Tuesday, August 04, 2020
Follow us on
हरियाणा के सीएम मनोहर लाल ने राज्य में फसल अवशेष प्रबंधन के लिए 1,304.95 करोड़ रुपये की एक व्यापक योजना स्वीकृति प्रदान की मंडियों में नहीं रहेगी बारदाने की कमी : दुष्यंत चौटालाआडवाणी, जोशी, कल्याण सिंह राम मंदिर भूमि पूजन कार्यक्रम में नहीं होंगे शामिल: स्वामी गोविंद गिरीराम मंदिर निर्माण शुभारंभ कार्यक्रम में कुल 175 लोगों को भेजा निमंत्रण: श्री राम जन्मभूमि ट्रस्टसुशांत सिंह राजपूत केस में पिता का बड़ा आरोप, कहा- मुंबई पुलिस को फरवरी में ही किया था आगाहसुशांत सिंह राजपूत केस में पिता से मुंबई पुलिस का सवाल, किस थाने में दी थी शिकायत?सुशांत सिंह राजपूत के पारिवारिक सूत्रों ने कहा- पूजा-पाठ के नाम पर अकाउंट से निकाले गए पैसेगुजरात के भरूच जिले में महसूस किए गए भूकंप के झटके

Hackers post NHAI data online, say there’s more

July 04, 2020 06:10 AM


Hackers post NHAI data online, say there’s more
Binayak Dasgupta and Anisha Dutta


New Delhi : Financial records, contract documents, and employee information of the National Highways Authority of India (NHAI) has been posted online by cyber criminals, according to cybersecurity researchers who said the stolen data includes personal identity documents of at least one former chairman of the agency that is responsible for building and maintaining highways in the country.

The information was posted online on July 2, two days after NHAI denied sensitive information was compromised. The agency, however, confirmed it had on June 28 been the target of ransomware — a type of cyber attack carried out usually by groups looking to make money.

Details about the leak were shared with HT by Singapore-based cybersecurity firm Cyfirma, which said in its initial assessment that “the data compromised includes tax information, audit reports, passport copies, identity cards, assessment reports, and many other PII (personally identifiable information) and financial records”.

The data was in two files about 1.8GB in size, which the hackers said was 5% of the information they had. The files, seen by HT, included copies of personal identity documents of former NHAI chairman Raghav Chandra, included his passport and government ID card.

According to Cyfirma, the hackers used the Maze ransomware, and the leaks may have been meant to force the NHAI to pay a ransom to stop more data from being exposed. “This is how Maze hackers work. They release in batches as they attempt to extort their victims,” said Kumar Ritesh, CEO of Cyfirma, in an email to HT. HT reported the breach on June 29, and NHAI officials at the time denied losing any data. On Thursday, representatives of the agency declined to comment on questions about the new disclosure. “As NHAI is going digital, it is advancing its security posture by adopting world’s best cyber security measures. It is adopting ...tool based user awareness training where user’s IT skill improvement can be monitored and measured,” said Akhilesh Srivastava, chief general manager (IT), of NHAI in response to HT’s questions.

Chandra, who retired in 2018, said he did not think the leak of his personal data would be a security risk, “...but we need to find out the source of the attack. Tendering documents are slightly of vulnerable nature... NHAI needs to ensure it builds a strong security system to be able to thwart such attacks”.

While it was not clear how much ransom may have been sought, Ritesh said that typically, “Maze hackers are known to ask in excess of hundreds of thousands of dollars to millions”.

Cybersecurity research agencies have not yet indicted a particular group for using Maze, but, according to Ritesh, the techniques overlap with groups in Russia, China and North Korea. “As of now our attribution shows Russian hackers are behind Maze but same techniques are being used by Chinese and Korea cyber criminals,” he said.

NHAI manages contracts worth millions of rupees a year, and its network systems are used for sensitive data, including toll management

Have something to say? Post your comment
More National News
गुजरात के भरूच जिले में महसूस किए गए भूकंप के झटके विनय तिवारी आधिकारिक काम से मुंबई गए थे, क्वारनटीन गाइडलाइन की जरूरत नहीं थी- बिहार डीजीपी मौसम विभाग की चेतावनी, गुजरात में 4 से 7 अगस्त के बीच हो सकती है भारी बारिश केंद्र ने सीरम इंस्टीट्यूट को कोरोना वैक्सीन के दूसरे और तीसरे फेज के ट्रायल को अनुमति दी जब चातुर्मास और भादो चल रहा है तो 5 अगस्त को भूमिपूजन क्यों- दिग्विजय सिंह केंद्रीय मंत्री गजेंद्र सिंह शेखावत का कोरोना टेस्ट नेगेटिव, अमित शाह से हुई थी मुलाकात कांग्रेस नेता पी चिदंबरम के बेटे कार्ति चिदंबरम कोरोना पॉजिटिव बेंगलुरु: CM येदियुरप्पा की बेटी भी कोरोना पॉजिटिव, मणिपाल अस्पताल में भर्ती Bhushan, aides launch multi-pronged response in SC contempt case Govt plans personal health IDs, e-records for citizens PM Likely To Announce It On August 15