African Union’s System Crashes Due to a Severe Cyber Attack

African Union’s System Crashes Due to a Severe Cyber Attack

The African Union has been hit by a cyber attack that has caused an unscheduled suspension of its systems, according to an internal memo obtained by The Reporter.

The attack on the AU data center began on March 3, 2023, resulting in services and applications becoming unavailable. Sources indicate that over 200 corrupted devices have been discovered and are being cleaned at a facility outside AU headquarters. While the cloud-based data is secure, staff cannot access it.

The memo, written by Monique Nsanzabaganwa (PhD), the AU Commission’s deputy chairperson, describes the cyber attack as “massive” and reports that it has compromised numerous IT assets. The memo goes on to say that some applications are still operational, and the Management Information System (MIS) can recover some of the lost data.

Nonetheless, all the impacted devices must be cleaned before being granted internet access again. The cause of the attack is still unclear, and it’s uncertain whether it was an external attack or an internal breakdown. AU officials and stakeholders are working to restore service.

However, employees have reported being unable to use their work emails or the internet for over a week. Neither Esther Azaa Tankou, Head of Information Division at the AUC, nor Wynne Musabayana, the AUC’s head of communication, have confirmed or denied the attack.

Meanwhile, Molalet Tsedeke, the AU’s Media Center Coordinator, has stated that the institution is experiencing an IT system issue and is trying to determine the root cause. The Reporter’s queries to officials at the Information Network Security Agency (INSA) went unanswered.

Massive DDoS Attack Sets New Record: 158.2 Million Packets Per Second

Massive DDoS Attack Sets New Record: 158.2 Million Packets Per Second

Akamai recently reported on one of the largest DDoS attacks against a customer in the Asia-Pacific region, which was successfully mitigated by the company. During the attack, the targeted server received a massive influx of garbage requests, depleting its capacity. At its peak, the attack generated 900.1 gigabits per second and 158.2 million packets per second of traffic.

In September 2022, Akamai faced another record-breaking DDoS attack against a client in Eastern Europe, with a volume of packets sent per second reaching 704 million. The attack was distributed across Akamai’s scrubbing network, primarily originating in APAC, the most heavily targeted region. Despite this, the top five scrubbing centers for traffic accounted for less than 12% of the total traffic.

Akamai Prolexic’s industry-leading combination of platform, people, and processes helped mitigate the attack. The company’s dedicated defense capability, six global locations, and more than 225 frontline responders with decades of experience were crucial in thwarting the attack. The incident response plans for DDoS attacks were optimized by developing custom runbooks, performing service validations, and conducting operational readiness drills.

The Cyber Security and Infrastructure Security Agency (CISA) recommends implementing mitigation controls for critical subnets and IP spaces in your network. DDoS security controls should be deployed in an always-on mitigation posture to reduce the burden on incident responders during an attack. Situation response plans and runbooks should be updated regularly to ensure they are responsive to changes in the situation.

Cloudflare also faced a massive DDoS attack against Wynncraft, a Minecraft server that is one of the largest in the world, peaking at 2.5 terabits per second. These attacks highlight the critical need for robust defense strategies against DDoS attacks.

SAS Hit by Cyber Attack: Customer Data Breached

SAS Hit by Cyber Attack: Customer Data Breached

On Tuesday (14th of Feb) evening, Scandinavian airline SAS (SAS.ST) experienced a cyber attack that resulted in the leaking of customer information from its app and website. The hack caused the carrier’s website to become paralysed. SAS has advised customers not to use the app and website as a precautionary measure. However, the airline later announced that it had resolved the problem.

Karin Nyman, head of press at SAS, stated that the company was working on remedying the attack on its app and website at the time of the incident. She also cautioned customers that logging onto the app posed a risk of obtaining incorrect information. As the attack was ongoing, Nyman refrained from providing further details.

Reports suggested that customers who tried to log into the SAS app were directed to the wrong accounts and had access to the personal details of others. This issue was reported by customers in Norway as well.

Several Swedish companies and organisations have been targeted by presumed cyber attacks recently. On Tuesday, Sweden’s national public television broadcaster, SVT, experienced a temporary shutdown. The broadcaster attributed the attack to a group called “Anonymous Sudan,” which posted on Telegram that Swedish media would be targeted due to Koran burnings in Sweden.

