Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Ransomware

Russian Hackers Suspected of Sweden Cyberattack

Swedish government agencies and shops were disrupted by a ransomware attack believed to have been carried out by Russian hackers.

Online services at some Swedish government agencies and shops have been disrupted in a ransomware attack believed to have been carried out by a Russian hacker group, IT consultancy Tietoevry said.

The Swedish-Finnish group, which provides online security systems, said the problem could take weeks to fix.

It said one of its data centers in Sweden was attacked overnight Friday to Saturday, knocking out online purchases at the country’s biggest cinema chain as well as some department stores and shops.

The centralized human resources system used by Sweden’s national government service center (Statens Servicecenter) was also affected, making it impossible for public sector employees to declare their overtime hours, sick leave or holiday requests.

“Considering the nature of the incident and the number of customer-specific systems to be restored, the restoration process may extend over several days, even weeks,” Tietoevry said in a statement issued late Monday.

“120 government agencies and more than 60,000 employees” were affected by the attack, Statens Servicecenter spokeswoman Caroline Johansson Sjowall told AFP.

Advertisement. Scroll to continue reading.

Tietoevry and other cyber security experts have pointed the finger at hacker group Akira, which has ties to Russia.

Tietoevry said it had filed a police complaint regarding the attack, the financial impact of which it “was not able to fully assess” yet.

The company has provided no information about a ransom demand.

Ransomware attacks typically access vulnerable computer systems and encrypt or steal data, before sending a ransom note demanding payment in exchange for decrypting the data or not releasing it publicly.

“Cybersecurity must be a priority for all of society, both the public and private sector,” Civil Defense Minister Carl-Oskar Bohlin wrote on X, formerly known as Twitter.

“Once the operational phase is over, the government intends to gather the affected parties … to thoroughly evaluate this incident,” he wrote.

The Swedish Civil Contingencies Agency (MSB) said the attack should serve as a wake-up call.

“Sweden has digitalized very rapidly, but in general we have not invested as much time and resources into cybersecurity,” Margareta Palmqvist, head of information security at MSB, told Swedish news agency TT.

“It’s important to be prepared, to work preventively … so that you’re ready when something happens,” she said.

Written By

AFP 2023

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.