Funksec Ransomware Breach Targets Milliy Tiklanish Data
Ransomware Attack on Milliy Tiklanish by Funksec
On December 9, 2024, the Milliy Tiklanish Democratic Party of Uzbekistan, a prominent national-conservative political entity, allegedly fell victim to a ransomware attack by the cybercriminal group Funksec. The attack targeted the party's online platform, mtgazeta.uz, resulting in a significant data breach.
Victim Profile: Milliy Tiklanish
Milliy Tiklanish, officially known as the Uzbekistan "National Revival" Democratic Party, plays a crucial role in Uzbekistan's political landscape. Established in 1995, the party emphasizes national identity, cultural heritage, and socio-economic development. With a membership of approximately 358,377 individuals, the party operates through 14 territorial councils and 7032 primary party organizations across Uzbekistan. Its influence is evident in legislative processes, with a notable presence in the Legislative Chamber of the Oliy Majlis.
The party's digital platform, mtgazeta.uz, is a vital communication tool, disseminating news and information on various topics, including education, economics, culture, politics, and sports. This makes it an essential asset for the party's mission of fostering cultural and national identity renewal in Uzbekistan.
Attack Overview
The ransomware attack by Funksec allegedly resulted in a data leak of approximately 200MB, comprising sensitive materials such as FTP server source code, databases, configuration files, and secret keys. This breach represents a significant compromise of Milliy Tiklanish's digital infrastructure, potentially impacting its operations and mission.
Funksec: The Ransomware Group
Funksec is an emerging cybercrime group first observed in December 2024. It operates a Tor-based data-leak site and has claimed responsibility for over 10 breaches across various industries. The group employs double extortion tactics, combining data exfiltration with encryption to pressure victims. Funksec's activities suggest potential operations as a data broker, diversifying its extortion methods.
The group distinguishes itself by hosting breach announcements and a free DDoS tool on its data-leak site. Funksec's penetration into Milliy Tiklanish's systems likely involved exploiting vulnerabilities in the party's digital infrastructure, underscoring the need for enhanced cybersecurity measures.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!