Top 25 cyber attacks of all time

Top 25 cyber attacks of all time

Here’s the list of top 25 cyber attacks of all time:

 

  1. SolarWinds: The SolarWinds attack, which was revealed in December 2020, impacted government agencies and businesses around the world. The attack involved attackers infiltrating the software supply chain of SolarWinds, a provider of network management software, and distributing malware to customers through updates.

  2. Marriott data breach: In November 2020, Marriott revealed that hackers had gained access to the reservation system of its subsidiary, Starwood Hotels & Resorts, and had accessed the personal data of up to 500 million guests.

  3. Colonial Pipeline ransomware attack: In May 2021, the Colonial Pipeline, which transports fuel along the East Coast of the United States, was hit by a ransomware attack that forced the company to shut down operations. The attack had a significant impact on fuel supplies in the region.

  4. Capitol One data breach: In July 2019, the personal data of over 100 million individuals was exposed in a data breach at Capital One. The attack was carried out by a former Amazon Web Services employee.

  5. Equifax data breach: In September 2017, the personal data of 147 million individuals was exposed in a data breach at credit reporting company Equifax. The attack was the result of a vulnerability in the company’s web application software.

  6. Yahoo data breaches: In December 2016, Yahoo disclosed that it had suffered two data breaches, one in 2013 and one in 2014, which exposed the personal data of all 3 billion of its users.

  7. Target data breach: In December 2013, the personal data of 40 million credit and debit card users was exposed in a data breach at retail giant Target. The attack was the result of malware that was installed on the company’s point-of-sale systems.

  8. Sony Pictures hack: In November 2014, Sony Pictures was the victim of a cyber attack that exposed sensitive emails and personal data of employees. The attack was later attributed to North Korea.

  9. Anthem data breach: In February 2015, the personal data of 78.8 million individuals was exposed in a data breach at health insurance company Anthem. The attack was the result of a spearphishing campaign.

  10. JPMorgan Chase data breach: In July 2014, the personal data of 76 million households and 7 million small businesses was exposed in a data breach at JPMorgan Chase. The attack was attributed to Russian hackers.

  11. Uber data breach: In November 2017, Uber disclosed that it had suffered a data breach in October 2016 that exposed the personal data of 57 million riders and drivers.

  12. OPM data breach: In June 2015, the personal data of 22 million individuals was exposed in a data breach at the Office of Personnel Management (OPM). The attack was attributed to Chinese hackers.

  13. Deloitte data breach: In October 2017, Deloitte disclosed that it had suffered a data breach in March 2016 that exposed the personal data of clients and the confidential emails of Deloitte employees.

  14. eBay data breach: In May 2014, the personal data of 145 million eBay users was exposed in a data breach. The attack was the result of the attackers gaining access to the company’s corporate network through the use of compromised employee credentials.

  15. Home Depot data breach: In September 2014, the personal data of 56 million payment cards was exposed in a data breach at Home Depot. The attack was the result of malware being installed on the company’s point-of-sale systems.

  16. Adobe data breach: In October 2013, the personal data of 153 million Adobe users was exposed in a data breach. The attack was the result of the attackers gaining access to Adobe’s network through the use of compromised employee credentials.

  17. Dyn DDoS attack: In October 2016, internet performance company Dyn was the victim of a distributed denial of service (DDoS) attack that caused widespread internet disruption. The attack was launched using the Mirai botnet, which was made up of compromised IoT devices.

  18. Snapchat data breach: In December 2013, the personal data of 4.6 million Snapchat users was exposed in a data breach. The attack was the result of a third-party app that was able to access Snapchat’s user database.

  19. LinkedIn data breach: In May 2016, the personal data of 117 million LinkedIn users was exposed in a data breach. The data had been stolen in a 2012 data breach and was later sold on the dark web.

  20. Airbnb data breach: In November 2014, Airbnb disclosed that it had suffered a data breach in October 2014 that exposed the personal data of its users. The attack was the result of an employee’s account being compromised.

