Bringing cybersecurity globally to critical and complex key activities
On Monday 10 October 2022, the management of the French department of Seine Maritime issued a press release announcing that its networks would be cut off and that its services would be severely degraded. An investigation was opened by the cybercrime prosecutor's office for cyberattacks. Although no ransom demand has been communicated for the moment, the modus operandi of the attack strongly suggests ransomware. While it will still be possible to deal with the department by telephone and on paper, many online services, particularly for disabled people, will remain offline for an indefinite period, which will have a significant impact on many citizens of Seine-Maritime. Read more about it : here
One of the spokesmen for the pro-Ukraine hacktivist group TeamOneFist claimed responsibility for a major attack on the Russian satellite network "Gonets" during the "Pleiades" cyberoperation. The attack would have disabled the satellite network. He claims to have penetrated the CRM/customer database, which is referenced by the network in order to send/receive messages. Having failed to download the database, which was under heavy surveillance, the group decided to destroy it without being detected. From this data, the group discovered that the Gonets network was used by 97 organizations to transmit sensitive data, including fishing companies, energy companies and the FSB. Read more about it : here
According to Valery Marchive, managing editor of "MAG-IT", an attack on the Belgian-based Casa Shop on August 8 was claimed by the cybercriminal group AvosLocker. The amount of the ransom or the nature of the data has not been communicated, however it seems that no customer data has been stolen. Read more about it : here
A phishing campaign is currently targeting Poland, with attackers posing as "binzes.gov.pl.", a public service for entrepreneurs. The email typically contains: "The notification will be available on your authorised account until 09-17-2022 and if you do not read it within the specified period, appropriate consequences will be triggered (...)". A copy of the notification mentioned in the fake email is included in the email attachment but it is a fake document which is actually a malicious web script. When it is opened, the computer is infected. Read more about it : here
On the morning of 6 September, the pro-Ukraine hacktivist group "IT Army of Ukraine" claimed to have attacked the website of the bank "Gazprombank". The bank, wholly owned by Gazprom, is the third largest bank in Russia in terms of assets and investments. The website was still inaccessible on 6 September at 4pm. Read more about it : here
Eni, too, after Gse, reports that it was attacked on the IT level. But with minor damage, unlike Gse, which is still down. Various experts suspect an attack from Russia, at a time when energy plays a critical geopolitical role Read more about it : here
According to officials at the Swedish website val.se, the site faced serious technical problems as a result of DDoS cyber attacks from 10 to 11 September. The head of the authority's secretariat said on 11 September: "There have been three DDoS attacks against val.se, one yesterday and two today. The most recent one is still ongoing. During the elections, the Swedish regional governments also reportedly experienced problems with their telecommunication facilities, but this did not disrupt the elections or their outcome. Read more about it : here
According to the cyber media, the cyber actor PoCExploiter has announced that the telecommunications operator Vodafone Italy has had approximately 309 gigabytes of data stolen. This data may already be exposed on the net, although no information is available at the moment to confirm this. Read more about it : here
On 14 September 2022, LockBit 3.0 claimed responsibility for a ransomware attack on the French online company artdis.fr. The company specialises in express delivery throughout France and Europe, storage, order picking and redistribution. The data will be released on 29 September if the ransom is not paid. No information on the nature of the data has yet been provided. Read more about it : here
The company OrangeCyberFR has confirmed the publication of a file containing the personal information of several hundred French customers, which is currently being sold on a deep web forum. Read more about it : here