CSIDB logo
Incident

Gemalto

Incident posture

Attack window
Oct 2017
Location
France
Status
Unknown
CIA posture
Available to members
Updated
2026-08-29 03:39

Linked entities

Victim
Gemalto
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hackers gained unauthorized access to Amazon Web Services infrastructure used by Aviva and Gemalto, hijacking their computing resources to mine Bitcoin cryptocurrency. The intrusion did not involve data theft or attempts to steal sensitive information, and the affected companies were notified by the security researchers who discovered the activity.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

A group of hackers gained unauthorized access to Amazon Web Services infrastructure that was being used by two companies, Aviva and Gemalto. Once inside, the attackers did not attempt to exfiltrate sensitive data such as personal information or credentials. Instead, they repurposed the compromised compute instances to perform cryptocurrency mining for Bitcoin. The hackers’ activity consisted of running workloads that solved the mathematical puzzles required to generate new Bitcoin tokens.

The security research group RedLock identified the intrusion and published a report describing the compromised instances as having been turned into parasitic bots conducting nefarious activity on the internet. RedLock noted that the attackers’ focus on resource hijacking rather than data theft was unusual compared to typical breach motives. Following the discovery, RedLock notified Amazon, Aviva, and Gemalto about the compromise.

Amazon, Aviva, and Gemalto were all informed of the incident by RedLock at the time the article was written. None of the three companies had issued any public statements regarding the breach. The unauthorized consumption of compute power for mining resulted in the companies’ resources being used to generate cryptocurrency that benefited only the attackers.

Sources

Sources available to members: 1 source.

CSIDB