FB pixel

Cybercriminals exploit lack of MFA use by aid groups

Categories Access Control  |  Biometrics News
Cybercriminals exploit lack of MFA use by aid groups
 

Humanitarian organizations in the Middle East are being targeted by cyberattacks likely coming from supporters of the Houthi rebels, an Islamist movement based in Yemen.

The revelation that cyber attackers are attempting to steal credentials and gather information from humanitarian and human rights groups comes amid a trend of incorporating biometrics into aid distribution. The United Nations’ World Food Programme (WFP) has been introducing biometric solutions in Yemen to answer the country’s humanitarian catastrophe.

The cyberattacks were performed by a group named OilAlpha, according to findings from threat intelligence company Recorded Future. The threat group established a fake web portal that spoofed a generic login capability. It then created a cluster of malicious Android applications and supporting infrastructure used to conduct credential theft against human rights or humanitarian aid workers based in the Middle East.

Recorded Future’s threat research division Insikt Group believes the attacks could be organized to control aid distribution in Yemen.

Among the organizations that have been affected are CARE International, the Norwegian Refugee Council, and the Saudi Arabian King Salman Humanitarian Aid and Relief Centre. Insikt Group suspects malicious applications tied to OilAlpha have spoofed the UN or its World Food Programme.

The division first uncovered the cyberattacks in May 2023. A year later, the company discovered a suspicious Android file connected to OilAlpha which requested invasive permissions, such as access to the camera, audio, SMS, contacts and more.

To limit the damages of credential theft, Insikt Group recommends strong passwords and enabling multi-factor authentication (MFA) where possible.

A recent investigation from digital rights group Access Now concluded that the use of biometrics and digital ID in humanitarian projects could use more transparency, including better disclosure around procurement, data protection impact assessments (DPIAs) and incident reports.

Related Posts

Article Topics

 |   |   |   | 

Latest Biometrics News

 

India scales farmer ID system for payments with KPMG support

The India office of influential accounting firm KPMG has explained how it supported the advancement of the country’s Digital Agriculture…

 

Digital ID systems fail migrants due to policy gaps, Caribou finds

A new report by research organization Caribou has warned that digital ID systems around the world have continued to deepen…

 

Certainty vs flexibility – does the UK need a Biometric Surveillance Act?

By Professor Fraser Sampson, former UK Biometrics & Surveillance Camera Commissioner Last week London became a city of two tales. Two…

 

TestMu AI releases testing tool for agent-produced code

TestMu AI (formerly LambdaTest) has launched Kane CLI, “a new browser automation tool that runs directly from the terminal,” and…

 

Travel biometrics making new connections

Airport biometrics projects and companies are breaking new ground and intersecting with other industry trends, from digital wallets to biometric…

 

Biometric Update Podcast: Teresa Wu on SIA’s Corporate Credential Design Guide

The Security Industry Association (SIA) has published its Corporate Credential Design Guide, and Idema Public Security’s Teresa Wu, who has…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events