Menu
Browse

Cyber Incident Victim: Court of Accounts of Moldova

Date:

Jul 2021

Location:

Moldova

Summary

A cyberattack targeting Moldova's supreme audit institution destroyed public databases and audit reports, prompting an immediate website shutdown during investigation and restoration efforts. The agency stated this unprecedented incident disrupted critical audit missions at their reporting stage, with potential motives including arbitrary hacking, extortion, or deliberate obstruction of governmental oversight functions. While the primary impact involved data destruction and operational interference, attackers could have exploited the compromised site for malware distribution, mirroring recent regional cyber threats against governmental financial platforms.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 4 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 14, 2021, Moldova’s Court of Accounts, the government authority responsible for auditing public financial resources and ensuring compliance with international standards, suffered a destructive cyberattack. Threat actors hacked the agency’s website and destroyed critical public databases containing audit reports and other operational data. The attack occurred during a period of significant audit missions, including high-impact societal audits at the reporting and public disclosure stages. The Court of Accounts described this as the first such incident in the institution’s history, emphasizing the severity of the disruption. In response, the agency immediately shut down its website to contain the incident and initiated efforts to restore the lost data. Officials publicly confirmed the attack through Moldova’s state news agency, Moldpres, on July 15, 2021, while forensic investigations commenced to determine the attackers’ methods and objectives.

Cyber Incident Image

The destruction of public audit records hindered transparency and impeded the institution’s core mandate of overseeing government financial activities. The Court of Accounts launched an investigation to ascertain whether the attack was random, financially motivated through extortion, or a deliberate attempt to sabotage its operations. Although the primary impact involved data destruction, the agency acknowledged the potential for secondary threats, such as malware distribution to website visitors—a tactic previously observed in a separate incident involving Kazakhstan’s government budget portal. No evidence confirmed secondary payload deployment in this case. Recovery efforts focused on data restoration and securing systems, with no public disclosure of technical specifics regarding attacker entry points or infrastructure compromises. The incident underscored vulnerabilities in governmental audit institutions during critical reporting phases.

Sources
Sources available to members
1 source