{"id":15878,"date":"2019-07-23T09:21:56","date_gmt":"2019-07-23T17:21:56","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/07\/23\/news-9623\/"},"modified":"2019-07-23T09:21:56","modified_gmt":"2019-07-23T17:21:56","slug":"news-9623","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2019\/07\/23\/news-9623\/","title":{"rendered":"Hacked Bulgarian database reaches online forums"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/sophosnews.files.wordpress.com\/2019\/07\/shutterstock_1344705767-compressor.jpg\"\/><\/p>\n<p><strong>Credit to Author: Danny Bradbury| Date: Mon, 22 Jul 2019 12:21:30 +0000<\/strong><\/p>\n<div class=\"entry-content\">\n<div class=\"entry-prefix\">\n<div class=\"entry-author\"> \t\t\t\t \t \t\t\t\t\t<span class=\"by\">by<\/span> \t\t\t<a href=\"https:\/\/nakedsecurity.sophos.com\/author\/danny-bradbury\/\" title=\"Posts by Danny Bradbury\" class=\"author url fn\" rel=\"author\">Danny Bradbury<\/a>\t\t \t \t\t\t\t<\/div>\n<div class=\"entry-sharing\">\n<ul class=\"block social share\">\n<li class=\"facebook\"><a href=\"https:\/\/www.facebook.com\/share.php?u=https%3A%2F%2Fnakedsecurity.sophos.com%2F2019%2F07%2F22%2Fhacked-bulgarian-database-reaches-online-forums%2F&#038;title=Hacked+Bulgarian+database+reaches+online+forums\" data-title=\"Hacked Bulgarian database reaches online forums\" title=\"Share on Facebook\"><svg style=\"height: 20px;\" viewbox=\"0 0 100 100\" class=\"icon facebook\"><use xlink:href=\"#facebook\"><\/use><\/svg><\/a><\/li>\n<li class=\"twitter\"><a href=\"https:\/\/twitter.com\/home?status=Hacked+Bulgarian+database+reaches+online+forums+https%3A%2F%2Fwp.me%2Fp120rT-1T73\" data-title=\"Hacked Bulgarian database reaches online forums\" title=\"Share on Twitter\"><svg style=\"height: 20px;\" viewbox=\"0 0 100 100\" class=\"icon twitter\"><use xlink:href=\"#twitter\"><\/use><\/svg><\/a><\/li>\n<li class=\"linkedin\"><a href=\"https:\/\/www.linkedin.com\/shareArticle?mini=true&#038;url=https%3A%2F%2Fwp.me%2Fp120rT-1T73&#038;title=Hacked+Bulgarian+database+reaches+online+forums\" data-title=\"Hacked Bulgarian database reaches online forums\" title=\"Share on LinkedIn\"><svg style=\"height: 20px;\"  viewbox=\"0 0 100 100\" class=\"icon linkedin\"><use xlink:href=\"#linkedin\"><\/use><\/svg><\/a><\/li>\n<li class=\"reddit\"><a href=\"https:\/\/reddit.com\/submit\/?url=https%3A%2F%2Fwp.me%2Fp120rT-1T73&#038;title=Hacked+Bulgarian+database+reaches+online+forums\" title=\"Share on Reddit\"><svg style=\"height: 20px;\"  viewbox=\"0 0 100 100\" class=\"icon reddit\"><use xlink:href=\"#reddit\"><\/use><\/svg><\/a><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<p>Data on millions of people stolen from the Bulgarian government has already popped up on hacker trading forums.<\/p>\n<p>A hacker originally stole the data from the National Revenue Agency (NRA), which is part of Bulgaria\u2019s Ministry of Finance, sending media outlets a link to the downloadable copy last Monday, 15 July 2019. The NRA confirmed this in a <a href=\"https:\/\/nap.bg\/news?id=3990\" rel=\"nofollow\">statement<\/a> on its website.<\/p>\n<p>After analysing the leak, it said that the data had been stolen around three weeks before. The hacker had accessed only 3% of its systems, it <a href=\"https:\/\/nap.bg\/news?id=3992\" rel=\"nofollow\">said in an update<\/a> the following day.<\/p>\n<p><a href=\"https:\/\/www.zdnet.com\/article\/bulgarias-hacked-database-is-now-available-on-hacking-forums\/\" rel=\"nofollow\">ZDNet learned<\/a> that a hacker known as Instakiller obtained the documents after a local TV outlet displayed a link to the file. It was password protected, but the hacker gave it to members of a forum, who cracked the password within hours.<\/p>\n<p>According to local media reports, data came from sources including the Employment Agency, Bulgarian Excise Centralized Information System, and the National Health Insurance Fund, alongside the NRA.