ALL NEWS

An entire nation just got hacked

Jul 22, 2019, 6:07 AM | Updated: 6:10 am

Iran digital intrusion...

(Stock Photo)

(Stock Photo)

(CNN) — Asen Genov is pretty furious. His personal data was made public this week after records of more than 5 million Bulgarians got stolen by hackers from the country’s tax revenue office.

In a country of just 7 million people, the scale of the hack means that just about every working adult has been affected.

“We should all be angry. … The information is now freely available to anyone. Many, many people in Bulgaria already have this file, and I believe that it’s not only in Bulgaria,” said Genov, a blogger and political analyst. He knows his data was compromised because, though he’s not an IT expert, he managed to find the stolen files online.

The attack is extraordinary, but it is not unique.

Government databases are gold mines for hackers. They contain a huge wealth of information that can be “useful” for years to come, experts say.

“You can make (your password) longer and more sophisticated, but the information the government holds are things that are not going to change,” said Guy Bunker, an information security expert and the chief technology officer at Clearswift, a cybersecurity company.

“Your date of birth is not going to change, you’re not going to move house tomorrow,” he said. “A lot of the information that was taken was valid yesterday, is valid today, and will probably be valid for a large number of people in five, 10, 20 years’ time.”

Hackers’ paradise

Data breaches used to be spearheaded by highly skilled hackers. But it increasingly doesn’t take a sophisticated and carefully planned operation to break into IT systems. Hacking tools and malware that are available on the dark web make it possible for amateur hackers to cause enormous damage.

A strict data protection law that came into effect last year across the European Union has placed new burdens on anyone who collects and stores personal data. It also introduced hefty fines for anyone who mismanages data, potentially opening the door for the Bulgarian government to fine itself for the breach.

Still, attacks against government systems are on the rise, said Adam Levin, the founder of CyberScout, another cybersecurity firm. “It’s a war right now — one we will win if we make cybersecurity a front-burner issue,” he said.

The notion that governments urgently need to step up their cybersecurity game is not new. Experts have been ringing alarm bells for years.

The US Department of Veterans Affairs suffered one of the first major data breaches in 2006, when personal data of more than 26 million veterans and military personnel were compromised.

“And it was all, ‘Oh, this is dreadful. We must do things to stop it.’ … And here we are, 13 years later, and an entire country’s data has been compromised, and in between, there’s been incidents of large swathes of citizen data being compromised in different countries,” Bunker said.

Out-of-date systems are often the problem. Some governments may have used private companies to manage the data they collected before the array of hacks and breeches brought their attention to cybersecurity.

“In many cases, our data was sent to third-party contractors years ago,” Levin said. “The way we looked at data management 10 years ago seems antiquated today, yet that old data is still out there being managed by third parties, using legacy systems.”

If the “old data” hasn’t changed, it’s still valuable to hackers.

The Bulgaria incident is concerning, said Desislava Krusteva, a Bulgarian privacy and data protection lawyer who advises some of the world’s biggest tech companies on how to keep their clients’ information safe.

“These kinds of incidents should not happen in a state institution. It seems like it didn’t require huge efforts, and it’s probably the personal data of almost all Bulgarian citizens,” said Krusteva, a partner at Dimitrov, Petrov & Co., a law firm in Sofia.

The Bulgarian Commission for Personal Data Protection has said it would launch an investigation into the hack.

A National Revenue Agency spokesman would not comment on whether the data was properly protected.

“As there is undergoing investigation, we couldn’t provide more details about reasons behind the hack,” Communications Director Rossen Bachvarov said.

‘Very embarrassing for the government’

A 20-year-old cybersecurity worker has been arrested by the Bulgarian police in connection with the hack. The computer and software used in the attack led police to the suspect, according to the Sofia prosecutor’s office.

The man has been detained, and the police seized his equipment, including mobile phones, computers and drives, the prosecutor’s office said in a statement. If convicted, he could spend as long as eight years in prison.

“It’s still too early to say what exactly happened, but from political perspective, it is, of course, very embarrassing for the government,” Krusteva said.

The embarrassment is made worse by the fact that this was not the first time the Bulgarian government was targeted. The country’s Commercial Registry was brought down less than a year ago by an attack.

“So, at least for a year, the Bulgarian society, politicians, those who are in charge of the country, they knew quite well about the serious cybersecurity problems in the government infrastructures,” Genov said, “and they didn’t do anything about it.”

