Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Germany IT Watchdog Knew for Weeks of Mass Cyber Theft

BERLIN – Germany’s cyber crime watchdog said Wednesday it learnt last month of the mass theft of 16 million digital identities through a criminal probe but needed weeks before alerting the public.

BERLIN – Germany’s cyber crime watchdog said Wednesday it learnt last month of the mass theft of 16 million digital identities through a criminal probe but needed weeks before alerting the public.

The website of the Federal Office for Information Security (BSI) had buckled Tuesday under an onslaught of requests by millions of worried online users soon after the warning was issued.

By Wednesday morning, with the site working again, the BSI said it had handled over 12 million online queries and informed 884,000 affected users, reported national news agency DPA.

Cyber criminals stole email addresses and matching passwords, which could also compromise linked social media, shopping and other online services, said the office.

The mass theft was uncovered in a probe by criminal investigators and researchers of so-called botnets, networks of hijacked computers whose users are usually unaware their infected “zombie computers” are themselves sending out spam and malware.

“The data was discovered by criminal investigators,” a BSI spokesman told AFP, saying the theft was “of exceptional magnitude”, but without specifying which judicial authority had conducted the probe.

BSI president Michael Hange defended the time lag in issuing the public alert, saying the office had needed time to set up a website where online users could securely check whether they had fallen victim to the theft.

“Setting up a process that complies with data protection laws and can handle such a large number of requests needs preparation time,” Hange told public broadcaster Bayerischer Rundfunk.

Advertisement. Scroll to continue reading.

Interior Minister Thomas de Maiziere praised the BSI’s “well-prepared operation”, saying the mass theft showed the extent of the cyber threat and that the state had a duty to ensure online security.

Those affected have been advised to clean their computers using anti-virus software and to change their passwords, using complex combinations of letters, numbers and symbols.

About half of the affected accounts had email addresses with Germany’s domain-name ending .de, while many others were from other EU states, suggesting an international network was behind the spectacular data theft, Hange told DPA.

The BSI’s German-language website sicherheitstest.bsi.de allows Internet users to check whether their accounts are affected by entering their email address and then checking an email reply from the office, marked with a unique security code.

Written By

AFP 2023

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Cybercrime

Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.