Hacker wipes Romania's land registry database

Hacker wipes Romania’s land registry database

黑客清空罗马尼亚土地登记数据库

A hacker has breached Romania’s cadastre agency and wiped the country’s entire land registry database following a failed extortion attempt. 一名黑客在勒索未果后,入侵了罗马尼亚地籍局,并清空了该国整个土地登记数据库。

The hack has brought Romania’s entire real-estate market to a standstill as official apps and websites have been offline for a week. Notaries can’t record new transactions while citizens can’t obtain proof of ownership or detailed land records. 此次黑客攻击导致罗马尼亚整个房地产市场陷入停滞,官方应用程序和网站已离线一周。公证人无法记录新的交易,公民也无法获取所有权证明或详细的土地记录。

Email servers at the National Agency for Cadastre and Real Estate Advertising (Agenția Națională de Cadastru și Publicitate Imobiliară, or ANCPI) were also down as part of the incident. 作为此次事件的一部分,国家地籍和房地产广告局(ANCPI)的电子邮件服务器也已瘫痪。

Sources told Risky Business that the hacker entered using valid credentials, mapped internal systems, and wiped systems and backups after failing to extort the agency. 消息人士告诉《Risky Business》,黑客使用有效的凭据进入系统,在对内部系统进行测绘后,因勒索该机构未果,随即清空了系统和备份。

The incident became public on July 14 as the hacker started deleting data. A day later, some of ANCPI’s stolen data was put up for sale on a known hacking forum. The posted data included employee credentials, internal documents, and details on the agency’s IT network. 7月14日,随着黑客开始删除数据,该事件被公之于众。一天后,部分被盗的 ANCPI 数据出现在一个知名的黑客论坛上进行兜售。发布的数据包括员工凭据、内部文件以及该机构 IT 网络的详细信息。

Since the hack, officials restored their website and posted a message announcing they are rebuilding the agency’s entire network from scratch. Even if the hacker claims they deleted backups, the agency appears to have had an offline copy, otherwise things would have gotten really messy over the coming months in Romania. 黑客攻击发生后,官方恢复了网站并发布消息称,他们正在从零开始重建该机构的整个网络。尽管黑客声称删除了备份,但该机构似乎保留了离线副本,否则罗马尼亚未来几个月的情况将会变得非常混乱。

The stolen data was posted online by an account with the name ByteToBreach, a known hacker who also breached Sweden’s e-government portal this year, and many other government agencies and high-profile companies over the past year. 被盗数据是由一个名为“ByteToBreach”的账户发布到网上的。该黑客此前曾入侵过瑞典的电子政务门户网站,并在过去一年中入侵了许多其他政府机构和知名公司。

Security firm KELA published a profile on ByteToBreach last December and hinted they might be located in Algeria, but since the ANCPI hack has updated the post and outright doxxed the hacker as Zakaria Mahdjoub, an individual from Oran, Algeria. 安全公司 KELA 去年 12 月发布了关于 ByteToBreach 的资料,暗示其可能位于阿尔及利亚。但在 ANCPI 事件发生后,该公司更新了文章,直接曝光了该黑客的身份为 Zakaria Mahdjoub,一名来自阿尔及利亚奥兰市的个人。

Well, that will make the job of Romanian law enforcement a hell lot easier! gj! 好吧,这会让罗马尼亚执法部门的工作轻松多了!干得漂亮!

Romania joins Poland, Slovakia, Greece, Morocco, Russia, and Ukraine as countries that had their land registry agencies hacked over the past three years. 罗马尼亚加入了波兰、斯洛伐克、希腊、摩洛哥、俄罗斯和乌克兰的行列,成为过去三年中土地登记机构遭到黑客攻击的国家之一。


Breaches, hacks, and security incidents

违规、黑客攻击及安全事件

Hugging Face hacked using AI: A threat actor used an autonomous AI agent to breach AI platform Hugging Face last week. The attacker used exploits in the platform’s data-processing pipeline to pivot to some parts of the company’s internal systems. Hugging Face says no customer data was exposed but the attacker stole internal datasets and some cloud credentials. Hugging Face says it tried to use a frontier AI model to analyze the hack but was blocked by its guardrails, which couldn’t differentiate between an IR event and offensive operations. Hugging Face 遭 AI 入侵: 上周,一名威胁行为者利用自主 AI 代理入侵了 AI 平台 Hugging Face。攻击者利用该平台数据处理管道中的漏洞,转向了公司内部系统的部分区域。Hugging Face 表示没有客户数据泄露,但攻击者窃取了内部数据集和一些云凭据。Hugging Face 称其曾试图使用前沿 AI 模型来分析此次黑客攻击,但被其安全护栏拦截,因为护栏无法区分应急响应(IR)事件和攻击性操作。

