Government

Industry

Secret Network of US Marshall Infiltrated by Hackers

February 17, 2023

On February 17 the U.S. Marshals Service “discovered a ransomware and data exfiltration event affecting a stand-alone USMS system.” The unidentified hackers infiltrated a network used by the Technical Operations Group (TOG) to track fugitives, reports the Washington Post. The precise activities of the service are kept secret.

US Marshals Service spokesperson Drew Wade said no one in the witness protection program is in danger because of the breach. Nevertheless, the official said, the incident is significant, affecting law enforcement sensitive information pertaining to the subjects of Marshals Service investigations.

The agency developed a workaround enabling the unit to continue operations and efforts to track down fugitives. “Most critical tools” related to the affected computer network “were restored within 30 days of the breach discovery” in February, Wade told CNN, declining to explain what those critical tools were. The network remains compromised nearly 3 months after being hit.

The Technical Operations Group (TOG) network provides surveillance capabilities to track fugitives. The group operates 29 field offices in the US and Mexico and uses high-tech methods to track fugitives.

read more

225K Customers Without Power in Ukraine Power Grid Hack

December 23, 2015

On the evening of December 23, 2015, the cursor on the grid operator’s computer screen started to move on its own. Hackers had struck the power distributor company Prykarpattyaoblenergo in Ukraine, disabling one circuit breaker after another. It was one of a kind cyberattack on a power grid executed successfully. Soon after, half of the population of Ukraine’s Ivano-Frankivsk region were in the dark without power for up to six hours. While the power was restored in a few hours, it took months for all the control centers to become fully operational again.

The hack on Ukraine’s power grid was a first-of-its-kind attack that sets an ominous precedent for the security of power grids everywhere.

read more

Hacktivists Take Down Multiple Japanese Government Websites

September 6, 2022

A pro-Russia hacker group has claimed to be involved in attacks on Japanese government and company websites.

The DDoS attack on the e-Gov website shut down the site for a few hours on Sept. 6. It then became inaccessible again around noon on Sept. 7 until early morning, Sept. 9. The e-Gov website allows users to request disclosure of administrative documents and provides information on laws and regulations. The site receives about 7.8 million hits a day.

In addition, between Sept. 6 and 9, the attacks made 23 government websites temporarily inaccessible. These sites belonged to the Digital Agency, the Internal Affairs and Communications Ministry, the Education, Culture, Sports, Science and Technology Ministry and the Imperial Household Agency. Some sites of credit card business JCB Co. were inaccessible, while websites of social media company mixi, Inc. were also hard to access.

On September 6, 2022, the website of the Nagoya Port Authority was unreachable for about 40 minutes.

read more

Accellion-related Data Breach Reported by QIMR Berghofer

December 25, 2020

The QIMR Berghofer Medical Research Institute has also announced today a data breach caused by the Accellion FTA service and has provided more detailed information regarding what information was accessed.

According to the research institute, the data breach appears to have occurred on December 25, 2020, when threat actors accessed approximately 4 percent, or 620MB, of data stored on the Accellion FTA service.

QIMR Berghofer states that they received their first notification to install Accellion’s patch on January 4th, 2021. It wasn’t until February 2nd, 2021 that Accellion notified them that they had suffered a data breach.

“The first notification QIMR Berghofer received from Accellion was on 4 January 2021, when the company advised the Institute to apply a security patch. The Institute immediately took the software offline and applied the patch.”

“Accellion notified QIMR Berghofer on Tuesday 2 February 2021 that it believed the Institute had been affected by the data breach, which has also affected a number of Accellion’s other Australian and international clients,” QIMR Berghofer disclosed in a data breach notice on their website.

read more

Critical Infrastructure Disrupted in Martinique by Prolonged Cyberattack

May 16, 2023

The Caribbean island of Martinique is dealing with a cyberattack that has disrupted internet access and other infrastructure for weeks. The attack began on May 16, forcing officials to isolate the affected systems. Cybersecurity experts were mobilized to help gradually restore their operations.

