Skip to main content

Hackers breach IMF with ‘sophisticated cyberattack’ [update]

Image used with permission by copyright holder

Hackers have hit the International Monetary Fund with a “large and sophisticated cyberattack,” reports The New York Times. The IMF oversees the global financial system, and has highly confidential records about the economies of nations around the world. IMF staff and its board of directors learned of the attack on Wednesday, but no public pronouncement about the breach has yet been made, besides a vague statement by an IMF spokesman that all but ignores the incident.

“The fund is fully functional,” IMF spokesman David Hawley said in a statement to Reuters. “I can confirm that we are investigating an incident. I am not in a position to elaborate further on the extent of the cybersecurity incident.”

An unnamed IMF “official” who spoke with the Times describes the breach as “very major,” though exact details about what information, if any, was compromised remains unknown. Because the IMF has played an integral role in the bailouts of economically fragile countries like Portugal, Greece and Ireland, its databases contain agreements between various world governments that one fund official described as “political dynamite in many countries.” It is not yet clear whether this information was compromised in the breach.

One official indicated that the attack took place over the last few months, before Dominique Strass-Kahn, a French politician who ran the fund, was arrested in New York for allegedly sexually assaulting a hotel maid.

The attack on the IMF follows a wave of similar digital assaults on a variety of other entities, including Sony, Google, Citibank and prominent US defense contractor Lockheed Martin. The fund reportedly told the Times that it “did not believe” that the intrusion into their system was related to the Lockheed breach.

Those with knowledge of the IMF attack believe that hackers used a technique known as “spear phishing” — tricking a user to click on a malicious link or download spyware that reveals their private credentials — to carry out the intrusion. For the Lockheed breach, on the other hand, hackers broke into the systems of RSA Security and stole data that made it possible to duplicate their SecurID encryption keys, which are used to login to a wide variety of sensitive computer systems around the world.

As the near-constant high-profile attacks that have taken place over the past months shows us, no computer system is 100 percent safe. And because of that, this is far from the last time such an attack will take place. Prepare  yourself, people; it’s about to get interesting.

UPDATE: Bloomberg reports that “hackers believed to be connected to a foreign government” carried out the IMF attack. Nearly every time a “foreign government” has been implicated in a cyberattack recently, that government is China’s. That’s not to say China carried out this attack — we have no idea — but you can bet your dollars they are on the short list.

Editors' Recommendations

Andrew Couts
Former Digital Trends Contributor
Features Editor for Digital Trends, Andrew Couts covers a wide swath of consumer technology topics, with particular focus on…
Lapsus$ hackers convicted of breaching GTA 6, Nvidia, and more
A hacker typing on an Apple MacBook laptop, which shows code on its screen.

The Lapsus$ hacking gang caused havoc in 2021 and 2022 with a series of high-profile security breaches and ransom demands. Yet things have been very quiet since then, and two alleged members of the group have just been convicted in the U.K., potentially bringing an end to one of the most notable hacking sprees in recent times.

According to Bloomberg and the BBC, two people accused of being members of the gang were convicted in the U.K. of a number of crimes, including serious computer misuse, blackmail, and fraud. The defendants included Arion Kurtaj, 18, and a 17-year-old male who could not be named due to his age. Both defendants are autistic and psychiatrists deemed that Kurtaj was not fit to stand trial, so he did not give evidence. They will both be sentenced at a later date.

Read more
Hacker sent to jail for huge 2020 Twitter breach
A Twitter logo graphic.

A British man who took part in a high-profile Twitter hack in 2020 was handed a five-year jail term by a New York federal court on Friday.

Joseph O’Connor, 24, had pled guilty in May to four counts of computer hacking, wire fraud, and cyberstalking. He was also ordered to pay $794,000, the amount that he nabbed in the crypto crime.

Read more
Is ChatGPT creating a cybersecurity nightmare? We asked the experts
A person's hand holding a smartphone. The smartphone is showing the website for the ChatGPT generative AI.

ChatGPT feels pretty inescapable right now, with stories marveling at its abilities seemingly everywhere you look. We’ve seen how it can write music, render 3D animations, and compose music. If you can think of it, ChatGPT can probably take a shot at it.

And that’s exactly the problem. There's all manner of hand-wringing in the tech community right now, with commenters frequently worrying that AI is about to lead to a malware apocalypse with even the most green-fingered hackers conjuring up unstoppable trojans and ransomware.

Read more