Technology and philosophy

Showing posts with label cybercrime. Show all posts
Showing posts with label cybercrime. Show all posts

Tuesday, July 7, 2026

IGAD Cyber Drill Participants Demand Enhanced Cooperation Against New Threats

Addis Ababa, June 30, 2026 (ENA) – The IGAD Regional Cyber Exercise 2026 came to an end, with nations involved urging increased regional collaboration, unified cybersecurity strategies, and ongoing efforts to enhance capabilities in response to escalating transnational cyber threats.

The exercise gathered cyber security professionals, government officials, police departments, and key infrastructure managers from Djibouti, Ethiopia, Kenya, Sudan, South Sudan, Somalia, and Uganda.

It became clear during the exercise that participants took part in policy debates, technical drills, and real-world cybersecurity defense activities designed to enhance regional readiness and boost collaborative reactions to cyber threats.

In an interview with ENA, Khadra Ali Yusuf, an expert on data governance at IGAD, mentioned that the exercise effectively integrated policy debates with practical technical drills, such as exchanging threat intelligence and analyzing malicious software.

She mentioned that IGAD plans to capitalize on the achievements of the initiative by setting up a Regional Information Sharing and Analysis Center (ISAC), allowing member countries to exchange details about cybersecurity threats, perform analyses on malicious software, and disseminate insights gained.

As per Yusuf, IGAD is exploring the possibility of turning the regional cyber exercise into a yearly occurrence to enhance technological skills and foster greater collaboration between participating nations.

"Member countries have explicitly stated that they require additional technical knowledge and greater chances to exchange learning experiences. As IGAD, we intend to conduct these exercises every year," the specialist mentioned.

Head of IT Infrastructure at the Ugandan Prime Minister's office, Robert Lwasa stated that the exercise has allowed countries to share insights on cyber security management, organizational structures, and national plans.

Lwasa emphasized that ongoing training, more robust legal systems, political dedication, and cooperation across regions are crucial for safeguarding vital infrastructure and maintaining a safe online space.

On behalf of South Sudan's National Communication Authority, SOC Analyst Yom Malual Majok stated that the hands-on approach of the drill allowed attendees to practice responding to actual cyber threats impacting governmental bodies, banking networks, and private companies.

She mentioned that the training will enable attendees to recognize essential systems, enhance their ability to respond to incidents, and reinforce national cyber security strategies once they return to their own nations.

She highlighted that protecting against cyber threats involves collective effort and requires cooperation across regions.

"Cyber threats do not focus on a single nation since we all utilize the same internet and function within the same digital space," Majok stated, emphasizing that regional structures and collaborative policies can enhance shared strength against such challenges.

On behalf of Somalia's Ministry of Communications and Technology, ICT Director Hassan Hussein Mohammed highlighted the cyber exercise as very advantageous, noting that attendees acquired significant technical expertise and hands-on experience through collaboration with Ethiopian and global specialists.

He stated that Somalia intends to implement the acquired knowledge to enhance its national cybersecurity organizations and bolster the security of vital infrastructure.

Supplied by SyndiGate Media Inc. ( Syndigate.info ).

Cyber Threats Demand Regional Collaboration, Says INSA Deputy Director-General

Addis Ababa, June 30, 2026 (ENA) – Cyber dangers have gone past country lines, highlighting the importance of working together within regions to safeguard vital infrastructure, banking networks, communication services, and people’s confidence, stated Daniel Guta, Deputy Director-General of the Information Network Security Administration (INSA), during the conclusion of the IGAD Regional Cyber Exercise 2026 held in Addis Ababa today.

Speaking to attendees of the five-day regional cyber security exercise, the Deputy Director-General stated that cyber security has now become more than just a national duty; it is also a key concern at both regional and international levels because of how connected digital networks have become.

"Currently, a cybersecurity threat can easily cross international boundaries. A breach targeting one nation may rapidly impact the whole area. Essential infrastructure, banking networks, communication services, and public confidence extend throughout our region. Therefore, our reaction needs to be strongly coordinated," he mentioned.

The Assistant Director-General emphasized that the completion of the exercise signifies the start of a new stage in regional cyber security collaboration instead of the termination of the program.

"This final event does not signify the conclusion of the path. Instead, it represents the start of the most recent stage in global cyber security collaboration," Daniel mentioned.

He identified six key focus areas for upcoming collaboration aimed at enhancing lasting regional cyber resilience. These involve making routine national and regional cyber simulations an official practice, broadening future exercises to address increasingly sophisticated cyber risks, adopting unified cybersecurity standards nationally, setting up systems for swift exchange of threat information across regions, ensuring consistent funding for cybersecurity efforts, and crafting clear strategies to track development.

On behalf of IGAD's Executive Secretary, IGAD Chief Representative in Ethiopia, Abebaw Belachew, stated that the exercise has greatly enhanced the region's joint cybersecurity abilities.

"Five days back, we launched this initiative with the core belief that within our connected system, our safety depends entirely on our shared determination," he remarked. "Today, our regional cybersecurity has significantly improved compared to what it was five days earlier," he continued.

Abeba observed that the activity started with talks about cybersecurity policy, management, and new dangers, then moved to practical instruction in digital investigation techniques utilizing artificial intelligence-based equipment, finally ending with real-time cyber attack exercises on an online network simulation system.

