Swiss cheese security? Play ransomware gang milks government of 65,000 files
- Reference: 1709901312
- News link: https://www.theregister.co.uk/2024/03/08/swiss_government_files_ransomware/
- Source link:
A total of 1.3 million files were stolen during the incident at software biz Xplain in May 2023, meaning 5 percent of the entire trove related to the Swiss Federal Administration – a collection of seven federal agencies that alongside the Federal Council comprise the main government departments.
Among them were classified files and sensitive, personally identifiable information (PII) – all of which are believed to be published on the [1]dark web .
[2]
The vast majority of the files (95 percent) were related to the administrative units of various government arms including those concerning justice, police, migration, and internal IT. A smaller proportion (3 percent) related to the Federal Department of Defense, Civil Protection, and Sport, while other departments are only described as being "marginally affected."
[3]
[4]
Despite 65,000 files concerning the Swiss government, the NCSC said 47,413 of these belonged to Xplain itself and 9,040 belonged to the Federal Administration. More than half of these (5,182) included sensitive content such as [5]PII , classified files, passwords, and technical documentation.
[6]Possible China link to Change Healthcare ransomware attack
[7]JetBrains TeamCity under attack by ransomware thugs after disclosure mess
[8]Belgian ale legend Duvel's brewery borked as ransomware halts production
[9]Reminder: Infostealer malware is coming for your ChatGPT credentials
Personal data formed the bulk of this, with names, email addresses, home addresses, and phone numbers accounting for 4,779 of the sensitive files.
Technical documentation on IT systems and software – requirement documents and architecture information – accounted for 278 of these files. Classified files comprised the remaining sensitive files that were stolen, only four of which contained readable [10]passwords , the NCSC said.
"A considerable amount of analysis was required to determine how much data was leaked and the owners of the leaked data," it said in a [11]statement accompanying the full report, available only in German and French.
[12]
"Suitable tools were required to process unstructured data records and make their contents readable. The objects identified as relevant then had to be manually viewed and categorized.
"The various federal offices and service providers involved worked closely under the lead of the NCSC to manage the security incident. This allowed all parties to utilize synergies, make effective use of resources, and save valuable time."
An administrative investigation was launched in August 2023 to fully understand how the breach at Xplain took place and is set to conclude this month. The resulting report will then provide actionable recommendations for the Federal Council to apply with a view to preventing future breaches. ®
Get our [13]Tech Resources
[1] https://www.theregister.com/2024/02/16/dark_web_kids_limit_uk/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZetEOOkNA7D89yBABju5-gAAAMg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZetEOOkNA7D89yBABju5-gAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZetEOOkNA7D89yBABju5-gAAAMg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2024/01/23/serial_data_peddler_faces_prison/
[6] https://www.theregister.com/2024/03/07/china_link_change_healthcare_ransomware/
[7] https://www.theregister.com/2024/03/07/teamcity_exploits_lead_to_ransomware/
[8] https://www.theregister.com/2024/03/07/no_piss_up_in_duvels/
[9] https://www.theregister.com/2024/03/07/more_than_250000/
[10] https://www.theregister.com/2022/11/25/infosec_roundup/
[11] https://www.admin.ch/gov/en/start/documentation/media-releases.msg-id-100315.html
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZetEOOkNA7D89yBABju5-gAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[13] https://whitepapers.theregister.com/
With the type of sensitive industries that [1]Xplain AG works with, one would really expect them to encrypt all stored and transported data, and to keep backups at separate geolocations -- which should have prevented this major leakage and tedious reconstruction work. Their page on the [2]"hacker attack" states that they have " replaced the external operators " as a result ... maybe they had outsourced to some less secure lower-bidder (not good!)?
[1] https://www.xplain.ch/en/
[2] https://www.xplain.ch/en/hackerangriff/
I'm not sure whether encryption of storage or transport would have worked in this case. But I certainly agree that dealing with such sensitive data they should have had better preventive and detective measures in place (which is kind of self-explanatory ex post). I find a rather unsatisfying explanation what Xplain writes in the link you've provided ( «Hackers like "Play" group usually leave no traces» ).
Surely, that must have been a mistake. I mean, why would someone attack Switzerland?! It is, after all, a neutral country and should therefore be exempt from any hostile activity. I do expect and hope that the Federal Council will, with utmost urgency, initiate an information campaign about the country's neutrality to prevent future attacks. Or isn't that what they do in other threat scenarios?
On a more serious note, it's not the only country with its national security freeloading on others. At least, with cyber security that doesn't work so well.
Not sure what you mean by: " it's not the only country with its national security freeloading on others. ". Firstly, it's surrounded very deeply on all sides by friendly countries, so it's military spending is anyway unlikely to be as high as any country bordering Russia for example. I don't see how that can be seen as 'freeloading'. One could equally say that they are in the middle of a stable region with friends on all sides because they are skilled diplomats. Also, having a low military spend as %age of GDP is as much due to having a very high GDP as it is to have low spending.
In any case being neutral is very very different from being unarmed and/or militarily unprepared. Switzerland has conscription (meaning even with a relatively small standing army it has a very large and well-trained reserve), and it's a big arms producer. On both counts it's probably quite small in absolute terms but very big considering small size and population.
"...A total of 1.3 million files were stolen during the incident at software biz Xplain in May 2023 ... An administrative investigation was launched in August..."
Hmm.
"... and is set to conclude this month. The resulting report will then provide actionable recommendations for the Federal Council to apply with a view to preventing future breaches."
I predict it won't work.