BreachExchange mailing list archives

Sth African police website hacked


From: Erica Absetz <erica () riskbasedsecurity com>
Date: Fri, 24 May 2013 14:46:43 -0500

http://www.heraldsun.com.au/news/breaking-news/sth-african-police-website-hacked/story-fni0xqll-1226648803656

HACKERS have broken into the website of South Africa's police,
downloading information that could leave whistleblowers vulnerable,
police and a government data agency say.

State Information Technology Agency (Sita), which hosts all of the
government's websites, said that last week the hackers accessed
information relating to crimes posted by some 15,000 whistleblowers
and complainants.

"Most of the information was submitted anonymously... We are concerned
because there is information where people have given further details"
of crimes, Daniel Mashao, Sita's divisional manager, was quoted as
saying by SAPA news agency.

The hackers then posted the information onto a public website.

Local media said some of the whistleblowers' details that may have
been compromised include phone numbers, identity numbers and email
addresses provided between 2005 and 2013.

The hacker "DomainerAnon" claimed responsibility for the cyber attack
in a tweet late last week, saying it was linked to last year's killing
by police of 34 striking workers at the Marikana platinum mine
operated by Lonmin.

Police have launched an investigation into the breach, which was only
discovered on Monday.
_______________________________________________
Dataloss-discuss Mailing List (dataloss-discuss () datalossdb org)
Archived at http://seclists.org/dataloss/
Unsubscribe at http://datalossdb.org/mailing_list

Supporters:

Risk Based Security (http://www.riskbasedsecurity.com/)
Risk Based Security equips organizations with security intelligence, risk
management services and on-demand security solutions to establish
customized risk-based programs to address information security and
compliance challenges. 

Tenable Network Security (http://www.tenable.com/)
Tenable Network Security provides a suite of solutions which unify real-time
vulnerability, event and compliance monitoring into a single, role-based, interface
for administrators, auditors and risk managers to evaluate, communicate and
report needed information for effective decision making and systems management.


Current thread: