kelvinsecurity attacks eGOV

Incident Date: Apr 01, 2022

Attack Overview
VICTIM
eGOV
INDUSTRY
Government
LOCATION
Jamaica
ATTACKER
Kelvinsecurity
FIRST REPORTED
April 1, 2022

eGov: A Government Sector Victim of the Kelvinsecurity Ransomware Attack

Company Overview

eGov is a government sector organization in the Philippines, details about its size and specific role within the industry remain unclear. Notably, the Philippine Health Insurance Corporation (PhilHealth), another entity within the government sector, suffered a ransomware attack in September 2023, impacting approximately 13 million members.

Vulnerabilities and Targeting

While specific vulnerabilities of eGov leading to the ransomware attack are not detailed, the involvement of Medusa ransomware suggests potential exploitation of outdated software or unpatched vulnerabilities by the attackers. Medusa ransomware is known for its file encryption capabilities and the ability to disable systems.

Mitigation and Response

In response to increasing cyber threats, the National Privacy Commission (NPC) and the Department of Information and Communications Technology (DICT) have initiated a digital security and privacy quick response (DSPQR) project. This initiative aims to promptly address privacy violations and enhance the nation's cybersecurity posture.

The Kelvinsecurity ransomware attack on eGov underscores the critical importance of cybersecurity within government sector organizations. The collaborative efforts between the NPC and DICT through the DSPQR project represent significant strides towards bolstering cybersecurity defenses and mitigating future threats.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.