kelvinsecurity attacks eGOV
Incident Date:
April 1, 2022
Overview
Title
kelvinsecurity attacks eGOV
Victim
eGOV
Attacker
Kelvinsecurity
Location
First Reported
April 1, 2022
eGov: A Government Sector Victim of the Kelvinsecurity Ransomware Attack
Company Overview
eGov is a government sector organization in the Philippines, details about its size and specific role within the industry remain unclear. Notably, the Philippine Health Insurance Corporation (PhilHealth), another entity within the government sector, suffered a ransomware attack in September 2023, impacting approximately 13 million members.
Vulnerabilities and Targeting
While specific vulnerabilities of eGov leading to the ransomware attack are not detailed, the involvement of Medusa ransomware suggests potential exploitation of outdated software or unpatched vulnerabilities by the attackers. Medusa ransomware is known for its file encryption capabilities and the ability to disable systems.
Mitigation and Response
In response to increasing cyber threats, the National Privacy Commission (NPC) and the Department of Information and Communications Technology (DICT) have initiated a digital security and privacy quick response (DSPQR) project. This initiative aims to promptly address privacy violations and enhance the nation's cybersecurity posture.
The Kelvinsecurity ransomware attack on eGov underscores the critical importance of cybersecurity within government sector organizations. The collaborative efforts between the NPC and DICT through the DSPQR project represent significant strides towards bolstering cybersecurity defenses and mitigating future threats.
Sources
- PhilHealth: 13 million members affected by data breach | Philstar.com
- PhilHealth paralyzed by Medusa ransomware attack - Manila Bulletin
- PhilHealth hit by ransomware – report - Rappler
- Administrator Samantha Power at the 2023 International Counter Ransomware Initiative Summit | November 1, 2023 | U.S. Agency for International Development
- PhilHealth estimates 13 to 20 million members affected by data breach - iTnews Asia
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.