SHARE
COPY LINK

CRIME

Austria wary of cyber attacks after personal data of foreign residents leaked online

A massive breach of IT security in the immigration and citizenship services of local authorities in the state of Carinthia has put all states on high alert.

Austria wary of cyber attacks after personal data of foreign residents leaked online
Austria is investigating a claim that spyware targeted law firms and banks (Photo by freestocks on Unsplash)

For more than two weeks, authorities in Austria have been trying to deal with a massive security breach of government systems in the state of Carinthia.

The primary victims seem to be foreigners, as the data leaked from departments that deal with immigration and citizenship issues.

A relatively simple phishing attack, when a hacker creates a fake email or webpage to give the appearance of official communication and asks the victim to click on a link, was how the IT systems in the state were first breached.

The malware entered the system, encrypted data, and now the responsible group, known as Black Cat, has been demanding a ransom to give access to precious information back to authorities.

READ ALSO: Stephansdom: Vienna woken up after hacker sets church bells to ring at 2am

Additionally, several consecutive attacks have blocked services and taken official websites off the air – though most of these have been restored.

The main issue now is that the hackers threaten Austrian authorities by leaking data from thousands of residents online. Some private information has already been revealed.

What kind of data do they have?

It has been difficult to ascertain how widespread the attack is, as the local government hasn’t been fully transparent. At first, they denied an attack, then they said the data breach concerned “only” public servants.

However, media reports have shown that entire files had actually been published online, including ID cards, passports, and corona test results from residents in Carinthia, a state in the south of Austria home to more than 560,000 people.

The groups that seem to be most affected are some 80,000 foreigners who have been granted a residence permit in the state since 1999, spokesperson of the state Gerd Kurath told a press conference.

“Data was read, but whether it was also stolen is still unclear”, he said.

READ ALSO: Six official websites to know if you’re planning to work in Austria

The hacker group also gained access to event management services, possibly retrieving data, including contact details and payment information from over 4,000 people and companies.

Finally, they also have government correspondence, including from the office of the governor Peter Kaiser (SPÖ).

What will they do with the information?

Ransomware works much like a hostage situation, except instead of people, criminals hold information. The group has blocked access to the information and is demanding $ 5 million as a ransom payment, which the government says they won’t pay.

They threaten to leak the data if the payment is not made. Still, it is unclear how much of the blocked information they can retrieve from government sites and leak.

If they do sell or publish data, people could have their identities stolen. The government says that if citizens become victims of identity theft, they will be informed about it.

What can I do now?

The state of Carinthia has set up an information hotline available every day from 8 am to 12:30 pm. People can call the line at 050 536 53003. However, no personal information, such as whether or not your own data has leaked, will be given at this moment.

At the moment, there is not much else people can do, data protection specialist Thomas Lohninger told Der Standard.

READ ALSO: Austria’s Foreign Ministry hit by ‘serious cyber attack’

Austria is not well prepared in terms of IT security, he says. The country needs to invest more in preventing attacks, according to the specialist. “This includes a secure architecture and training employees”.

Most cyberattacks, including this one, start with human error – clicking on a wrong link – and proper training is essential to prevent them.

Private citizens should also refrain from sharing personal information online as much as possible – of course, that is impossible when sharing information with public authorities.

“It does not help that there is no risk of a penalty for the loss of personal data for the public sector”, Lohninger adds.

Member comments

Log in here to leave a comment.
Become a Member to leave a comment.

CRIME

Austrian court approves incest rapist Fritzl’s transfer to regular jail

An Austrian court said Tuesday it had approved the transfer of incest rapist Josef Fritzl to a regular jail as the 89-year-old was now unlikely to commit a crime.

Austrian court approves incest rapist Fritzl's transfer to regular jail

Fritzl, who has changed his name, repeatedly raped his daughter he locked in a cellar for over 24 years, fathering seven children with her.

Served with a life sentence in 2019, Fritzl has been held in jail for the mentally ill who pose a high degree of danger in Krems, some 80 kilometres (50 miles) northwest of Vienna.

In a ruling published Tuesday, the Krems regional court said Fritzl “can be transferred… to normal detention” since he “no longer poses a danger that requires placement” in a jail psychiatric unit.

It noted Fritzl’s “advanced dementia and physical decline” and said he was “no longer likely to commit a criminal offence with serious consequences”.

It also set a 10-year probation period.

READ ALSO: Could Austria’s notorious incest rapist Josef Fritzl one day be released?

The decision confirms an initial ruling in January, which was overturned by a higher court in March after prosecutors appealed.

Monday’s ruling follows a hearing on April 30, where updated findings by psychiatric experts were presented.

The verdict can still be appealed within the next two weeks.

Contacted by AFP, Fritzl’s lawyer, Astrid Wagner, called the ruling “a big success”, adding that she doesn’t expect prosecutors to appeal.

“Fritzl could be transferred as soon as the appeal period of two weeks has lapsed,” Wagner said, adding that she would apply for a conditional release from jail by 2025.

Fritzl was jailed for the murder by neglect of a newborn baby he fathered with his daughter Elisabeth while holding her in the specially-built basement of his house.

He was also found guilty of incest, sequestration, grievous assault and 3,000 instances of rape.

SHOW COMMENTS