IMF hacked through phishing

Powered by SC Magazine
 

Spear phishing fingered in attack.

The International Monetary Fund was hacked in an attack that led a spooked World Bank to cut a network link to the organisation.

The IMF, which informed its directors of the incident on Wednesday, had not provided public details on the attack including if the highly sensitive data it held on the fiscal state of nations was compromised.

One official who spoke to the New York Times described the attack as a "very major breach" which had occurred over several months.

The World Bank "out of an abundance of caution" had cut a link with the IMF used to share less sensitive information and briefly terminated external access to its systems.

While the IMF hack did not exploit RSA's compromised SecurID tokens, both companies were attacked via spear phishing.

RSA annunced the attack on SecurID in March which was launched by sending a spear phishing email that contained a compromised Adobe file. Once an RSA staffer had opened the file, the attackers were able to launch exploits and eventually gain access to the company's network.

McAfee chief security officer Brett Whalin said the use of spear phishing had increased.

"To accentuate the damage of [sophisticated attacks] is to exploit social engineering".

He advised organisations to educate their staff about the dangers of talking to strangers or those not authorised to receive information.

Copyright © SC Magazine, Australia


IMF hacked through phishing
 
 
 
Top Stories
The True Cost of BYOD - 2014 survey
Twelve months on from our first study, is BYOD a better proposition?
 
Photos: Unboxing the Magnus supercomputer
Pawsey's biggest beast slots into place.
 
ANZ looks to life beyond the transaction
If digital disruptors think an online payments startup could rock the big four, they’ve missed the point of why people use banks, says Patrick Maes.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  29%
 
Application integration concerns
  3%
 
Security and compliance concerns
  28%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  22%
 
Lack of stakeholder support
  3%
 
Protecting on-premise IT jobs
  4%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 1079

Vote