Large-scale cyberattack halts Red Cross work reuniting families, exposes confidential data
Full article568 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The sensitive and confidential data for more than 500,000 individuals helped by the organization was exposed.
A cyberattack compromised personal and confidential data on more than half a million people helped by at least 60 Red Cross and Red Crescent organizations around the world, the International Committee of the Red Cross announced Wednesday.
The organization said the exposed information belonged to highly vulnerable groups, including families separated by conflict.
“An attack on the data of people who are missing makes the anguish and suffering for families even more difficult to endure. We are all appalled and perplexed that this humanitarian information would be targeted and compromised,” said Robert Mardini, ICRC’s director general. “This cyber-attack puts vulnerable people, those already in need of humanitarian services, at further risk.”
The hack compromised personal data including names, location and contact information of 515,000 individuals served by the group, including children and detainees. Login information for roughly Red Cross and Red Crescent staff and volunteers was also compromised.
ICRC clarified in a statement Jan. 21 that the attack was specifically targeted at its servers, not the Swiss company hosting them. No suspects have been identified yet.
International human rights organizations and nonprofits are popular targets for attackers. The United Nations confirmed in September it was hit earlier in the year by attackers that breached its infrastructure and accessed. The Red Cross has been a strong voice in calling for an end to cyberattacks against health care facilities.
Mardini urged those responsible for the attack to “do the right thing” and “not share, sell, leak or otherwise use this data.” There is currently no indication the data has been shared online.
As a result of the attack, the ICRC temporarily shut down its “Restoring Family Links” program, which helps reunite families separated by conflict, disaster, or migrations. IRIC is “working as quickly as possible to identify workarounds to continue this vital work,” according to a news release.
Updated 1/21/2022: Updated with additional information about the attack.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/large-scale-cyberattack-halts-red-cross-work-reuniting-families-exposes-confidential-data/