Funksec Ransomware Breach Targets Milliy Tiklanish Data

Incident Date: Dec 06, 2024

Attack Overview
VICTIM
Milliy Tiklanish
INDUSTRY
Government
LOCATION
Uzbekistan
ATTACKER
Funksec
FIRST REPORTED
December 6, 2024

Ransomware Attack on Milliy Tiklanish by Funksec

On December 9, 2024, the Milliy Tiklanish Democratic Party of Uzbekistan, a prominent national-conservative political entity, allegedly fell victim to a ransomware attack by the cybercriminal group Funksec. The attack targeted the party's online platform, mtgazeta.uz, resulting in a significant data breach.

Victim Profile: Milliy Tiklanish

Milliy Tiklanish, officially known as the Uzbekistan "National Revival" Democratic Party, plays a crucial role in Uzbekistan's political landscape. Established in 1995, the party emphasizes national identity, cultural heritage, and socio-economic development. With a membership of approximately 358,377 individuals, the party operates through 14 territorial councils and 7032 primary party organizations across Uzbekistan. Its influence is evident in legislative processes, with a notable presence in the Legislative Chamber of the Oliy Majlis.

The party's digital platform, mtgazeta.uz, is a vital communication tool, disseminating news and information on various topics, including education, economics, culture, politics, and sports. This makes it an essential asset for the party's mission of fostering cultural and national identity renewal in Uzbekistan.

Attack Overview

The ransomware attack by Funksec allegedly resulted in a data leak of approximately 200MB, comprising sensitive materials such as FTP server source code, databases, configuration files, and secret keys. This breach represents a significant compromise of Milliy Tiklanish's digital infrastructure, potentially impacting its operations and mission.

Funksec: The Ransomware Group

Funksec is an emerging cybercrime group first observed in December 2024. It operates a Tor-based data-leak site and has claimed responsibility for over 10 breaches across various industries. The group employs double extortion tactics, combining data exfiltration with encryption to pressure victims. Funksec's activities suggest potential operations as a data broker, diversifying its extortion methods.

The group distinguishes itself by hosting breach announcements and a free DDoS tool on its data-leak site. Funksec's penetration into Milliy Tiklanish's systems likely involved exploiting vulnerabilities in the party's digital infrastructure, underscoring the need for enhanced cybersecurity measures.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.