KelvinSecurity Hacker Group: A Notorious Data Seller

 





Introduction

KelvinSecurity hacker group is likely a Russian-based hacker organization, also having a significant presence deep and Dark Web forums that are frequented by all types of hackers and cybercriminals. It is a notorious data seller that offers valuable information to its customers, along with the unauthorized access to cybercriminals within various systems to let them exploit their vulnerabilities. 

This group is popular for selling initial access to the cybercriminals and attacked many organizations like Vodafone (Italy), Drakorindo, etc. Recently, it has targeted the German Institute of Global and Area Studies (GIGA), situated in Hamburg. 

GIGA conducts interdisciplinary research on political, economic, and social developments in Asia, Africa, Latin America, and Middle East. KelvinSecurity stole a total of 1GB of its data containing confidential information about the organization's employees and staff. The hacker group shared a post on Dark Web claiming that the stolen data also includes SQL and Drupal databases. 

Why an Educational Institution?

There is a significant rise in the number of cyber attacks on various educational institutions globally. This may be because post-pandemic many institutions were forced to work online resulting in storing of more sensitive data on the computer systems. 

Hence, the increase in the use of technology has resulted in making these educational institutions a prime target for the hackers. So, these institutions must work  proactively to protect their data from such attacks.

Detection & Mitigation

Some of the prevention and mitigation techniques are as follows:
  • Network and host hardening to reduce exposure to threats.
  • Vulnerability management to reduce the security weakness in the exposed services. 
  • Using strong data encryption will reduce its usefulness even if it is stolen.
  • Make use of Data Loss Prevention (DLP) and Endpoint Security to protect the sensitive data from leaking via the network or end-user devices. 
  • Use network and application-level firewalls to stop unwanted traffic from entering.

Conclusion

KelvinSecurity sells data of various organizations to the cybercriminals on Dark Web. Hence, a strong prevention strategy should be applied to prevent these attacks from compromising valuable information. 














































Comments

Popular posts from this blog

Query, Visualize, & Monitor Data in Azure Sentinel

Planning for Implementing SAP Solutions on Azure (Part 2 of 5)

Work with String Data Using KQL Statements