hiveleak attacks Advanced Geosciences

Incident Date:

January 25, 2022

World map

Overview

Title

hiveleak attacks Advanced Geosciences

Victim

Advanced Geosciences

Attacker

Hiveleak

Location

Islamabad, Pakistan

Punjab, Pakistan

First Reported

January 25, 2022

Hiveleak Ransomware Attack on Geological Survey of Pakistan (GSP)

The Geological Survey of Pakistan (GSP) has been targeted by the ransomware group Hiveleak, as reported on their dark web leak site. The victim's website is http://www.gsp.gov.pk/, and they operate in the Minerals & Mining sector. GSP is a government agency responsible for the study of the geology of Pakistan, assessing its geological resource potential, and conducting geological mapping and geoscientific surveys.

Company Size and Industry Standing

GSP is a significant player in the geological survey and mineral exploration sector in Pakistan. The organization is responsible for a wide range of activities, including geological mapping, geophysics, drilling, chemistry, petrology-mineralogy, remote sensing, and GIS. GSP's mission includes promoting sustainable development and utilization of national mineral resources, managing water scarcity, and increasing the GDP of minerals in Pakistan.

Vulnerabilities and Targeting

The ransomware attack on GSP highlights the importance of cybersecurity in the geological survey and mining sector. As the mining of critical minerals is highly concentrated in some countries, supply disruptions affecting major suppliers due to natural disasters or geopolitical tensions may lead to disruptions in the gas turbine industry supply chain. This underscores the need for robust cybersecurity measures to protect critical infrastructure and data in the sector.

The Hiveleak ransomware attack on GSP serves as a reminder of the importance of cybersecurity in the geological survey and mining sector. As the mining of critical minerals is highly concentrated in some countries, supply disruptions affecting major suppliers can have significant consequences. Organizations in this sector must prioritize cybersecurity to protect their operations and data from potential threats.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.