  21. Dropbox data breach: In August 2016, it was revealed that the personal data of 68 million Dropbox users had been exposed in a data breach that occurred in 2012. The data had been stolen and was later sold on the dark web.

  22. Twitter data breach: In November 2017, Twitter disclosed that it had suffered a data breach in October 2017 that exposed the personal data of 330 million users.

  23. TalkTalk data breach: In October 2015, the personal data of 157,000 TalkTalk customers was exposed in a data breach. The attack was the result of a SQL injection attack.

  24. Ashley Madison data breach: In July 2015, the personal data of 37 million users of the Ashley Madison dating website was exposed in a data breach. The attack was carried out by a group calling itself the “Impact Team.”

  25. VTech data breach: In November 2015, the personal data of 4.2 million children and 200,000 adults was exposed in a data breach at VTech, a manufacturer of children’s electronic toys. The attack was the result of a SQL injection attack.

These 25 cyber attacks demonstrate the importance of good digital hygiene and the need for individuals and businesses to take steps to protect themselves and their data against cyber threats. By being aware of the risks and taking steps to protect against them, individuals and businesses can help reduce the chances of falling victim to a cyber attack.

US, UK: Russia responsible for cyberattack against Ukrainian banks

US, UK: Russia responsible for cyberattack against Ukrainian banks

WASHINGTON, Feb 18 (Reuters) – Russian military hackers were behind a spate of distributed denial of service (DDoS) attacks that briefly knocked Ukrainian banking and government websites offline, the United States and the United Kingdom said on Friday.

U.S. deputy national security adviser Anne Neuberger told journalists at the White House that Washington was seeking to hold Russia to account for its aggressive moves in cyberspace.

“Russia likes to move in the shadows and counts on a long process of attribution,” Neuberger said. “In light of that, we’re moving quickly to attribute the DDoS attacks. We believe the Russian government is responsible for widespread attacks on Ukrainian banks this week.”

Neuberger said that Americans have data showing that infrastructure connected with Russia’s military agency, generally known as the GRU, “was seen transmitting high volumes of communication to Ukraine-based IP addresses and domains.”

In a simultaneous announcement, British officials said the GRU was “almost certainly involved” in the DDoS, which works by flooding targeted websites with a firehose of data.

“The attack showed a continued disregard for Ukrainian sovereignty,” Britain’s Foreign Commonwealth and Development Office (FCDO) said in a statement. “This activity is yet another example of Russia’s aggressive acts against Ukraine.”

“This disruptive behavior is unacceptable,” the FCDO said.

Russia has denied any role in the DDoS, which inflicted relatively limited disruption on Tuesday.

Kyiv had already blamed Moscow for the DDoS amid heightened tensions since Russia began massing troops near the border, raising fears Russia was planning to attack. The Kremlin has denied it plans to push deeper into the country.

Neuberger said that while the denial of service had “limited impact,” the recent spate of malicious digital activity could be a prelude to “more disruptive cyberattacks accompanying a potential further invasion of Ukraine’s sovereign territory.”

Queensland hospitals and nursing centers afflicted by cyber attack

Several Queenland hospitals and nursing centers have been affected by a cyberattack, which has caused several disruptions in internal systems.
According to news sources the entire UnitingCare Queensland IT system was attacked by ransomware software, with all UCQ hospitals and nursing homes working without IT systems until further notice.

Among a number of nursing centers that have been affected in Queenland, Wesley and St.Andrews war hospitals in Brisbane have also had inoperable systems.

The cyber attack has impacted all operational IT systems including staff emails and patient’s booking systems for treatments, forcing onsite staff to revert to paper-based operations for the foreseeable future. Doctors have been told not to expect to be able to access vital patient information and details like x-rays. UnitingCare Queensland confirmed the attack but wasn’t able to provide an estimation when the systems could be brought back up.

“On Sunday, 25th of April, UnitingCare Queensland was impacted by a cyber incident. As a result of this incident, some of the organisation’s digital and technology systems are currently inaccessible,” a UnitingCare spokesperson said. “It is not possible to provide a resolution timeframe at this stage, however, our Digital and Technology Team are working to resolve this issue,”

It is currently unclear if any of the patients’ personal data was breached during the attack.

