ransomware
Credible
Libya (LY)
government
BSISP Libya listed by the DragonRansomware group
BSISP Libya
CompanyBSISP Libya
Domainbsisp.ly
CountryLibya (LY)
Sectorgovernment
Breach date2024-10-29
People affected500,000
Ransomware groupdragonransomware
Data typescitizen records, administrative data, employee information
Overview
The DragonRansomware group has listed BSISP (bsisp.ly), a Libyan public institution, on its leak site. The announcement was made via the group's Telegram channel on 29 October 2024.
What was published
The group claims to have hacked the institution's website. The archive is expected to include administrative data and citizen records.
Risks for affected individuals
- Citizens' personal data may be exposed.
- Administrative records could be misused.
- Employees' information may be included.
What remains unknown
- The volume of data exfiltrated.
- Whether the data has been published.
- The response status of the institution.
What affected people should do
The institution should coordinate with Libyan authorities, review affected systems, and inform staff. Citizens should be alert to phishing referencing public services.
Sources
- https://t.me/DragonRansom/348