IMF hacked through phishing

By

Spear phishing fingered in attack.

The International Monetary Fund was hacked in an attack that led a spooked World Bank to cut a network link to the organisation.

IMF hacked through phishing

The IMF, which informed its directors of the incident on Wednesday, had not provided public details on the attack including if the highly sensitive data it held on the fiscal state of nations was compromised.

One official who spoke to the New York Times described the attack as a "very major breach" which had occurred over several months.

The World Bank "out of an abundance of caution" had cut a link with the IMF used to share less sensitive information and briefly terminated external access to its systems.

While the IMF hack did not exploit RSA's compromised SecurID tokens, both companies were attacked via spear phishing.

RSA annunced the attack on SecurID in March which was launched by sending a spear phishing email that contained a compromised Adobe file. Once an RSA staffer had opened the file, the attackers were able to launch exploits and eventually gain access to the company's network.

McAfee chief security officer Brett Whalin said the use of spear phishing had increased.

"To accentuate the damage of [sophisticated attacks] is to exploit social engineering".

He advised organisations to educate their staff about the dangers of talking to strangers or those not authorised to receive information.

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

Qantas facing 'significant' data theft after cyber attack

Qantas facing 'significant' data theft after cyber attack

Home Affairs officer accessed data on "friends and associates"

Home Affairs officer accessed data on "friends and associates"

Ex-student charged over Western Sydney University cyberattacks

Ex-student charged over Western Sydney University cyberattacks

International Criminal Court hit by cyber attack

International Criminal Court hit by cyber attack

Log In

  |  Forgot your password?