Ukraine accuses Russian networks of massive cyber attacks

Ukraine accuses Russian networks of massive cyber attacks

Ukraine on Monday accused Russian internet networks of massive attacks on Ukrainian security and defence sites, but did not provide details about any damage or say who believed it was behind the attack. Kyiv has accused Moscow of orchestrating major cyber attacks as part of a “hybrid war” against Ukraine, contradicting Russia’s denial.
However, a declaration by the National Security and Defence Council of Ukraine did not show who it believed that had organised the attacks or give any details of the effect that the intrusions had on Ukrainian cybersecurity.

The attacks began on 18 February and were aimed at websites of the Ukrainian Security Service, the Council itself and some other state institutions and strategic companies, it said in a statement. “It was shown that the addresses of certain Russian transport networks were the source of these coordinated attacks,” the Council said. The Council added that the attacks attempted to infect the government’s vulnerable web servers with a virus that added them to a bot-net used for DDoS attacks against other resources.
A DDoS attack is a cyber attack where hackers try to flood a network with unusually high traffic volumes to paralyze it.

Ukraine’s and Russia’s relations have been very problematic since the Russian annexation of Crimea in Ukraine in 2014 and participation in a conflict in the eastern Donbass region of Ukraine, which, according to Kiev, has killed 14000 people.

This month, the Ukrainian army said that five of their staff were killed last week in the east of the country, despite a ceasefire with pro-Russian separatists. On Monday, the military informed another dead soldier who had been killed by a rocket propelled grenade.

France identifies hackers connected to Russia in a large cyberattack

France identifies hackers connected to Russia in the big cyberattack

The hackers breached the software company that listed by Airbus, Orange and the French Ministry of Justice as their clients.

France’s ANSSI cybersecurity agency on Monday said that “several French entities” had been attacked, and linked the attacks to a group of Russian hackers who are thought to be behind some of the most devastating cyberattacks in recent years.

The agency said that it had identified “an intrusion campaign” in which hackers, linked to the Russian military intelligence agency GRU, committed the French software firm Centreon to install two pieces of malware on their clients’ networks. The “support chain attack” is similar to the recently discovered commitment of U.S. business software SolarWinds which breached several US government agencies and many others.

The intrusion campaign began in late 2017 and lasted until 2020, ANSSI said, adding that “it most affected information technology providers, especially web hosting providers.”

Centreon said in a statement that “he has taken note of the information,” adding that “it has not been shown at this stage that the identified vulnerability refers to a commercial version provided by Centreon during the period in question.”

The company lists Airbus, Air France, Thales, ArcelorMittal, Electricité de France (EDF) and the signature of Orange telecommunications among its clients, as well as the French Ministry of Justice. It is not clear how many or what organizations were penetrated through the software hack.

ANSSI said that the campaign “shares several similarities with previous campaigns attributed to the established intrusion called Sandworm,” which “is known to lead consecutive intrusion campaigns before focusing on specific goals that fit their strategic interests within the victim pool.”

The hacker group Sandworm has been linked to GRU by cybersecurity authorities and experts. The group is believed to be behind some of the most damaging cyberattacks in recent history, including the NotPetya ransomware outbreak in 2017 and the attacks on the Winter Olympic Games in South Korea.

European diplomats imposed sanctions on several officers of the Russian intelligence unit linked to Sandworm in relation to cyberattacks. The U.S. authorities also accused the hackers belonging to the same group and said the group was suspected to be behind the 2017 cyberattack at the then president of the Emmanuel Macron La République En Marche party.

The public mention of Sandworm by the French authorities is rare, as the country has traditionally been hesitant to attribute cyberattacks.

Cyberpunk 2077 developer, CD Projekt, hit by cyber attack

Cyberpunk 2077 developer, CD Projekt, hit by cyber attack

CD Projekt has been hit by a cyber attack, which compromised some of its internal systems including the source code to its flagship Cyberpunk 2077 game, dealing another blow for the Polish video game maker.

“An unidentified actor gained unauthorized access to our internal network, collected certain data belonging to CD PROJEKT capital group, and left a ransom note,” the company said on Twitter on Tuesday, adding it would not negotiate with the actor.

