European weather services hit by storm of malicious email attacks

HamaraTimes.com | European weather services hit by storm of malicious email attacks

[ad_1]

Umbrella and rain binary code. Data protection and security and privacy concept

Weather services have been hit by malware

Who_I_am/Getty Images

Weather services across Europe have been caught in a storm of malicious email attacks in the past week, forcing groups to upgrade security measures and creating challenges for staff.

The Met Office and European Centre for Medium-Range Weather Forecasts (ECMWF) in the UK, SpainтАЩs State Meteorological Agency and the Danish Meteorological Institute (DMI) are among the European services that were affected, New Scientist has confirmed.

People at meteorological services have received a mass of emails purporting to come from trusted contacts, with some of the senders spoofing European Commission addresses.

Advertisement


The widespread attacks came after the laptop of an individual in the meteorological community was infected by malware, leading the userтАЩs mailbox to be acquired by a botnet, the ECMWF says. The botnet then used their email account to send messages with malware to contacts in the community. Email lists from several international meteorological organisations, which havenтАЩt been named, were infected.

тАЬWhilst this attack has created disruption, we can confirm that the attack has remained at email level and that our systems were not breached, and our operations were at no time jeopardised,тАЭ a spokesperson for the ECMWF says.

It is unclear whether the attackers were deliberately targeting weather services, which are considered national infrastructure in many countries, or simply got lucky by infecting the computer of an individual who was a member of several meteorological groups.

Either way, the attack posed a challenge. The Met Office confirmed that several members of staff had received malicious emails purporting тАЬto be from a range of sources within the European Met communityтАЭ.

A spokesperson for the Met Office says the number of emails has greatly reduced in the past few days and it is confident that measures put in place, including blocking links and attachments and providing security guidance to staff, means no machines have been compromised. The new measures тАЬcreated some challenges for our day-to-day workтАЭ but the impact on services had been minimal, they add.

Ruth Mottram, a climate scientist at the DMI, says there has been some minor disruption as legitimate emails are being caught in spam filters. Colleagues at other weather services have reported that IT departments are stripping out any attachments, she adds. The attacks are тАЬnaturally putting a bit of pressure on the email system, and therefore working lifeтАЭ, but the DMIтАЩs IT team are тАЬon top of itтАЭ, she says.

Mike Beck at UK cyber security firm Darktrace says meteorological groups are likely to be naturally vulnerable to such┬аattacks because of their open and collaborative nature. тАЬIтАЩve seen that before in academia, itтАЩs much easier for attackers to spread,тАЭ he says.

David Emm at cybersecurity firm Kaspersky says having an insiderтАЩs email account compromised is тАЬgoldтАЭ for attackers, and would have helped emails spread. He says it is hard to say whether the owner of the original infected laptop was targeted specifically, or fell victim to a generalised phishing approach.

More on these topics:

[ad_2]

Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here