Europol confirms hacking of the organization's web portal without data leakage

Father

Professional
Messages
2,604
Reputation
4
Reaction score
608
Points
113
Europol confirmed that its Platform for Experts (EPE) portal was hacked, but denied the data leak. The attacker previously stated that he stole the documents "only for official use."

EPE is an online platform that law enforcement experts use to "share knowledge, best practices, and depersonalized crime data."

Europol claims that the platform did not contain any operational information, so important data was not compromised.

Meanwhile, the EPE website is disabled and the service itself is unavailable.

IntelBroker, the attacker behind the leak claims, claims that the data it stole includes information about alliance employees, source code for documents, PDFs, and intelligence data and instructions. According to him, he got access to EC3 SPACE (a secure platform for accredited cybercrime experts), which hosts hundreds of materials related to this topic. More than 6 thousand authorized cybercrime experts from all over the world rely on them. The hacker published a small sample of the EC3 SPACE database, presumably containing 9,128 records. It includes something like the personal information of law enforcement officers and cybercrime experts who have access to the community.

IntelBroker also claims to have hacked the SIRIUS platform used by judicial and law enforcement agencies from 47 countries, including EU member states, the UK and others. It provides access to cross-border electronic evidence in the context of criminal investigations.

IntelBroker became known after hacking DC Health Link, which manages the health care plans of members of the US House of Representatives and employees and families. At the same time, the personal data of 170 thousand individuals, including employees of the US House of Representatives, were disclosed.

In addition, the hacker hacked Hewlett Packard Enterprise (HPE) systems.

Earlier this week, IntelBroker also started selling network access information to cloud security company Zscaler. It includes logs with credentials, SMTP access, PAuth pointer authentication access, SSL access keys, and SSL certificates.

• Source: https://www.bleepingcomputer.com/ne...ortal-breach-says-no-operational-data-stolen/
 
Top