Site navigation

Data on 500k “Vulnerable People” Compromised in Red Cross Cyber-Attack

Ross Kelly

,

Red Cross Cyber attack
Charities and humanitarian organisations are becoming “highly attractive” targets due to the sensitive data they hold.

Information on more than half a million people has been exposed following a “sophisticated” cyber-attack onthe International Committee of the Red Cross (ICRC).

In a statement on 19th January, the Committee confirmed the cyber-attack, which targeted and compromised an external company in Switzerland contracted to store ICRC data.

At least 60 Red Cross and Red Crescent organisations were impacted by the attack, and initial analysis shows that personal data and confidential information on 515,000 “highly vulnerable people” has been exposed.

This includes data on people separated from families due to conflict, migration or natural disasters, as well as information on missing persons and people in detention worldwide.

ICRC computer systems were shut down in the wake of the attack, taking the Restoring Family Links programme offline. The global initiative aims to reunite separated families and operates in a host of countries worldwide.

“Because of the attack, we have been obliged to shut down the systems underpinning our Restoring Family Links work, affecting the Red Cross and Red Crescent Movement’s ability to reunite family members,” the ICRC said in a statement.

“We are working as quickly as possible to identify workaround to continue this vital work.”

‘Appalled and Perplexed’

The ICRC said the “most pressing concern” for the charity is that confidential information may be shared publicly, exposing vulnerable people and putting lives at risk.

“An attack on the data of people who are missing makes the anguish and suffering for families even more difficult to endure,” said Robert Mardini, Director-General of the ICRC.

“We are all appalled and perplexed that this humanitarian information would be targeted and compromised,” he added.

At present, the Committee said there was no “immediate indication” of who was responsible for the attack, or that compromised information had been leaked online or shared publicly.

Mardini also appealed to the culprit(s) behind the Red Cross cyber-attack, urging them not to release exposed data.

“While we don’t know who is responsible for this attack, or why they carried it out, we do have this appeal to make to them,” said Mardini. “Your actions could potentially cause yet more harm and pain to those who have already endured untold suffering.”

“The real people, the real families behind the information you now have are among the world’s least powerful. Please do the right thing. Do not share, sell, leak or otherwise use this data,” he added.

‘Highly Attractive’ targets

Lotem Finkelsteen, Head of Threat Intelligence and Research for Check Point, said that humanitarian organisations are now appealing targets for hackers and cybercriminals.

Many charities hold personal, financial and commercial data that could be of interest or monetary value to cybercriminals.

“Hackers show no mercy on healthcare or other such humanitarian targets, and the Red Cross is not alone here,” he said. “Hacking groups are aware of the sensitivity of this data, and they see them as ‘fast money targets’.”

“The larger risk here is leak of compromised data, which could lead to potentially devastating consequences for victims, Finkelsteen,” Finkelsteen added.


Recommended


Brian Higgins, security specialist at Comparitech, echoed Finkelsteen’s comments, noting that charities are coming under increasing strain from cyber threats.

He said: “Egregious attacks such as this are, unfortunately, becoming an occupational hazard for charity and relief organisations as the vital nature of the data the possess, coupled with the extreme vulnerability of the individuals to whom it relates, provides a highly attractive target for certain groups.”


Get the latest news from DIGIT direct to your inbox 

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

We will keep you up to date on the pivotal issues impacting the sector and let you know about key upcoming events to ensure that you don’t miss out on what’s going on across the Scottish tech community.

To subscribe, click here.

Ross Kelly

Staff Writer & Researcher

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data