SingHealth attack was by APT group typically linked to foreign governments: Iswaran

Published Mon, Aug 6, 2018 · 09:50 PM

    Singapore

    THE cyber attack in Singapore that led to the leak of 1.5 million SingHealth patients' personal data was the work of an "advanced persistent threat" group typically linked to foreign governments, Parliament heard on Monday.

    Advanced persistent threats (APTs) are stealthy and continuous computer-hacking processes to gain intelligence or steal information.

    Minister for Communications and Information S. Iswaran, responding to a record 19 questions filed by MPs, the highest in this term of Parliament on a single issue, said: "This refers to a class of sophisticated cyber attackers, typically state-linked, who conduct extended, carefully planned cyber campaigns, to steal information or disrupt operations.

    "The APT group that attacked SingHealth was persistent in its efforts to penetrate and anchor itself in the network, bypass the security measures, and illegally access and exfiltrate data."

    Mr Iswaran, who is also Minister-in-charge of cyber security, noted that the attack fits the profile of certain known APT groups, but for national security reasons, he did not elaborate.

    He has already convened a Committee of Inquiry to get to the bottom of what went wrong. Lessons will be drawn from the incident to strengthen the safeguards of Singapore's critical information infrastructure (CII), including those in healthcare, banking, land transport and telecommunications.

    Acknowledging that the cyber attack has sparked worries of identity theft or fraudulent transactions, Mr Iswaran assured the House that there are "multiple safeguards" to prevent the stolen data from being misused.

    He said: "I would like to emphasise that that there are multiple safeguards in place to mitigate such risks, especially for financial transactions and sensitive government e-transactions."

    For instance, financial institutions such as banks and insurance companies do not just rely on personal information to verify customer identity. "All banks and insurance companies in Singapore already have two-factor authentication (2FA) for online financial services, such as making fund transfers or accessing account details."

    Under 2FA, account holders have to key in their Personal Identification Number (PIN) and a one-time-password (OTP), which is received via SMS or a bank's authentication token.

    Mr Iswaran said the OTP allows for an additional authentication layer known as "transaction signing", which protects higher-risk transactions such as adding a third party payee or transferring large sums of money.

    He added: "Unless the attacker has access to all authentication information, it would not be possible for fraudulent transactions or identity theft to occur."

    All sensitive government electronic transactions have been protected by SingPass 2FA since July 2016.

    Last Friday, 11 critical services sectors in Singapore were told to review their cyber security readiness, even as the government lifted the pause on new Smart Nation projects that was imposed after the recent SingHealth data breach.

    Specifically, they were instructed to strengthen the security around their network connectivity gateways to prevent data leakage.

    Mr Iswaran said the Cyber Security Agency's (CSA) forensic investigations team has extracted the "indicators of compromise", or pieces of forensic data used to identify malicious activity on a network, from the infected computers. "CSA then instructed owners and regulators of CII to scan for these indicators, and advised them on possible measures to mitigate a similar incident," he added.

    The 11 affected sectors are aviation, healthcare, land transport, maritime, media, security and emergency, water, banking and finance, energy, infocomm and the government itself.

    Of the compromised database of 1.5 million SingHealth patients, 160,000 patients had their prescription data stolen, including that of Prime Minister Lee Hsien Loong, who was the primary target of the hackers.

    Member of Parliament (MP) Joan Pereira (Tanjong Pagar GRC) said there is heightened interest in the cyber attack because it follows the Wannacry ransomware attack last year, which affected hundreds of thousands of computers worldwide.

    Questions from MPs included whether the culprit will be taken to task, and how the government plans to restore public confidence in the Smart Nation project.

    Attacks by hackers on National University of Singapore (NUS) and Nanyang Technological University (NTU), discovered in April last year, were also performed by APT groups aiming to steal government and research data.

    NTU and NUS are involved in government-linked projects for the defence, foreign affairs and transport sectors.