Singapore universities hacked in attempt to steal government data
Hackers broke into NUS and NTU IT systems with advanced persistent threats.
Hackers broke into IT systems in two of Singapore’s largest universities looking to steal government and research data, according to the Cyber Security Agency of Singapore.
The attacks on the National University of Singapore and the Nanyang Technological University were detected in April. They were Advanced Persistent Threats, where a hacker breaks into a network and remains there undetected for a long period of time with the intent of stealing data.
CSA has not revealed what data has been stolen, but in a statement said that the attacks are “carefully planned and are not the work of casual hackers. The objective may be to steal information related to government or research”.
The universities' systems are separate from government ones, so the extent of the attacks “appear to be limited”, it added. “There is no evidence that information or data related to students was being targeted” and “no sign of suspicious activity” on critical infrastructure and government networks.
"We know who did it, and we know what they were after. But I cannot reveal this for operational security reasons," Chief Executive David Koh told a press conference.
The agency is working with NTU and NUS to conduct forensic analysis of the nature and extent of the attack. “At both NTU and NUS, affected desktop computers and workstations were quickly isolated, removed and replaced,” CSA said.
These hacks are separate from the global ransomware attacks that took place over the weekend. No Singaporean government agencies or critical infrastructure were affected by those, CSA said. A shopping mall, however, was attacked.
Subscribe to GovInsider Bulletin for the latest updates on public sector innovation
*If I have provided a non-business domain email address (such as, but not limited to, gmail, hotmail, etc) I am doing so in the context of it being used for my business and not personal interactions with GovInsider.
GovInsider is part of Clarion Events Pte Ltd which is part of the Clarion Events Group of companies (Clarion).
We take your privacy seriously. We wish to use your information on the basis of our legitimate interests to keep in contact with you about relevant events, products and services which may be of interest to you. We will only ever use the information we collect or receive about you in accordance with our Privacy Policy. If you prefer us not to contact you about relevant events, products and services that we believe you will be interested in, you can manage your preferences via a link we will send you, unsubscribe using the link in our emails or by emailing [email protected].