computer system and encrypts the data stored in it. It demands a ransom from the user for data recovery.
Zdroj: https://www.idnes.cz/zpravy/domaci/ustav-jaderneho-vyzkumu-kyberutok-hackeri.A221207_135851_domaci_vajo

read more

Bitcoin ATM Manufacturer Suffers Attack

March 17, 2023

General Bytes, a manufacturer of Bitcoin ATMs, disclosed a security incident that resulted in the theft of millions of dollars’ worth of funds. Attackers were able to steal cryptocurrency from the company and its customers using a Zero Day in its BATM management platform.
In terms of the March 17-18 incident, here is what General Bytes said what happened:
The attacker identified a security vulnerability in the master service interface used by Bitcoin ATMs to upload videos to server.
The attacker scanned the Digital Ocean cloud hosting IP address space and identified running Crypto Application Server (CAS) services on ports 7741, including the General Bytes Cloud service and other GB ATM operators running their servers on Digital Ocean (our recommended cloud hosting provider).
Using this security vulnerability, attacker uploaded his own application directly to application server used by admin interface. Application server was by default configured to start applications in its deployment folder.

read more