Hackers Breach Tax Administration of RS: Data Sold on Black Market, Employees Used Official Emails for Website Access

Patria
AutorPatria
17:28
Podijeli:
Hackers Breach Tax Administration of RS: Data Sold on Black Market, Employees Used Official Emails for Website Access

(Patria) - Data of clients of the Tax Administration of RS and email addresses of employees of this institution, following those from the database of the Integrated Health Information System of RS, are being sold on criminal hacker forums on the black market, exclusively learned by the portal CAPITAL.

According to information they had access to, the leakage of taxpayer data occurred due to the use of official emails of PU employees to access entertainment sites, classified ads, and LinkedIn.

Information has already been released on several forums on the “dark web” and the sale of data from about 410 users of the Tax Administration has been offered. Data of the PU, i.e., passwords used by legal and natural persons to access their profiles in the Tax Administration database, have also been offered.

According to IT experts, this is most likely not a “ransomware” attack, but it is undoubtedly related to the desperately poor protection of highly sensitive data and potentially to the breach of IZIS that occurred on December 31, 2023, around 12:20 PM, since when all patient records have been locked, and the database offered for sale.

Our IT expert consultant claims that PU employees carelessly registered on various websites using their official email addresses, but that client data was also found there.

“Data about the business operations of PU clients has leaked. This information can be misused in several ways, for example, to access the PU database or to steal the identity of its users. It is also problematic that only a fraction of information from the logs can be used by a hacker to access all other data. They can even reach the user and trick them into logging in again, entering their password, and everything will be revealed to them,” he says.

We informed the management of the Tax Administration this morning that this database had leaked onto the black market, to give them time to react, with the aim of preventing greater damage before the publication of the text.

“We want to point out that we immediately reacted to the journalists' claims. All data related to the Health Insurance Fund, with which we exchange data in accordance with the Law, is currently under careful verification. Usernames associated with the Health Insurance Fund have been identified as a potential source of the problem. To protect the integrity of our systems, we have immediately suspended all connections with the Fund and blocked access for all system users until further notice. All data related to the HIF with which we exchange data is currently under careful verification,” they told us at the Tax Administration.

They claim that their team of experts is “actively monitoring the situation, conducting an investigation, and responding promptly to ensure the protection of all data and systems of the Tax Administration”.

“We want to emphasize that all systems of the Tax Administration are functional and operating at full capacity, and that we are seriously committed to preserving public trust and transparency in the work of the Tax Administration. We will continue to cooperate with relevant authorities and provide additional information to ensure the public is fully informed about all aspects of the current security incidents,” they said at the PU RS.

The Tax Administration emphasizes that it is committed to implementing the latest versions of traffic filtering technologies and maintaining the highest standards of information security.

“However, at the same time, we are aware that attempts at malicious actions are always possible, and we are fully committed to detecting and suppressing potential threats,” they say at the PU RS.

Komentari (0)

Prijavite se za komentiranje

Prijava

Jos nema komentara. Budite prvi!

Minuta

Sve →

Iz drugih kategorija