“Regarding education services, technical solutions are being set up to restore internet access to colleges and high schools. School administrators and the government are coordinating in order to ensure the smooth handling of exams. The government will make every effort to ensure the payment of social benefits,” officials said in a statement.

“Regarding financial services, the community will be able to issue new purchase orders and ensure the payment of bills. These must be filed in paper format from the mail office in Plateau Roy. Concerning aid and subsidy services, the filing of requests must be made in paper format to the office in Plateau Roy due to the unavailability of online platforms.”

read more

Disruption of online vote in Martinique

January 4, 2023

The platform for the online vote on a flag and anthem for the French overseas department of Martinique had to be taken offline, on January 4, 24 hours after the start of the vote. The reason for the disruption was reported to be a cyberattack.

The attack on government servers upended a nearly two-week online voting window that began on Jan. 2. Officials said the attack was not successful but forced them to temporarily shut down the system.

read more

Ransomware Attack at Royal Mail Disrupts International Operations more than a Month

January 10, 2023

The LockBit ransomware operation has claimed the cyberattack on UK’s leading mail delivery service Royal Mail that forced the company to halt its international shipping services due to “severe service disruption.”

Royal Mail refused to pay an $80m (£67m) ransom sought by hackers linked to Russia after the “cyber incident”, which resulted in 11,500 Post Office branches across the UK being unable to handle international mail or parcels fro almost six weeks after the attack. The company has said it is losing £1m a day.

read more

City of Dallas Operations Widely Disrupted by Ransomware Attack

May 2, 2023

The City of Dallas, Texas, has suffered a Royal ransomware attack, causing it to shut down some of its IT systems to prevent the attack’s spread. Local media reported that the City’s police communications and IT systems were shut down Monday morning due to a suspected ransomware attack. This has led to 911 dispatchers having to write down received reports for officers rather than submit them via the computer-assisted dispatch system. The Dallas County Police Department’s website was offline for part of the day due to the security incident.

“Wednesday morning, the City’s security monitoring tools notified our Security Operations Center (SOC) that a likely ransomware attack had been launched within our environment. Subsequently, the City has confirmed that a number of servers have been compromised with ransomware, impacting several functional areas, including the Dallas Police Department Website,” explained a media statement from the City of Dallas. “The City is currently working to assess the complete impact, but at this time, the impact on the delivery of City services to its residents is limited. Should a resident experience a problem with a particular City service, they should contact 311. For emergencies, they should contact 911.”

BleepingComputer has also confirmed that the City’s court system canceled all jury trials and jury duty from May 2nd into today, as their IT systems are not operational. Dallas is the ninth largest city in the United States, with a population of approximately 2.6 million people.

read more

Ransomware Attack Halts Public Postal Services in Greece

March 20, 2022

Ransomware hit ELTA encrypting its systems and halting operations in a major service disruption. “Threat actors exploited an unpatched vulnerability to drop malware that allowed access to one workstation using an HTTPS reverse shell.” To stop the spread, they shut down all data centers. Online parcel tracking and labelling is also down for customers. Full service was restored by April 6th. The attack affected mail system, financial transactions and bill payments.

read more

IT Systems of Hydraulic Office of Corsica Attacked by Ransomware

November 3, 2022

The Hydraulic Office of Corsica was hacked on the night of November 2 to 3. The agents were faced with 33 completely blocked computer systems. They immediately took them offline after the malfunctions were noted. A ransom, the amount of which has not been disclosed, has been demanded.

Two weeks after the event the company published a press release. They needed time to analyze and evaluate the damage on IT infrastructures,. And needed the time to assess the damage before deciding what to do. The company stated that essential activities are carried out normally, and “those relating to customer management will quickly be back to normal” . The problem remains mainly with the accounting and financial management of the organization. A large part of the historical data has been encrypted, “making this data inaccessible at this moment” .

read more