After Romanian Land Registry Attack

Same Hacker Behind Romanian Attack Now Targets Hungary’s Treasury

Hungary, Hungary State Treasury, Hungary’s Treasury, Hungary State Treasury data breach, ByteToBreach, ByteToBreach ransomware attack on Hungarian State Treasury, hacker targets Hungarian government systems after Romanian breach
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: csikiphoto/Shutterstock.com

The hacker behind the attack on Romania’s land registry authority has now also targeted Hungary’s State Treasury (Magyar Államkincstár).

The incident occurred last week. Over the weekend, the Hungarian State Treasury confirmed the attack to local media, according to a report by risky.biz.

Ad

Agency Reports Limited Impact

According to an official statement, only the Office of Agricultural and Rural Development (MVH) was affected. Unlike the attack in Romania, the authority said that no data was deleted or lost.

However, the attack appears to have followed the same pattern as the Romanian incident. First, data was extracted from the affected systems. The attackers then deployed ransomware described as unstable and error-prone, encrypting parts of the infrastructure. The affected Treasury systems have since been taken offline. Hungary’s national cybersecurity authority is investigating the incident.

Unpatched Server Provided Entry Point

The attack is believed to have originated from an Oracle WebLogic Server that had not received the latest security updates. Journalists who obtained screenshots from the attacker described the level of access to the systems as extensive and classified the incident as particularly severe.

Ad

Previously Identified Threat Actor

The attack has been attributed to an actor known as ByteToBreach. Initially, the hacker claimed not to know the origin or significance of the stolen data. Later, however, the attacker admitted that the operation was financially motivated.

This aligns with the hacker’s previous activities. Their operations can be traced back nearly a year and have primarily focused on financial gain rather than political objectives.

In connection with the earlier attack on Romania’s land registry authority, cybersecurity company KELA identified the hacker as Zakaria Mahdjoub from the Algerian city of Oran. This information could now also play a role in investigating the Hungarian incident.

(lb)

Ad

Artikel zu diesem Thema

Weitere Artikel