A little-used archive held information on foreign citizenship applicants, but officials have not confirmed whether the attackers managed to take any records.

    Lithuania’s Ministry of the Interior reported a cyberattack on the EPEKIS archival information system. Unauthorized access to the system was blocked, and the ministry passed information about the incident to law enforcement.

    This is reported by the media outlet LRT.

    What data the EPEKIS system stored

    The attackers used the system, administered by the Ministry of the Interior’s Information Technology and Communications Department, to access data about foreigners who had applied for Lithuanian citizenship. EPEKIS also contains information about public services related to documents and consultations.

    The system has not been actively used since 2018. According to the ministry, most records contain names and surnames but no personal identification numbers.

    Consequences of the cyberattack and checks of other systems

    The ministry said recently introduced security measures helped detect the attack and stop it from spreading. Data sets were created after the breach, but there is currently no evidence that the attackers downloaded them.

    The incident was reported to the Criminal Police Bureau, the State Data Protection Inspectorate, and the National Cyber Security Centre. Lithuania’s Minister of the Interior, Martynas Katelinas, ordered a review of the security of all information systems and databases under the ministry’s authority. He also suggested that an artificial intelligence platform may have been used in the attack.

    In May, Lithuania’s Prosecutor General’s Office reported an investigation into unauthorized access to more than 600,000 records in the Real Estate Register. According to law enforcement, the records – including those containing personal identification numbers – were accessed using compromised accounts belonging to employees of the Migration Department.

    Lithuania’s Ministry of the Interior reported a cyberattack on its information system

    Share.

    Comments are closed.