Amnesty International branch hit by suspected Chinese hackers
The Canadian branch of global non-governmental human rights organization Amnesty International suffered a recent cyberattack that was apparently orchestrated by a Chinese state-sponsored attacker.
In a press release (opens in new tab), Amnesty International Canada said it spotted “suspicious activity” on its IT infrastructure on October 5 2022. As soon as the activity was observed, the organization brought in “a highly skilled team of forensic investigators and cyber security experts” to investigate, and secure the systems.
The team was led by Secureworks, which established that an unnamed threat actor gained access to the organization’s IT systems in a “sophisticated digital security breach”.
Human rights in the crosshairs
“A digital security breach was perpetrated using tools and techniques associated with specific advanced persistent threat groups (APTs),” the announcement reads.
Secureworks later pointed the finger at Chinese threat actors, saying the nature of the targeted information, the tools used in the attack, as well as the behaviors of the attackers, all line up with entities “associated with Chinese cyberespionage threat groups.”
The organization’s Secretary General, Ketty Nivyabandi, did not sound too upset about the incursion: “As an organization advocating for human rights globally, we are very aware that we may be the target of state-sponsored attempts to disrupt or surveil our work. These will not intimidate us and the security and privacy of our activists, staff, donors, and stakeholders remain our utmost priority,” he stated.
The researchers also determined that this was most likely an espionage campaign, as there is no evidence of any donor or membership data having been exfiltrated. The organization said it notified law enforcement organizations, staff, donors, as well as other stakeholders, of the event.
The organization decided not to share the details on the attack, including the name of the threat actor, or the potential malware (opens in new tab) or fraud used to gain access to the target endpoints (opens in new tab).
Via: BleepingComputer (opens in new tab)
For all the latest Technology News Click Here
For the latest news and updates, follow us on Google News.