Bulgaria's Hacked Database Leaks To Hacking Forums (zdnet.com) 32
The database of Bulgaria's National Revenue Agency (NRA), which was hacked over the weekend and sent to local reporters, is now being shared on hacking forums, ZDNet has learned from sources in the threat intelligence community. From a report: Download links to the hacked database have been shared by a hacked data trader known as Instakilla, believed to be operating out of Bulgaria. ZDNet obtained a copy of the database and verified its authenticity with local sources, and this is a copy of the same database sent to local media over the weekend. The database contains 57 folders, 10.7 GB in size, and holds personal and financial information consistent with what Bulgarian newspapers reported receiving over the weekend. This includes personally identifiable information, tax information, from both the NRA, and from other government agencies who shared their data.
Great! Always wanted data on everyone in Bulgaria (Score:2)
Age of Anything Goes and Nothing Matters (Score:3)
Re: (Score:1)
Re: (Score:2)
The comments of the minister of finances, (Score:4)
who is the boss of the organizations that have leaked the data is as clueless as his IT staff.
The other day someone sent me a comment he made when the leak became known: "I apologize to the affected by the hacker attack Bulgarian citizens and I assure them that their data is being well defended". The authorities also apparently arrested a guy who had nothing to do with the leak and pressured him to "confess".
It seems there are some places in the world that are so backwards and corrupt that for them IT access is more trouble than advantage.
Easy to catch the culprit (Score:2)
So, it's Bulgarian tax data and was uploaded by a hacker who is believed to also be Bulgarian. So take the uploaded data, compare it to the original data, and see if any people/information are missing. One would assume a hacker wouldn't want their own information included in data they are offering up for sale.
Re: (Score:1)
Most of the data is old, but there are some records as recent as March/April this year.
To me it looks like a warning shot.
Isolate critical information from the internet !! (Score:2)
"... a Bulgarian IT expert for releasing public details about how to exploit a vulnerability in a state-managed kindergarten web portal to harvest the GRAO details of all Bulgarians."
This kind on information (GRAO : Department Civil Registration and Administrative Services) MUST BE TOTALLY DISCONNECTED FROM THE INTERNET ! Why on earth is this kind of information available on the "same network" as a public Web portal ?!
Re: (Score:2)
Re: (Score:2)
Shocked Face (Score:1)
"This includes personally identifiable information, tax information, from both the NRA, and from other government agencies who shared their data."
Hmmm, NRA tax data from Russia? As George Takei would say, "Oh MY!"
The NRA (the National Russian Alliance) is going to have some 'splainin to do by the time this is all over.
When asked for a comment, Trump said, "I don't even know what street Russia is on!"