CD Projekt has been in the limelight recently amid the troubled roll-out of Cyberpunk 2077, leading Sony to pull the game from its PlayStation Store after just a week.

The cyber attacker gained access to source codes to Cyberpunk 2077, Wither 3, card game Gwent and an as yet unreleased version of Witcher 3, CD Projekt said.

The company’s shares were down 3% at 276 zlotys by 0948 GMT after dropping as much as 6.3%.

CD Projekt said its backup systems remained intact and it was still investigating the incident but to the best of its knowledge, the compromised systems did not contain any personal data of its players or users of its services.

VTB Capital analyst Vladimir Bespalov said the most immediate negative effect would be the need to allocate resources to repair the damage, which might slow down somewhat the company’s work on fixing Cyberpunk 2077.

“It is possible that since CD Projekt informed about the attack on its Twitter account and not via a regulatory filing, it is not worried that the attack has caused significant negative effect or the data might be irrelevant,” said Kacper Kopron, an analyst at Trigon DM.

Kopron saw the main risk for CD Projekt would be further losing trust among customers after the disappointing premiere of Cyberpunk 2077.

CD Projekt said it would not comment beyond the statement published on its social media account.

Shares in the company plunged at the end of last year amid the Cyberpunk roll-out problems, from a record high of 464.2 zlotys. They recovered losses after the recent Reddit-fueled retail frenzy caused short sellers to close their positions.

Reserve Bank of New Zealand’s IT system breached in cyber attack

The Reserve Bank of New Zealand's IT system breached in cyber attack

New Zealand’s reserve bank is working with cyber security specialists to assist it understand the affects of a breach of a third-party file-sharing system used to share and store info.

The Reserve Bank of New Zealand (Te Pūtea Matua) stated it had been instructed the assault was not particularly geared toward it, and other users of the file-sharing system from Accellion, generally known as File Transfer Application, have been also compromised.

The financial institution, alongside cyber safety specialists, is working to ascertain “the nature and extent of information that has been potentially accessed” and stated the compromised information “may include” commercially and personally delicate info.

Adrian Orr, governor of the Reserve Bank of New Zealand, stated the breach is contained and the financial institution is at present working to establish what info has been affected.

“We are actively working with domestic and international cyber security experts and other relevant authorities as part of our investigation,” Orr stated in a press release. “This contains the Government Communications Security Bureau’s National Cyber Security Centre [NCSC], which has been notified and is offering steering and recommendation.

No additional particulars of the assault have been accessible. “We recognise the public interest in this incident,” Orr added. “However, we are not in a position to provide further details at this time.”

Part of the explanation for not revealing extra particulars is to keep away from adversely have an effect on the investigation and the steps being taken to mitigate the breach, stated the financial institution.

The financial institution stated its predominant features are unaffected and it stays open for enterprise. “Our core functions and New Zealand’s financial system remain sound, and Te Pūtea Matua is open for business,” stated Orr. “This includes our markets operations and management of the cash and payments systems.”

The system has been secured and brought offline whereas investigations are below means and the financial institution is speaking with system customers about other ways to share information securely. “It will take time to understand the full implications of this breach, and we are working with system users whose information may have been accessed,” it stated.

New Zealand’s monetary sector was shaken just lately by a significant attack on the country’s stock exchange, which was hit by an unprecedented volumetric distributed denial of service (DDoS) attack final August. That assault was one other instance of cyber attackers breaching by a third-party provider’s service. 

Like central banks, inventory exchanges are very important to a functioning economic system, and even a brief outage may cause financial havoc.

New Zealand’s NCSC published a report in November that stated the nation’s “nationally significant organisations continue to be the target of frequent cyber attacks from a range of malicious actors”.

The report stated that from July 2019 to the tip of June 2020, the NCSC recorded 352 cyber safety incidents at nationally important organisations, in contrast with 339 incidents within the earlier 12 months. It added that 30% have been linked to state-sponsored actors.

The NCSC identified that the variety of incidents recorded was a small proportion of the overall incidents affecting New Zealand and New Zealanders. “This is because of our focus on providing support for nationally significant organizations and response to potentially high-impact cyber security events,” it stated.