Coca-Cola hit by ransomware: Coca-Cola has suspended production at its Fairlife dairy subsidiary after a ransomware attack. In an SEC filing, Coca-Cola said hackers accessed Fairlife production-related systems this week. Production has been halted at Fairlife US factories. The company’s Canadian production lines were unaffected. No ransomware group has taken credit for the incident, yet. 可口可乐遭遇勒索软件攻击: 在遭受勒索软件攻击后,可口可乐暂停了其 Fairlife 乳制品子公司的生产。在提交给美国证券交易委员会(SEC)的文件中,可口可乐表示黑客本周访问了 Fairlife 的生产相关系统。Fairlife 美国工厂的生产已停止,但该公司在加拿大的生产线未受影响。目前尚无勒索软件组织对该事件负责。

Qantas breach has a cause: The hack of Australian airline company Qantas last year was traced back to a social engineering attack. Hackers called an overseas contractor posing as the Qantas IT team to access their systems, connect to the Qantas CRM platform, and exfiltrate the data of 5.7 million customers. Australia’s Information Commissioner says Qantas took all the steps to protect customer data on its side and will not be opening further probes into the hack. 澳洲航空泄露事件原因查明: 去年澳大利亚航空公司澳洲航空(Qantas)的黑客攻击事件被追溯为一起社会工程学攻击。黑客冒充澳洲航空 IT 团队致电海外承包商,从而访问了他们的系统,连接到澳洲航空的 CRM 平台,并窃取了 570 万客户的数据。澳大利亚信息专员表示,澳洲航空已采取一切措施保护客户数据,不会对此次黑客攻击展开进一步调查。

Suno hack: A threat actor hacked AI music generator platform Suno and dumped internal files and documents online. The files allegedly show that Suno scraped millions of songs and lyrics from YouTube Music, Deezer, Genius, and other music platforms. The leaked files include source code and detailed scraping instructions targeting the platforms. Several music industry groups have sued Suno over the past year for training its AI song generator tool on copyrighted material. Suno was allegedly hacked following a compromise with the Shai-Hulud npm worm. Suno 遭黑客攻击: 一名威胁行为者入侵了 AI 音乐生成平台 Suno,并将内部文件和文档泄露到网上。这些文件据称显示 Suno 从 YouTube Music、Deezer、Genius 等音乐平台抓取了数百万首歌曲和歌词。泄露的文件包括源代码和针对这些平台的详细抓取说明。过去一年中,多个音乐行业组织起诉了 Suno,指控其使用受版权保护的材料训练其 AI 歌曲生成工具。据称,Suno 是在受到 Shai-Hulud npm 蠕虫攻击后被入侵的。

WINDTRE fined for breaches: Italy’s privacy watchdog has fined telecommunications provider WINDTRE €1.7 million for “serious security deficiencies” that led to two security breaches last year. WINDTRE 因违规被罚款: 意大利隐私监管机构对电信运营商 WINDTRE 处以 170 万欧元的罚款,原因是其存在“严重的安全缺陷”,导致去年发生了两起安全漏洞事件。

KNPP leak: Threat intel analyst Rakesh Krishnan looks at a leak of sensitive files from India’s KNPP nuclear power plant after one of its contractors got hit by the World Leaks extortion group. KNPP 泄露事件: 威胁情报分析师 Rakesh Krishnan 调查了印度 KNPP 核电站敏感文件的泄露事件,此前该核电站的一家承包商遭到了 World Leaks 勒索组织的攻击。

Ostium crypto-heist: The Ostium DeFi platform was hacked for $18 million last week after hackers exploited its own price-reporting infrastructure. Ostium 加密货币盗窃案: 上周,DeFi 平台 Ostium 遭到黑客攻击,损失 1800 万美元,黑客利用了其自身的价格报告基础设施。

Estée Lauder discloses Oracle EBS breach: Cosmetics giant Estée Lauder has confirmed that hackers stole customer data from its Oracle E-Business Suite platform last year. The company disclosed the breach to US state officials almost a year after it took place. 雅诗兰黛披露 Oracle EBS 泄露事件: 化妆品巨头雅诗兰黛证实,黑客去年从其 Oracle E-Business Suite 平台窃取了客户数据。该公司在事件发生近一年后才向美国州政府官员披露了此次泄露。