Information theft and politically-motivated hacking in focus: Tenth report of the Reporting and Analysis Centre for Information Assurance
In its latest report, the Reporting and Analysis Centre for Information Assurance (MELANI) examines cybercriminal activities in the second half of 2009. The focus is on global information theft, politically-motivated hacking and blackmailing through the use of DDoS attacks.
Cybercrime has many facets, ranging from data theft for the purposes of making money to hacking websites as a way of giving vent to political frustration. Those affected are companies, administrations and political parties. Even the federal administration has not been spared.
Information theft - attacks on administrations, on the EU, on Google and on banks
In the second half of 2009, time and again incidents occurred in which harmful software (so-called malware) was used to access external computer systems and steal data. The data was subsequently either put on sale or provided to the media or misused for other purposes. Prominent cases were the attacks on the Secretariat-General of the EU, the HSBC bank customer data and Google. The Federal Department of Foreign Affairs (FDFA) was also affected, and was the victim of a targeted hacker attack in mid-October 2009.
Politically-motivated hacking as an outlet for protest
More and more frequently, the internet is abused as an outlet for political, sporting or religious protest, with the organisations concerned being hacked, defaced or saturated with political or religious statements. One well-known example was in Switzerland in the aftermath of the popular vote on banning the construction of minarets. Here, thousands of websites were hacked.
Blackmail using DDoS attacks
DDoS attacks against companies and governments pursue the most diverse goals. In the case of DDoS attacks, the website of the victim is simultaneously accessed by thousands of computers and is thereby disabled. The perpetrators attempt either to extort money or to force a course of action. With last year's DDoS attacks on Swisscom, the goal of the perpetrators was to evict erotic industry internet providers from its network.
Information protection is top priority
The protection of personal and confidential data is enormously important. The best way of protecting oneself from cybercriminal attacks is and remains regular system updates and making PC users aware of this.