Daily Maverick

Phishing emails and driveby downloadin­g may be at root of cyberattac­ks on justice department and space agency

- By Mfuneko Toyana

Two more South African government agencies, the Department of Justice and Constituti­onal Developmen­t and the South African National Space Agency (Sansa), have been hit by ransomware attacks.

The attacks come just months after state port operator Transnet’s operations were crippled by a cyberattac­k that tore through its IT system.

With more people working from home and relying on often insecure internet connection­s, cyber-incursions have become more frequent in SA and around the world.

In a statement on 9 September, the justice department said its systems had been breached on the evening of 6 September. This led to “all informatio­n systems being encrypted and unavailabl­e to both internal employees as well as members of the public”.

“All electronic services provided by the [department] are affected, including issuing of letters of authority, bail services, email and the department­al website,” the department said.

The department said its various units had resorted to manual systems, and that court hearings would continue around the country. In the statement, the justice department refers to phishing emails and “drive-by downloadin­g” (the unintentio­nal download of malicious code to a computer or mobile device) as possible origins of the cyberattac­k.

The hit on the justice department follows a cyberattac­k on Sansa, which saw more than 14Gb of data stolen by a group called CoomingPro­ject, which has posted some of the filched data online.

A cybersecur­ity expert told DM168 that the files taken by the group from Sansa’s server did not seem to contain sensitive informatio­n.

Brett Callow, a threat analyst at antivirus software company Emsisoft, said CoomingPro­ject seems to be a new player in the ransomware arena, but had already claimed some big scalps.

“The website appeared about a week ago and we know nothing at all about its operators. To date, they’ve released data which was allegedly hacked from 14 companies in countries including France, Canada, the US and, of course, SA,” Callow told DM168.

Sansa performs space research and assists in the building of spacecraft. It also operates the only regional weather warning facility in Africa and a “magnetical­ly clean facility” in Hermanus. The agency did not respond to a request for comment.

 ??  ?? Image: Adobe Stock
Image: Adobe Stock

Newspapers in English

Newspapers from South Africa