Ukrainian MP suggests hackers used phishing or bribery in state registry cyber attack

Nation

23 December 2024, 03:48 PM

During a large-scale cyberattack on state registries on Dec. 19, a top-level account was logged into the system, Oleksandr Fediyenko, a member of the Parliamentary Committee on National Security, Defense and Intelligence, told Radio Liberty.

The breach was well-prepared and involved accessing the system through a high-level account. The hackers might have used phishing techniques or bribed an employee with access to the registries.

"There could be components of recruiting an employee of this institution, there could be a multi-level mechanism of planting a USB drive to be inserted by someone within the internal perimeter," Fediyenko said.

“There could be phishing of computers of all employees who might work with the closed circuit, remotely, which is generally prohibited.”

The hackers successfully breached the registry infrastructure, and the timeline for data recovery depends on whether the databases were damaged.

"I think within a week or two, the data will start to be gradually restored," said Fediyenko.

Cyberattack on Ukraine's state registries on Dec. 19

Vice Prime Minister for European and Euro-Atlantic Integration Olga Stefanishyna reported on Dec. 19 the largest cyberattack in recent times from Russia on Ukrainian state registries, including the Civil Status Acts Registry, the state register of legal entities and entrepreneurs, and the real estate rights registry.

The government official said it would take up to two weeks to restore the registries, and no personal data leak has been confirmed as a result of the attack.

On Dec. 20, Andriy Kovalenko, head of the Center for Countering Disinformation at the National Security and Defense Council (NSDC), reported that the cyberattack on the Ministry of Justice’s state registries was carried out by Russian hackers linked to the Main Directorate of the General Staff of the Russian Ministry of Defense (GRU).

Later, Deputy Defense Minister Kateryna Chornohorenko stated that the Defense Ministry’s registries are operating as usual after the cyberattack, but temporarily suspended the processing of deferments from mobilization through the Reserve+ application.

Інші новини

Все новости