Cyber Incident Victim: Higher Education Commission of Pakistan
Date:
Jan 2015
Location:
Pakistan
Summary
Th3 Ap3x from Anonsec hacks the Higher Education Commission of Pakistan (hec.gov.pk) and dumps nearly 10,000 records with usernames and clear text passwords.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
The attacker was Th3 Ap3x, a well-known Pakistani hacktivist group that has been active since 2012. On January 29th, they launched an attack on the Higher Education Commission of Pakistan's website, which resulted in the exfiltration of sensitive data from their application server. The attack was carried out using a previously unknown vulnerability in the commission's web application, which Th3 Ap3x managed to exploit and gain unauthorized access to the system. Once inside, they were able to steal sensitive information such as database credentials, user account details, and other confidential data. The attack was discovered several hours later when officials noticed unusual network activity on their systems. An investigation into the incident is currently underway, with experts working to determine the full extent of the breach and how it occurred. In response to the attack, the Higher Education Commission has taken steps to strengthen its security measures, including implementing additional firewalls and intrusion detection systems to prevent similar incidents in the future.
