ZeroHour
CyberScooppublished ()ingested @snlyngaas

COVID-19 hacking extends to supply chain for controlling vaccine temperature, IBM says

criticalRansomware exploited in the wildimportance 60
Full article858 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The phishing campaign began in September and has targeted organizations in six countries in Europe and Asia, according to IBM.

vaccine, coronavirus, COVID-19, research, supply chain, pandemic
(Getty Images)

As drug companies turn their attention from the development to the deployment of a coronavirus vaccine, well-resourced hackers are doing the same.

IBM researchers on Thursday revealed a global spearphishing campaign they said was aimed at companies involved in the storage and transport of vaccines in temperature-controlled environments. Those controls allow the medicine to be sent to far-flung places. IBM suspects the attackers are tied to a government, but they said they didn’t have enough evidence to determine which one.

The attackers’ goal may have been to steal login credentials from those companies in order to gain future access “to corporate networks and sensitive information relating to the COVID-19 vaccine distribution,” the researchers said. It’s unclear how successful the phishing has been.

The findings illustrate how virtually every step of the months-long project by drug companies to produce a vaccine has been targeted by hackers. The U.S. government accused Chinese hackers of targeting vaccine research in May, and examples of similar espionage operations tied to North Korea and Russia have also emerged.

The phishing campaign uncovered by IBM began in September and has targeted organizations in six countries in Europe and Asia. All of the organizations appear to be associated with a supply-chain program run by Gavi, an international organization that handles vaccines.

The attackers targeted companies from the energy, manufacturing and software sectors that are supporting the distribution of a vaccine (IBM did not name any of them.) With access to internal communications at such companies, the attackers could gather information on the “infrastructure that governments intend to use to distribute a vaccine to the vendors that will be supplying it,” the IBM researchers said.

“This adversary picked the perfect cover – one that would pass scrutiny and suspicion,” Claire Zaboeva, senior cyber threat analyst at IBM Security X-Force, said in an email.

That cover saw the hackers pose as an executive at Haier Biomedical, a supplier involved in Gavi’s vaccine supply-chain program, and send phishing emails to companies supporting transportation needs for the program. China-based Haier touts itself as “the world’s only complete cold chain provider,” or organization that offers the full range of temperatures needed for storing biomedical equipment.

The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency on Thursday highlighted the IBM research and urged organizations to guard against the hacking.

“Today’s report highlights the importance of cybersecurity diligence at each step in the vaccine supply chain,” said Josh Corman, CISA’s chief strategist for health care. “CISA encourages all organizations involved in vaccine storage and transport to harden attack surfaces, particularly in cold storage operation, and remain vigilant against all activity in this space.”

More Scoops

Sean Plankey, of Pennsylvania, responds to questioning during Senate Committee on Homeland Security and Governmental Affairs hearings to examine his nomination to be Director of the Cybersecurity and Infrastructure Security Agency, of the Department of Homeland Security, in the Dirksen Senate office building, in Washington, DC, on Wednesday July 24, 2025. (Mattie Neretin/CNP/Sipa USA)

Plankey vows to boot China from U.S. supply chain, advocate for CISA budget

But Trump’s pick to lead CISA sidestepped questions about alleged past or future election manipulation claims.

Wheat is displayed for judging at the Cedar County Fair on July 13, 2018 in Tipton, Iowa. (Photo by Scott Olson/Getty Images)

Ransomware gang strikes Iowa agriculture business New Cooperative, the latest hack on food supply chain

WASHINGTON, DC – AUGUST 25: U.S. President Joe Biden speaks during a meeting about cybersecurity in the East Room of the White House. Members of the Biden cabinet, national security team and leaders from the private sector attended the meeting about improving the nation’s cybersecurity. (Photo by Drew Angerer/Getty Images)

White House rolls out pipeline, supply chain security initiatives as companies pledge billions in cyber spending

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/coronavirus-vaccine-hacking-ibm/