The-CNN-Wire
™ & © 2019 Cable News Network, Inc., a Time Warner Company. All rights reserved.

We want to hear from you.

Have a story idea or tip? Send it to the KSL NewsRadio team here.

All News

Columbia University students hold a protest in support of Palestinians, during the ongoing conflict...

Matt Egan, Chris Boyette, Shimon Prokupecz and Nic F. Anderson, CNN

Columbia University main campus classes will be hybrid until semester ends; NYU students, faculty arrested during protests

Columbia University, the epicenter of pro-Palestinian protests at US college campuses in recent days, says all classes at its main campus will be hybrid until the spring semester ends. 

4 hours ago

Actor Rain Wilson arrives at the Cinema for Peace benefit for the J/P Haitian Relief Organization i...

Emma Keddington

Rainn Wilson speaking at Weber State graduation, how much did it cost the school?

OGDEN, Utah — Weber State University is shelling out big bucks to have Rainn Wilson, also known as Dwight Schrute from “The Office,” speak at their graduation commencement on Friday. $125,000 to be exact. Weber State public relations manager Bryan Magaña said while expensive, this serves a higher purpose. The choice to bring in Rainn […]

5 hours ago

FBI agent Douglas Hart, right, testifies Monday about texts between Chad Daybell and Lori Vallow Da...

EMILY ASHCRAFT, KSL.COM

‘Angels are angry’: FBI agent describes ‘manipulating’ texts between Lori and Chad Daybell

BOISE — Jurors in the Chad Daybell murder trial heard testimony Monday from some key people in Lori Vallow Daybell’s life, and from an FBI agent who described “manipulative” texts between the couple. Colby Ryan, Lori Daybell’s oldest child, took deep breaths and some time from the witness stand before identifying photos of his sister, […]

6 hours ago

Volunteers gather at Pedal and Pick at Jordan Park in Salt Lake City on Saturday, April 20, 2024. P...

Mariah Maynes

How did April 22 become Earth Day?

20 million Americans took part in the first Earth Day in 1970. Nowadays, the event is a global affair.

8 hours ago

Richfield City police say the male driver of a utility task vehicle died of injuries he sustained a...

Simone Seikaly

Crash kills utility task vehicle driver in Richfield

Richfield City police said a crash between a utility task vehicle and a car ejected the UTV driver, who died of his injuries.

8 hours ago

Former U.S. President Donald Trump returns to the courtroom after a break on the first day of his t...

Jeff Caplan

Jeff Caplan’s Minute of News: Trump is furious at her artwork

Christine Cornell is a courtroom sketch artist for the Trump trial.

9 hours ago

Sponsored Articles

Young couple hugging while a realtor in a suit hands them keys in a new home...

Utah Association of Realtors

Buying a home this spring? Avoid these 5 costly pitfalls

By avoiding these pitfalls when buying a home this spring, you can ensure your investment will be long-lasting and secure.

a person dressed up as a nordic viking in a dragon boat resembling the bear lake monster...

Bear Lake Convention and Visitors Bureau

The Legend of the Bear Lake Monster

The Bear Lake monster has captivated people in the region for centuries, with tales that range from the believable to the bizarre.

...

Live Nation Concerts

All the artists coming to Utah First Credit Union Amphitheatre (formerly USANA Amp) this summer

Summer concerts are more than just entertainment; they’re a celebration of life, love, and connection.

Mother and cute toddler child in a little fancy wooden cottage, reading a book, drinking tea and en...

Visit Bear Lake

How to find the best winter lodging in Bear Lake, Utah

Winter lodging in Bear Lake can be more limited than in the summer, but with some careful planning you can easily book your next winter trip.

Happy family in winter clothing at the ski resort, winter time, watching at mountains in front of t...

Visit Bear Lake

Ski more for less: Affordable ski resorts near Bear Lake, Utah

Plan your perfect ski getaway in Bear Lake this winter, with pristine slopes, affordable tickets, and breathtaking scenery.

front of the Butch Cassidy museum with a man in a cowboy hat standing in the doorway...

Bear Lake Convention and Visitors Bureau

Looking Back: The History of Bear Lake

The history of Bear Lake is full of fascinating stories. At over 250,000 years old, the lake has seen generations of people visit its shores.

An entire nation just got hacked