Singapore Says Hackers Stole 1.5 Million Health Records in Massive Cyberattack
22.7.18 securityweek Incindent
Hackers have stolen the health records of 1.5 million Singaporeans including Prime Minister Lee Hsien Loong, authorities said Friday, with the leader specifically targeted in the city-state's biggest ever data breach.
Singapore's health and information ministries said a government database was broken into in a "deliberate, targeted and well-planned" strike, describing the attack as "unprecedented".
"Attackers specifically and repeatedly targeted the personal particulars and outpatient information of Prime Minister Lee Hsien Loong," health minister Gan Kim Yong told a press conference.
Forensic analysis by Singapore's Cyber Security Agency "indicates this is a deliberate, targeted, and well-planned cyber-attack and not the work of casual hackers or criminal gangs," he added.
Officials declined to comment on the identity of the hackers, citing "operational security", but said the prime minister's data has not shown up anywhere on the internet.
"I don't know what the attackers were hoping to find. Perhaps they were hunting for some dark state secret, or at least something to embarrass me," Lee wrote on Facebook.
"My medication data is not something I would ordinarily tell people about, but there is nothing alarming in it."
Hackers used a computer infected with malware to gain access to the database between June 27 and July 4 before administrators spotted "unusual activity", authorities said.
The compromised data includes personal information and medication dispensed to patients, but medical records and clinical notes have not been affected, the health and communications ministries said.
"Health records contain information that is valuable to governments," said Eric Hoh, Asia-Pacific president of cyber-security firm FireEye.
"Nation-states increasingly collect intelligence through cyber-espionage operations which exploit the very technology we rely upon in our daily lives."
Earlier this month, the US National Intelligence Director Dan Coats described Russia, China, Iran and North Korea as the "worst offenders" when it came to attacks on American "digital infrastructure".
Wealthy Singapore is hyper-connected and on a drive to digitise government records and essential services, including medical records which public hospitals and clinics can share via a centralised database.
But authorities have put the brakes on these plans while they investigate the cyber-attack. A former judge will head a committee looking into the incident.
While the city-state has some of the most advanced military weaponry in the region, the government says it fends off thousands of cyberattacks every day and has long warned of breaches by actors as varied as high-school students in their basements to nation-states.
In his Facebook post about the attack, Loong warned that "those trying to break into our data systems are extremely skilled and determined. They have huge resources, and never give up trying."
In 2017, hackers broke into a defence ministry database, stealing the information of some 850 Singapore army conscripts and ministry staff.