Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Hackers Undetected on Queensland Water Supplier Server For 9 months

Hackers Undetected on Queensland Water Supplier Server For 9 months

Hackers stayed hidden for nine months on a server holding customer information for a Queensland water supplier, illustrating the need of better cyberdefenses for critical infrastructure.

SunWater is Australian government-owned water supplier responsible for operating 19 major dams, 80 pumping stations, and 1,600 miles long pipelines.

Also Read: 7 Principles of Personal Data Processing

According to the annual financial audit report that was published by the Queensland Audit Office yesterday, SunWater was breached for nine months, with the actors remaining undetected the entire time.

While the report doesn’t name the entity directly, ABC Australia questioned the authority and confirmed it was SunWater.

The breach occurred between August 2020 and May 2021, and the actors managed to access a webserver used to store cutomer information by the water supplier.

It appears that the hackers weren’t interested in the exfiltration of sensitive data, as they instead just planted a custom malware to increase visitor traffic to an online video platform.

The audit report mentions that there is no evidence that the threat actors stole any customer or financial information, and the vulnerability the actors used has now been fixed.

The report underlines that the actors compromised the older and more vulnerable version of the system, leaving the modern and far more secure web servers untouched.

Finally, the report raises the issue of the lack of proper account security practices, such as giving users minimum access required to perform their jobs.

Instead, SunWater had several user accounts with access to multiple systems, increasing the risk in the case of a single point of compromise.

A widespread problem

The auditors examined the internal controls of six water authorities in Australia and found deficiencies in three without naming them specifically.

Also Read: 10 Simple and Useful Tips On Agreement Drafting Services

From the absence of anti-fraud safeguards that would secure financial transactions from BEC actors to the presence of numerous vulnerabilities in IT systems, the report highlighted several key issues.

In summary, the auditors found that public entities have taken positive steps based on last year’s recommendations but still need to:

  • Implement security threat detection and reporting systems
  • Enable multi-factor authentication on all external systems available to the public
  • Set a minimum password length of eight characters
  • Organize security awareness training
  • Implement critical security vulnerabilities identification processes

“We continue to identify several control deficiencies relating to information systems. Cyber-attacks continue to be a significant risk, with ongoing changes in entities’ working environments due to COVID-19.” – reads the auditors’ report.

While a financial loss is always a dire scenario, as we saw back in a 2017 attack against a UK-based water supplier who lost $645,000, it’s not nearly as severe as threatening public safety.

In February 2021, a hacker gained access to a water treatment system in Oldsmar, Florida, and attempted to increase the concentration of caustic soda in the public supply network.

This was a wake-up call for U.S. authorities who took methodical steps to upgrade the security of these critical facilities, which are targeted more often than the public realizes.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us