Email Security

IMF Emails Hacked

The International Monetary Fund (IMF) detects a cybersecurity incident that involved nearly a dozen email accounts getting hacked.

IMF

The International Monetary Fund (IMF) recently detected a cybersecurity incident that involved nearly a dozen email accounts getting hacked. 

In a statement issued last week, the United Nations financial institution said it detected the security breach on February 16, 2024. 

An investigation conducted with external cybersecurity experts revealed that 11 IMF email accounts had been compromised. The hacked accounts were ‘re-secured’ and there is no indication at this point in the ongoing probe that the attacker gained access beyond these email accounts.

“The IMF takes prevention of, and defense against, cyber incidents very seriously and, like all organizations, operates under the assumption that cyber incidents will unfortunately occur,” the financial agency said. “The IMF has a robust cybersecurity program in place to respond quickly and effectively to such incidents.”

It’s unclear what the attackers’ goal was and what type of data they may have obtained from the IMF email accounts. 

Compromising the email accounts of a major financial organization such as the IMF could be useful to state-sponsored cyberspies, as well as profit-driven cybercriminals who could attempt to use the accounts for advanced social engineering.

The IMF told Reuters that the list of hacked accounts did not include the ones of Managing Director Kristalina Georgieva or other top officials. The agency said top leadership was “not targeted”. 

This appears to be the first cybersecurity incident disclosed by the IMF since 2011, when the agency was targeted in a cyberattack that reportedly resulted in the loss of a large quantity of data, including documents and emails.

Advertisement. Scroll to continue reading.

Related: Ransomware Group Takes Credit for LoanDepot, Prudential Financial Attacks

Related: Fidelity National Financial Takes Down Systems Following Cyberattack

Related: Willis Lease Finance Corp Discloses Cyberattack

Related Content

Email Security

KnowBe4 boasts that the merger will create “the largest, advanced AI-driven cybersecurity platform for managing human risk.”

Cybercrime

The financial sector has suffered over 20,000 cyberattacks in two decades, causing more than $12 billion in losses.

Email Security

8,800 domains, many once owned by major companies, have been abused to get millions of emails past spam filters as part of SubdoMailing campaign.

Email Security

HPE told the SEC that Russian state-sponsored threat group Midnight Blizzard had access to an email system for several months.

Email Security

A new attack technique named SMTP Smuggling can allow malicious actors to send out spoofed emails that bypass authentication mechanisms.

Email Security

Google and Yahoo are introducing new requirements for bulk senders, to improve phishing and spam protections.

Email Security

Patches are being developed for serious Exim vulnerabilities that could expose many mail servers to attacks. 

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version