Government

Industry

Major Canadian Institutions Targeted in Cyberattacks.

October 2, 2023

Major Canadian institutions, including military and Parliament websites, have been targeted in recent cyberattacks. The Indian Cyber Force hacker group claims responsibility, causing disruption in various government-operated web platforms. However, Canada’s signals-intelligence agency reassures that these “nuisance” attacks probably haven’t compromised private data.

Canadian Armed Forces acknowledged that its website was temporarily inaccessible for mobile users after a DoDDS attack. The issue was resolved.
House of Commons website also suffered from a DDoS attack, resulting in slow loading or incomplete page displays starting Mondaywithin hours. Elections Canada faced a denial-of-service attack for about an hour early Wednesday.

read more

Cyberattack Causes Widespread Disruption in Kenya

July 25, 2023

Kenya endured a huge cyber attack that has affected services on a key government online platform. The BBC reported the attack against the region’s eCitizen portal. The portal is used by the public to access over 5,000 government services. Impacted were passport applications and renewal, e-visas for non-citizens visiting Kenya, as well as driving licenses, ID cards and health records from being issued.

Anonymous Sudan claim responsibility for an extensive cyberattack in Kenya which saw multiple government services impacted and raised digital concerns.

Mobile-money banking services M-Pesa were also affected by the attack. People were unable to make payments at shops. Public transport vehicles, hotels and other platforms also experienced difficulties. Millions of people across Kenya use Mobile-money to receive and spend money and the platform is seen as widely convenient for those who do not have access to essential banking services.

read more

Ransomware Attack Suspends All Services at Seville City Council – $1.5M Ransom Demanded

September 6, 2023

The Seville City Council has returned to paper notes and in-person procedures after suffering the hijacking of its computer systems by a group of cybercriminals, as confirmed by the City Council. The pirates demand a ransom of more than one million euros and the City Council refuses to pay or agree “with cybercriminals”

The hackers have claimed up to one and a half million dollars (1,396,642 euros) from the municipal government, although it has assured that “in no case will it negotiate with cybercriminals.” It is the second successful attack on the municipal website in three years.

All services have been affected.

read more

Wuhan Earthquake Monitoring Center Suspects Cyberattack comes from US.

July 26, 2023

Wuhan Earthquake Monitoring Center suffered a cyberattack. The Wuhan public security bureau Jianghan sub-bureau confirmed the discovery of a Trojan horse program originating from abroad at the Wuhan Earthquake Monitoring Center. According to the public security bureau, this Trojan horse program can illegally control and steal seismic intensity data collected by the front-end stations. This act poses a serious threat to national security. The center has immediately sealed off the equipment that was affected and reported the attack to the public security authorities, in order to investigate the case and handle the hacker organization and criminals according to law, said the statement.

read more

$1M Ransom Demanded of Auckland Transport

September 13, 2023

The Auckland Transport (AT) transportation authority in New Zealand is dealing with a widespread outage caused by a cyber incident, impacting a wide range of customer services. The company announced that it is experiencing issues with its HOP services (integrated ticketing and fares system).

Auckland Transport dismissed a claim by Medusa hacker group, that it will release data at 8pm Tuesday from the agency’s ticketing system. AT said it would not be engaging, and believed no financial data had been lost.

read more

Ransomware Attack at Sri Lanka Government Wipes Months of Data

August 30, 2023

Sri Lanka’s government email network was hit by a ransomware attack that wiped months of data from thousands of email accounts, including ones belonging to top government officials, authorities confirmed on Monday. The attack, which started at the end of August, affected nearly 5,000 email addresses using the gov.lk email domain. The victims include Sri Lanka’s council of ministers which forms the central government of the country.

The targeted system, Lanka Government Cloud (LGC), was encrypted along with backups of the system. Although officials were able to restore LGC within 12 hours of the attack, they didn’t have backups from May 17 to August 26, so all affected accounts lost data from that period, according to Mahesh Perera, the head of Sri Lanka’s Information and Communication Technology Agency (ICTA).

Perera told media outlets that the Sri Lankan government doesn’t plan to negotiate with the attackers or pay any ransom to retrieve the lost data. The agency did not respond to a request for comment.

read more

Ransomware Attack at US-Canada Water Management Organization.

September 7, 2023

International Joint Commission (IJC), the organization tasked with managing the lake and river systems along the border between the U.S. and Canada for the last hundred years, announced Wednesday that it experienced a cyberattack following reports that ransomware hackers claimed to have stolen reams of data.

The NoEscape ransomware gang claimed it attacked the organization — which has offices in Washington, D.C., Ottawa and Windsor — and stole 80 GB of contracts, geological files, conflict of interest forms and more. The gang gave the IJC 10 days to respond to their demand for a ransom. The group did not say how much money it was demanding to unlock the files. IJC did not respond to requests for comment about whether a ransom would be paid.

This week, the Cybersecurity and Infrastructure Security Agency (CISA) announced that it would be offering drinking water and wastewater systems free vulnerability scanning services. Water systems can get weekly automated scans that will provide a report on known vulnerabilities found on internet-accessible assets, week-to-week comparisons, and mitigations.

read more

DDoS Attack at Bordercheck Point in Canada

September 14, 2023

A cyberattack suspected to be carried out by a pro-Russia hacking group reportedly resulted in widespread service disruptions at several Canadian airports. The Canada Border Services Agency (CBSA) confirmed to Recorded Future News that the connectivity issues that affected check-in kiosks and electronic gates at airports last week are the result of a distributed denial of service (DDoS) attack. Such attacks work by flooding systems with junk traffic, disrupting their operations. CBSA’s spokesperson said that they had restored all systems within a few hours. The Montreal Airport Authority (ADM) told the Canadian newspaper La Presse that a computer outage at check-in kiosks caused significant delays in the processing of arrivals for over an hour at border checkpoints throughout the country, including Montreal-Trudeau International Airport.

CBSA has not disclosed how a DDoS attack managed to breach the computer system used by check-in kiosks at airports. This system is supposed to be on a closed circuit, meaning it should not be connected to the internet, La Presse reported. CBSA did not respond to request to comment.

read more

MOVEit Campaign Continues Affecting <900 Schools in Almost Every US State.

May 30, 2023

U.S. educational nonprofit National Student Clearinghouse (NSC) has disclosed a data breach affecting 890 schools using its services across the United States. Attackers gained access to its MOVEit managed file transfer (MFT) server on May 30 and stole files from nearly 900 colleges and universities across the U.S. The stolen information includes personally identifiable information such as Social Security numbers and dates of birth.

The attack on NSC was one of several involving MOVEit that had wide-ranging downstream effects.

read more

Wide-ranging Ransomware Attack Takes Down Local County Government in Alabama

July 20, 2023

The local government of George County, Alabama was thrown into chaos this weekend when ransomware actors used a discrete phishing email to gain deep access to the county’s systems. The ransomware attack took down nearly all of the government’s in-office computers.

The attack is the latest in a string of incidents affecting counties across the U.S., including ones in Delaware, California, South Carolina, New Jersey and Oregon as well as major metropolitan areas like Oakland and Dallas. Ransomware groups have shown little preference, targeting both small counties and large ones alike. The second quarter of 2023 saw 59 attacks, far above the 51 seen in the second quarter of 2022.

read more