The Leader highlighted that, in addition to technical abilities, the confidence built between cybersecurity experts from participating countries would be crucial in addressing upcoming digital threats.

"If another significant real-world cybersecurity event happens, you won't be dealing with it by yourself. You'll have access to a local group of professionals you can reach out to," he said.

Abebaw also praised Ethiopia and INSA for organizing the event and recognized the assistance provided by the International Telecommunication Union (ITU), the World Bank, and other partner organizations in promoting regional cyber security collaboration.

A five-day exercise ended with the distribution of certificates to attendees representing Djibouti, Ethiopia, Kenya, Sudan, South Sudan, Somalia, and Uganda.

Supplied by SyndiGate Media Inc. ( Syndigate.info ).

Wednesday, July 1, 2026

Coupang Fined Record 624.6 Billion Won Over Data Leak

Coupang faced a data breach impacting 37.55 million consumers in November, leading to a penalty exceeding 600 billion South Korean won. On the 11th, the Personal Information Protection Commission (PIPC) stated that it had determined a fine of 624.681 billion won against Coupang during a session held on the 10th, due to violations of the Personal Information Protection Act. This amount exceeds the prior highest penalty of 134.791 billion won given to SK Telecom in August of the previous year. Additionally, the commission opted to charge an extra fine of 16.8 million won.

The committee said, "The inquiry verified that this event happened because of Coupang's failure in handling personal data security," and mentioned, "Additional instructions were provided to enhance protective protocols to avoid such occurrences."

In November of last year, the PIPC initiated an inquiry following a complaint from Coupang, establishing a collaborative task force alongside the Korea Internet & Security Agency.

A former employee at Coupang, who departed in late 2024, was discovered to have carried out a data leakage experiment in January of the previous year, methodically extracting personal details between April and November of that same year by gaining access to member profile editing sections, delivery address controls, and purchase history records.

A cybercriminal created fake authorization tokens to gain entry into the delivery address administration section roughly 148 million times starting from April 14 of the previous year, resulting in the exposure of names, phone numbers, and residential addresses. On June 24 of the same year, they entered the user profile editing area 34.966812 million times, causing leakage of names and electronic mail identifiers. Starting from September 26 of the prior year, they logged into the delivery address update segment 50,474 instances and reviewed the purchase record interface 85,213 times, also leading to disclosure of common access codes and transaction specifics.

Using these techniques, the hacker exposed personal details of 33.22472 million members and at least 4.338368 million individuals who were not members. This involved 33.057012 million names along with email addresses, 63.986351 million shipping address entries (including names, addresses, and common access codes) for a minimum of 22.375359 million members and 4.338368 million non-members, as well as purchase records from 58,349 members.

The committee verified that the event occurred due to Coupang's insufficient security management framework and carelessness. It stated, "Coupang was unable to effectively control access rights for authentication signature keys, and even though there were unusual surges in access during the attack timeframe, it didn’t identify these anomalies."

Coupang learned about the further exposure of 160,000 customers' private details from the delivery address section approximately on January 30 this year, yet reported it to officials just on February 5, which was six days after discovery. Moreover, despite being asked four times by the committee to inform non-member individuals affected by the breach, Coupang failed to take action.

The committee mentioned, "Individuals who were not members could not implement protective actions against additional harm because they did not know about the leakage."

In addition, Coupang had internal policies requiring the destruction of user data 90 days after an account was removed and immediate removal of addresses along with account numbers. However, it did not erase 2,465,592 delivery address details (including names, phone numbers, and addresses) belonging to deactivated accounts, resulting in these being exposed. Moreover, it was discovered that 318,499 account numbers from terminated users were not promptly erased.

Not long after the committee started its inquiry, it instructed Coupang to retain evidence like website access records connected to the event. Nevertheless, Coupang manually erased five months' worth of online activity logs spanning from July through November 2024, making it harder to establish the precise sequence of events surrounding the first data breach. Still, the committee mentioned, "There was no proof discovered indicating that the exposed personal details were shared unlawfully."

Additionally, the committee expressed disapproval towards Coupang for collecting consumers' internet browsing data without permission.

The inquiry found that Coupang gathered and kept track of online behavior data from 11.17613 million consumers between December 23, 2024, and February 4 of this year, encompassing 15.645338 million website and application accesses, which were utilized for personalized ads.

As a result, the committee chose to charge a penalty amounting to 423.575 billion won and a fine of 16.8 million won concerning the data breach, along with an extra penalty of 201.16 billion won related to the illicit gathering of internet usage information.

Penalties were assessed according to Coupang's online shopping service income. According to the Personal Information Protection Act, fines may be as high as 3% of revenue. The committee said, "The ultimate fine was decided taking into account the seriousness of the breach and the extent of the harm caused."

The committee independently chose to charge a fine of 248 million won against Coupang Fulfillment Services, which is part of Coupang.

The inquiry revealed that Coupang Fulfillment Services gathered and handled the names of 71 media representatives from the National Police Agency, despite these individuals never having worked at their distribution facilities, and added them to a confidential employee list. The committee considered this action a breach of guidelines for collecting and utilizing personal data. Furthermore, Coupang Fulfillment Services provided staff weight details to the court during a legal case involving an workplace injury, which the committee viewed as a violation of protocols concerning handling private information.