Hackers did attack the Hungarian State Treasury’s IT system from Russian servers, according to Népszava, but the operation was not carried out by any Russian intelligence service. Instead, it is alleged to have been the work of an organisation believed to be linked to an Algerian man. The newspaper suspects that the Russian connection is being emphasised merely in an attempt to downplay the authorities’ own serious information-security failings.

Hackers may have penetrated deeply and obtained vast amounts of data

The consequences of the attack on the Hungarian State Treasury’s IT system may have been far more serious than initially suspected. According to information obtained by Népszava, the attackers may have gained access not only to agricultural subsidy data, but also to the pension and family-support systems.

The Treasury has yet to disclose the extent of the damage or whether an attempt was made to extort money. Although the successful attack does not mean that the hackers could move public funds, they may have obtained huge amounts of data on Hungarian pensioners and citizens receiving various family-support payments. Such information could later prove extremely valuable in carrying out a range of fraudulent operations.

According to the newspaper, the hackers may have exploited a known security vulnerability that had not been properly closed. They reportedly gained entry through an outdated web server before acquiring administrator privileges for the central authentication system. From there, they may have been able to access other parts of the network.

Hungary North Korean hackers remote worker scams Hungarian State Treasury cybersecurity

The reason was that the central databases were protected by weak, outdated password security. The attackers were therefore able to break into them virtually in a single step and obtain whatever they wanted.

During the attack, databases containing confidential personal and financial information were also encrypted. The Hungarian State Treasury is currently attempting to restore the affected systems from earlier backups, but so far it has achieved only limited success.

The IT infrastructure is therefore operating only on a restricted basis. Damage limitation and the investigation are being conducted by the National Cybersecurity Institute of the National Security Special Service, working alongside Treasury specialists. The data-protection breach has also been reported to Hungary’s National Authority for Data Protection and Freedom of Information, although that alone will not resolve such a complex problem.

Interestingly, the new government has done nothing yet regarding this issue, although there is still much work to do in order to detect and close all backdoors in the system.

Underage hackers who threatened bomb blasts and murders arrested in Hungarian-Romanian operation – video

Stolen data could easily be abused

The incident is particularly alarming because the compromised credentials may, in theory, have provided access to data connected with the assessment and payment of pensions, as well as the system used to manage local authorities’ bank accounts.

An expert said, however, that this did not mean the attackers could directly access or transfer state funds. The greater danger lies in the abuse of the stolen data – through targeted phishing attacks, for example – and in the disruption of the operation of IT systems.

There are also unanswered questions surrounding the origin of the attack. The Hungarian State Treasury said that the operation had originated from Russian servers, while an analysis by a cybersecurity company pointed to a group known as ByteToBreach, which is believed to be backed by an Algerian man.

Cyberattack hits Hungary’s State Treasury as experts trace attack to Russian servers

According to the newspaper, the group had previously offered for sale on the DarkForums forum data that may have indicated a breach of the State Treasury’s systems.

The case also highlights the significance of an earlier finding by Hungary’s State Audit Office. As long ago as 2019, it warned that data-protection vulnerabilities remained in systems inherited from the former Central Administration of National Pension Insurance. Despite this, the vulnerable components were left in place, allowing the hackers to “walk straight in”.

Does blaming the Russians sound better?

Népszava suggests that the Russian connection may therefore be nothing more than a cover story. No one expects the Hungarian State Treasury and its experts to be able to thwart a Russian intelligence operation, but citizens would be entirely justified in holding those responsible to account if it emerged that an Algerian national had simply walked into the system by exploiting its vulnerabilities – as a result of failings on the Hungarian side – and stolen vast amounts of data about them.

Moreover, criticising Russia on this issue fits more neatly with the current government’s preferred narrative.

Russian hacker group breaches Hungarian geothermal system in coordinated cyberattack

Featured image: depositphotos.com