State-actors likely behind Singapore cyberattack: experts

Analysts would not be drawn into speculation on who might be behind the hack or why Singapore was targeted. (File photo: Reuters)
Updated 21 July 2018
0

State-actors likely behind Singapore cyberattack: experts

  • Singapore’s health minister said it was “a deliberate, targeted, and well-planned cyberattack"
  • Officials refused to comment on the identity of the hackers citing “operational security”

SINGAPORE: State-actors were likely behind Singapore’s biggest ever cyberattack to date, security experts say, citing the scale and sophistication of the hack which hit medical data of about a quarter of the population.
The city-state announced Friday that hackers had broken into a government database and stolen the health records of 1.5 million Singaporeans, including Prime Minister Lee Hsien Loong who was specifically targeted in the “unprecedented” attack.
Singapore’s health minister said the strike was “a deliberate, targeted, and well-planned cyberattack and not the work of casual hackers or criminal gangs.”
While officials refused to comment on the identity of the hackers citing “operational security,” experts told AFP that the complexity of the attack and its focus on high-profile targets like the prime minister pointed to the hand of a state-actor.
“A cyber espionage threat actor could leverage disclosure of sensitive health information... to coerce an individual in (a) position of interest to conduct espionage” on its behalf, said Eric Hoh, Asia-Pacific president of cybersecurity firm FireEye.
Hoh told national broadcaster Channel NewsAsia that the attack was an “advanced persistent threat.”
“The nature of such attacks are that they are conducted by nation states using very advanced tools,” he said.
“They tend to be well resourced, well-funded and highly sophisticated.”
Russia — which is accused of meddling in the US presidential election — China, Iran and North Korea are believed to have the capability to carry out such attacks.
Analysts, however, would not be drawn into speculation on who might be behind the hack or why Singapore was targeted.
The attack started two weeks after the wealthy city-state hosted the historic summit between US President Donald Trump and North Korean leader Kim Jong Un.
Jeff Middleton, chief executive of cybersecurity consultancy Lantium, said health care data is of particular interest to hackers because it can be used to blackmail people in positions of power.
“A lot of information about a person’s health can be gleaned from the medications that they take,” Middleton told AFP Saturday.
“Any non-public health information could be used for extortion. Russian spy services have a long history of doing this.”
Medical information, like personal data, can also be easily monetised on criminal forums, said Sanjay Aurora, Asia-Pacific managing director of Darktrace.
“Beyond making a quick buck, a more sinister reason to attack would be to cause widespread disruption and systemic damage to the health care service — as a fundamental part of critical infrastructure –- or to undermine trust in a nation’s competency to keep personal data safe,” he told AFP.
Today, cybercriminals are targeting more than just individuals or banks, said Shahnawaz Backer, regional security specialist at F5 Networks.
“Government services, from health care to education, are targets that are just as likely, as evidenced by the recent attacks in Singapore,” Backer said.
“As Singapore embraces the digital revolution, security breaches are bound to happen. Our growing digital footprint is growing every day, and enterprises need to take strict measures to safeguard and protect their data.”
Wealthy Singapore is hyper-connected and on a drive to digitise government records and essential services, including medical records which public hospitals and clinics can share via a centralized database.
But authorities have put the brakes on these plans while they investigate the breach. A former judge will head an inquiry looking into the hack.
Singapore officials have cautioned against jumping to conclusions about the attackers.
“With regard to the prime minister’s data and why he was targeted, I would say that it’s perhaps best not to speculate what the attacker had in mind,” said David Koh, head of Singapore’s Cyber Security Agency.
The hackers used a computer infected with malware to gain access to the database between June 27 and July 4 before administrators spotted “unusual activity,” authorities said.
The government says it fends off thousands of cyberattacks every day and has long warned of breaches by actors as varied as high-school students in their bedrooms to nation-states.
Earlier this month, US intelligence chief Dan Coats described Russia, China, Iran and North Korea as the “worst offenders” when it came to attacks on American “digital infrastructure.”


One third of UN workers say sexually harassed in past two years

Updated 16 January 2019
0

One third of UN workers say sexually harassed in past two years

  • The online survey was completed by 30,364 people from the United Nations and its agencies
  • More than half of those experienced sexual harassment said it happened in an office environment

UNITED NATIONS: One third of UN staff and contractors experienced sexual harassment in the past two years, according to a report released by the United Nations on Tuesday.
The online survey, carried out by Deloitte in November, was completed by 30,364 people from the United Nations and its agencies — just 17 percent of those eligible. In a letter to staff, Secretary-General Antonio Guterres described the response rate as “moderately low.”
“This tells me two things: first — that we still have a long way to go before we are able to fully and openly discuss sexual harassment; and second — that there may also be an ongoing sense of mistrust, perceptions of inaction and lack of accountability,” he wrote.
The survey comes amid the wider “Me Too” movement around the world against sexual harassment and assault.
According to the report, 21.7 percent of respondents said they were subjected to sexual stories or offensive jokes, 14.2 percent received offensive remarks about their appearance, body or sexual activities and 13 percent were targeted by unwelcome attempts to draw them into a discussion on sexual matters.
Some 10.9 percent said they were subjected to gestures or use of body language of a sexual nature, which embarrassed or offended them, and 10.1 percent were touched in way that made them feel uncomfortable.
More than half of those experienced sexual harassment said it happened in an office environment, while 17.1 percent said it happened at a work-related social event. Two out of three harassers were male, according to the survey.
Only one in three people said they took action after experiencing sexual harassment.
Guterres said the report contained “some sobering statistics and evidence of what needs to change to make a harassment-free workplace real for all of us.”
“As an organization founded on equality, dignity and human rights, we must lead by example and set the standard,” he said.
The United Nations has tried to increase transparency and strengthen how it deals with such accusations over the past few years after a string of sexual exploitation and abuse accusations against UN peacekeepers in Africa.
The head of the UN agency for HIV and AIDS is also stepping down in June, six months before his term ends, after an independent panel said that his “defective leadership” tolerated “a culture of harassment, including sexual harassment, bullying, and abuse of power.”