<\/p>\n<p>Aside from names, addresses and other personal details, the data included several hundred thousand photographs of citizens&#8217; faces. The hacker sent media 57 compromised databases totalling 10.5GB but claimed to have 110 databases amounting to over 20GB. The hacker <a href=\"https:\/\/www.capital.bg\/politika_i_ikonomika\/bulgaria\/2019\/07\/15\/3938624_ot_nap_sa_iztekli_lichni_danni_na_milioni_bulgarski\/\" rel=\"nofollow\">told media<\/a> (translated):<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>More than five million Bulgarian and foreign citizens as well as companies are affected<\/p>\n<\/blockquote>\n<aside id=\"sophos_ad-3\" class=\"widget sophos-inline-ad sophos_widget_ad\">\n<style><\/style>\n<div class=\"sophos_widget_ad\"><a href=\"https:\/\/secure2.sophos.com\/en-us\/security-news-trends\/whitepapers\/gated-wp\/sophos-best-practices-for-securing-the-cloud.aspx?cmp=34494\" class=\"s-ad-secure-cloud__link-wrapper\">    <\/p>\n<div class=\"s-ad-secure-cloud\">\n<div class=\"s-ad-secure-cloud__sophos-logo\">        <svg style=\"height:11px;\" viewbox=\"0 0 132 24\" class=\"block icon sophos\"><use xlink:href=\"#sophos\"><\/use><\/svg>      <\/div>\n<div class=\"s-ad-secure-cloud__title\">        How to secure workloads in AWS, Azure and GCP      <\/div>\n<div class=\"s-ad-secure-cloud__action\">        <span class=\"s-button s-button--small s-button--green\">          Download&nbsp;Guide        <\/span>      <\/div>\n<\/p><\/div>\n<p>  <\/a><\/div>\n<\/aside>\n<p>In a country of 7 million people, this represents almost the entire adult population. The hacker also criticized the Bulgarian government\u2019s cybersecurity and called for the release of Julian Assange.<\/p>\n<p>In a <a href=\"https:\/\/www.mediapool.bg\/ruskiyat-haker-progovori-sistemata-e-probita-ot-11-godini-news295729.html\" rel=\"nofollow\">message<\/a> sent to a local TV station, the alleged hacker claimed to be a Russian married to a Bulgarian. He had a grievance against Bulgaria and threatened to reveal more data if the government did not \u201creveal the truth\u201d.<\/p>\n<p>On Wednesday, 17 July 2019, Bulgarian authorities <a href=\"https:\/\/www.prb.bg\/bg\/news\/aktualno\/sofijska-gradska-prokuratura-obvini-i-zadyrja--111\" rel=\"nofollow\">announced<\/a> that they had arrested a suspect in connection with the theft of the data, and on Friday, a local news outlet <a href=\"https:\/\/www.dnevnik.bg\/bulgaria\/2019\/07\/18\/3940054_prokuraturata_osvobodi_obvineniia_za_iztochenite_danni\/\" rel=\"nofollow\">reported<\/a> that a 20-year-old Bulgarian citizen had been arrested in connection with the hack, and subsequently released on bail.<\/p>\n<p>Government officials later <a href=\"https:\/\/www.dnevnik.bg\/bulgaria\/2019\/07\/18\/3939917_iavor_kolev_kaza_che_ne_e_opasno_iztichaneto_na_danni\/?ref=home_main_news\" rel=\"nofollow\">determined<\/a> that he had not hacked Bulgaria\u2019s critical national infrastructure and that the data released was &#8220;not particularly dangerous&#8221;.<\/p>\n<p>They consequently downgraded the charges against him, and he now faces up to three years in prison for the lesser charge of &#8216;crime against information systems&#8217;, rather than the eight years under the previous charge of &#8216;computer crime against critical infrastructure&#8217;.<\/p>\n<\/p><\/div>\n<p><a href=\"http:\/\/feedproxy.google.com\/~r\/nakedsecurity\/~3\/cIsspE3NhLw\/\" target=\"bwo\" >http:\/\/feeds.feedburner.com\/NakedSecurity<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/sophosnews.files.wordpress.com\/2019\/07\/shutterstock_1344705767-compressor.jpg\"\/><\/p>\n<p><strong>Credit to Author: Danny Bradbury| Date: Mon, 22 Jul 2019 12:21:30 +0000<\/strong><\/p>\n<p>Data on millions of people stolen from the Bulgarian government has already popped up on hacker trading forums.&lt;img src=&#8221;http:\/\/feeds.feedburner.com\/~r\/nakedsecurity\/~4\/cIsspE3NhLw&#8221; height=&#8221;1&#8243; width=&#8221;1&#8243; alt=&#8221;&#8221;\/&gt;<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10377],"tags":[22420,18362,22418,6272,22421,5897,16165],"class_list":["post-15878","post","type-post","status-publish","format-standard","hentry","category-security","category-sophos","tag-bulgaria","tag-data-loss","tag-government-security","tag-hackers","tag-national-revenue-agency","tag-privacy","tag-security-threats"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15878","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15878"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15878\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15878"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15878"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15878"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}