IMF hacked through phishing

By

Spear phishing fingered in attack.

The International Monetary Fund was hacked in an attack that led a spooked World Bank to cut a network link to the organisation.

IMF hacked through phishing

The IMF, which informed its directors of the incident on Wednesday, had not provided public details on the attack including if the highly sensitive data it held on the fiscal state of nations was compromised.

One official who spoke to the New York Times described the attack as a "very major breach" which had occurred over several months.

The World Bank "out of an abundance of caution" had cut a link with the IMF used to share less sensitive information and briefly terminated external access to its systems.

While the IMF hack did not exploit RSA's compromised SecurID tokens, both companies were attacked via spear phishing.

RSA annunced the attack on SecurID in March which was launched by sending a spear phishing email that contained a compromised Adobe file. Once an RSA staffer had opened the file, the attackers were able to launch exploits and eventually gain access to the company's network.

McAfee chief security officer Brett Whalin said the use of spear phishing had increased.

"To accentuate the damage of [sophisticated attacks] is to exploit social engineering".

He advised organisations to educate their staff about the dangers of talking to strangers or those not authorised to receive information.

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

India's alarm over Chinese spying rocks CCTV makers

India's alarm over Chinese spying rocks CCTV makers

Hackers abuse modified Salesforce app to steal data, extort companies

Hackers abuse modified Salesforce app to steal data, extort companies

Victoria's Secret pulls down website amid security incident

Victoria's Secret pulls down website amid security incident

Cyber companies hope to untangle weird hacker codenames

Cyber companies hope to untangle weird hacker codenames

Log In

  |  Forgot your password?