By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
TechgoonduTechgoonduTechgoondu
  • Audio-visual
  • Enterprise
    • Software
    • Cybersecurity
  • Gaming
  • Imaging
  • Internet
  • Media
  • Mobile
    • Cellphones
    • Tablets
  • PC
  • Telecom
Search
© 2023 Goondu Media Pte Ltd. All Rights Reserved.
Reading: Uphill struggle against cyber attacks, as Mindef hacking case shows
Share
Font ResizerAa
TechgoonduTechgoondu
Font ResizerAa
  • Audio-visual
  • Enterprise
  • Gaming
  • Imaging
  • Internet
  • Media
  • Mobile
  • PC
  • Telecom
Search
  • Audio-visual
  • Enterprise
    • Software
    • Cybersecurity
  • Gaming
  • Imaging
  • Internet
  • Media
  • Mobile
    • Cellphones
    • Tablets
  • PC
  • Telecom
Follow US
© 2023 Goondu Media Pte Ltd. All Rights Reserved.
Techgoondu > Blog > Internet > Uphill struggle against cyber attacks, as Mindef hacking case shows
Internet

Uphill struggle against cyber attacks, as Mindef hacking case shows

Alfred Siew
Last updated: March 1, 2017 at 7:09 PM
Alfred Siew
Published: March 1, 2017
5 Min Read
SHARE
PHOTO: Ady Satria Herzegovina via Creative Commons

Some 850 employees and national servicemen in Singapore would do well to change their online passwords immediately, after news emerged yesterday that their personal data was stolen from Ministry of Defence (Mindef) computers.

The NRIC numbers, telephone numbers and birth dates of these unfortunate users were lost as part of a cyber attack that breached the defences for one of the most security-conscious government agencies here.

With that data, cyber criminals could try logging in to e-government services, as some of them rely on an NRIC number as a username.

Or they could sell the information to spammers to deliver annoying messages on the phone. In an interconnected world, any data that exposes a user is a useful link to cyber criminals for follow-up attacks.

Bad news is, the victims may not yet know who they are. The defence ministry said it was reaching out to them within the week, after first discovering the hacks in early February. Meanwhile, their data is still out in the open, possibly to be exploited.

The incident has proven once more that defending against today’s cyber threats is an uphill struggle, even for the most prepared.

To be sure, the computers breached at the ministry were on its I-net system, which lets servicemen and employees go online. These are less strictly secured than those that store classified information, which was not stolen, according to the ministry.

Though it might come as a shock to the public, the attack on the ministry should not surprise anyone tasked to defend against such increasingly sophisticated cyber threats.

No longer are casual hackers and petty criminals involved in online attacks today. “State actors”, or government-sanctioned hackers, are the most dangerous threats now because of their training, skills and organisation.

The recommended approach today is to assume that your systems are already compromised, that an attacker has already entered the premises.

Industry experts now speak of an arms race. Just as cyber defences have relied on artificial intelligence (AI) to automate the search for vulnerabilities and identify attacks, hackers have learnt to fine-tune their attacks by using autonomous systems as well.

To its credit, the defence ministry has been open in announcing the hack. It could not hide, after all, when the protection of personal data was at stake.

The attack, said to be “targeted and carefully planned”, is also another wake-up call for government agencies planning to go digital with more e-services in the months ahead.

After personal data was stolen from SingPass accounts in 2014 to perform illegal e-government transactions, many agencies were forced to move from an antiquated login system to a more robust one using hardware tokens.

This time round, the emphasis must be on how the attack was carried out. Since the defence ministry’s public-facing computers were expected to be breached, what were the safeguards in place to protect users’ personal data? Why was this accessible on the arguably more vulnerable systems?

Investigations are still ongoing now, but the public has a right to know what happened, just as customers of a bank, e-mail provider or department store should be told if their data was lost.

Indeed, the government has a larger responsibility. Not just because people tend to trust it more – citizens often have no alternative but to deal with an agency. National serviceman, for instance, depend on the defence ministry to keep their data protected.

The government routinely fines small and medium enterprises (SMEs) if they are deemed to have inadequate security measures in place to protect customers’ data.

Why happens when the defence ministry loses personal data, then? The Personal Data Protection Act doesn’t apply to public agencies but surely they have to show they are better equipped to deal with emerging threats than SMEs.

Ultimately, what can end users do to protect themselves, if these breaches are expected to be more common? Unfortunately, the only advice is to be constantly vigilant.

Responding to each attack by quickly changing passwords or using multiple accounts to avoid being locked out all at once may be among the few mitigating actions one can take. This is the new normal.

Line messaging, iTunes gift card scams re-appear in Singapore
Zeemart Zoom promises to let F&B industry procure food items easily
Latest virtual mobile operator Giga launches in fast-saturating Singapore market
Netflix out in Singapore now, costs from S$10.98 a month
At 50, Singapore seeks new path as a Smart Nation
TAGGED:2FAcyber securitydata thefthackingMindefPDPCSingapore

Sign up for the TG newsletter

Never miss anything again. Get the latest news and analysis in your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Whatsapp Whatsapp LinkedIn Copy Link Print
Avatar photo
ByAlfred Siew
Follow:
Alfred is a writer, speaker and media instructor who has covered the telecom, media and technology scene for more than 20 years. Previously the technology correspondent for The Straits Times, he now edits the Techgoondu.com blog and runs his own technology and media consultancy.
Previous Article StarHub JuniorProtectPlus plan lets parents set surfing curfews for children
Next Article Phone makers pile in to exploit Samsung weakness
Leave a Comment

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Stay Connected

FacebookLike
XFollow

Latest News

Scammers are so successful they even accidentally scam themselves now
Cybersecurity Internet
June 10, 2025
Doom: The Dark Ages review: Future fantastic demon slaying
Gaming
June 10, 2025
Plaud NotePin review: Note-taking made easy with AI
Internet Mobile
June 9, 2025
Can smart grocery carts, biometric payments boost retailers like FairPrice?
Enterprise Internet
June 6, 2025

Techgoondu.com is published by Goondu Media Pte Ltd, a company registered and based in Singapore.

.

Started in June 2008 by technology journalists and ex-journalists in Singapore who share a common love for all things geeky and digital, the site now includes segments on personal computing, enterprise IT and Internet culture.

banner banner
Everyday DIY
PC needs fixing? Get your hands on with the latest tech tips
READ ON
banner banner
Leaders Q&A
What tomorrow looks like to those at the leading edge today
FIND OUT
banner banner
Advertise with us
Discover unique access and impact with TG custom content
SHOW ME

 

 

POWERED BY READYSPACE
The Techgoondu website is powered by and managed by Readyspace Web Hosting.

TechgoonduTechgoondu
© 2024 Goondu Media Pte Ltd. All Rights Reserved | Privacy | Terms of Use | Advertise | About Us | Contact
Join Us!
Never miss anything again. Get the latest news and analysis in your inbox.

Zero spam, Unsubscribe at any time.
 

Loading Comments...
 

    Welcome Back!

    Sign in to your account

    Username or Email Address
    Password

    Lost your password?