Singapore health system breach likely conducted by APT group, government says
Full article637 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The minister of communications and information says the attackers used sophisticated methods to conduct the hack and evade detection.
The government of Singapore says attackers responsible for a recent breach, largely being called the country’s worst in history, are likely linked to a state-backed advanced persistent threat group.
S. Iswaran, Singapore’s minister of communications and information, said in a statement to the country’s parliament Monday that a government analysis of the attack shows that it is the work of known state-linked threat actors. Iswaran stopped short of naming the APT group in question, citing “national security reasons.”
“The APT group that attacked SingHealth was persistent in its efforts to penetrate and anchor itself in the network, bypass the security measures, and illegally access and exfiltrate data,” Iswaran said in a statement.
According to the AFP news agency, third-party security researchers had already indicated that the attack was linked to state-backed hackers. Iswaran’s remarks shed more light on the perceived sophistication behind the attack, albeit without attribution.
Singapore initially announced the attack on July 20, Reuters reported. The personal information of 1.5 million patients of SingHealth, a national group of health care institutions, including that of Prime Minister Lee Hsien Loong. Additionally, the hackers made off with the outpatient dispensed medication records of 160,000 patients. But for the rest, the stolen data did not include medical records.
According to Iswaran, between June 27 and July 4, the hackers infected a computer on SingHealth’s network and “stealthily” made their way to servers hosting the records that were eventually stolen.
“The attacker used advanced and sophisticated tools, including customised malware that was able to evade SingHealth’s anti-virus software and security tools. After establishing a foothold in the network, the attacker took steps to remain in the system undetected, before stealing the patients’ information,” Iswaran said.
The government has set up a four-person inquiry panel to further investigate the incident. In addition, consulting firm PricewaterhouseCoopers (PWC) and the Singapore Cyber Security Agency are working to mitigate any lingering security issues in the systems that were compromised, according to Reuters.
Singapore is seen as a leader among its Southeast Asian neighbors in cybersecurity, investing heavily in the field. For the island nation of roughly 5.7 million people, the number affected by the breach reflects a more than quarter of the population.
“We will do our utmost to strengthen our cybersecurity. But it is impossible to completely eliminate the risk of another cyber-attack. This is an ongoing battle with potential cyber attackers who are constantly developing their capabilities and seeking out new vulnerabilities,” Iswaran said.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/singapore-singhealth-hack-apt-iswaran/