DICT says averted 'sophisticated' attacks vs PH websites | ABS-CBN
ADVERTISEMENT

Welcome, Kapamilya! We use cookies to improve your browsing experience. Continuing to use this site means you agree to our use of cookies. Tell me more!
DICT says averted 'sophisticated' attacks vs PH websites
DICT says averted 'sophisticated' attacks vs PH websites
JOHNSON MANABAT,
ABS-CBN News
Published Feb 05, 2024 06:53 PM PHT
|
Updated Feb 06, 2024 12:17 AM PHT

MANILA (UPDATED) — The Department of Information and Communications Technology (DICT) on Monday said the latest hacking attempts on different government websites that are linked to IP addresses of China-backed telco firms are considered "sophisticated."
MANILA (UPDATED) — The Department of Information and Communications Technology (DICT) on Monday said the latest hacking attempts on different government websites that are linked to IP addresses of China-backed telco firms are considered "sophisticated."
DICT Undersecretary for Infostructure Management, Cybersecurity and Upskilling Jeffrey Ian Dy told ABS-CBN News that this is more complicated than the previous hacking attempts thwarted by the cybersecurity experts of the government.
“These attack is quite sophisticated, siguro kung bibigyan mo ako ng scale of 1-10…10 being the most complicated…I would rate this as 9, even 9.5,” Dy said.
According to Dy, the perpetrators were detected in a telecom company based in China but he also clarified that as of the latest, there are no concrete evidence that the Chinese government has something to do with the incidents.
DICT Undersecretary for Infostructure Management, Cybersecurity and Upskilling Jeffrey Ian Dy told ABS-CBN News that this is more complicated than the previous hacking attempts thwarted by the cybersecurity experts of the government.
“These attack is quite sophisticated, siguro kung bibigyan mo ako ng scale of 1-10…10 being the most complicated…I would rate this as 9, even 9.5,” Dy said.
According to Dy, the perpetrators were detected in a telecom company based in China but he also clarified that as of the latest, there are no concrete evidence that the Chinese government has something to do with the incidents.
“We were able to detect a command sa isang computer na nasa loob ng China Unicom network na nag-o-operate sa China. We will have to cooperate with the Chinese government as we do. Pag-aari ito 100 percent ng Chinese government... Mahirap sabihin diretso na ito ay state-sponsored kasi wala naman tayong ebidensiya sa ngayon,” Dy said.
“Right now our investigations wouldn’t say if the Chinese government would know about this attack. As far as we know, the IP addresses, the command and control center including the techniques used ay mukang nandoon sa area na yun,” Dy explained.
“We were able to detect a command sa isang computer na nasa loob ng China Unicom network na nag-o-operate sa China. We will have to cooperate with the Chinese government as we do. Pag-aari ito 100 percent ng Chinese government... Mahirap sabihin diretso na ito ay state-sponsored kasi wala naman tayong ebidensiya sa ngayon,” Dy said.
“Right now our investigations wouldn’t say if the Chinese government would know about this attack. As far as we know, the IP addresses, the command and control center including the techniques used ay mukang nandoon sa area na yun,” Dy explained.
Dy said the agency was able to detect the possible denial of service or an attempt to takedown the website of the Overseas Workers Welfare Administration (OWWA).
There was also a report from Google of an attempted attack to gather government administrator credentials inside the “Google workplace” but the agency was immediately able to remove the malware from the hackers.
Dy named some of the government websites that were targeted by the hackers. These include: dict.gov.ph; coastguard.gov.ph; cabsec.gov.ph; cpbrd.congress.gov.ph; doj.gov.ph; ncws.gov.ph; and bongbongmarcos.com.
“Hindi siya ganon eh, kukunin nya yung administrator credentials pero hindi mo malalaman. Kumbaga, pupuwedeng dalawa kayong gumagamit pa din. Syempre pag nakuha mo na administrator credentials, maaari ka na ring makakita ng iba pang mga impormasyon… Kaya mong magbigay halimbawa ng access or kaya mong gumawa din ng sariling drive o email access,” according to Dy.
Dy said the agency was able to detect the possible denial of service or an attempt to takedown the website of the Overseas Workers Welfare Administration (OWWA).
There was also a report from Google of an attempted attack to gather government administrator credentials inside the “Google workplace” but the agency was immediately able to remove the malware from the hackers.
Dy named some of the government websites that were targeted by the hackers. These include: dict.gov.ph; coastguard.gov.ph; cabsec.gov.ph; cpbrd.congress.gov.ph; doj.gov.ph; ncws.gov.ph; and bongbongmarcos.com.
“Hindi siya ganon eh, kukunin nya yung administrator credentials pero hindi mo malalaman. Kumbaga, pupuwedeng dalawa kayong gumagamit pa din. Syempre pag nakuha mo na administrator credentials, maaari ka na ring makakita ng iba pang mga impormasyon… Kaya mong magbigay halimbawa ng access or kaya mong gumawa din ng sariling drive o email access,” according to Dy.
ADVERTISEMENT
Although the request for confidential funds of DICT was slashed during the budget deliberation, Dy said the agency’s budget for the Cyber Security Bureau was at almost P700 million.
Although the request for confidential funds of DICT was slashed during the budget deliberation, Dy said the agency’s budget for the Cyber Security Bureau was at almost P700 million.
LINKING CYBER ATTACKS WITH SOUTH CHINA SEA ISSUE 'IRRESPONSIBLE'
The Chinese government, meanwhile, said it does not condone any form of cyber attack, and is also cracking down on any cyber attack using Chinese infrastructure.
The Chinese government, meanwhile, said it does not condone any form of cyber attack, and is also cracking down on any cyber attack using Chinese infrastructure.
"The Chinese government all along firmly opposes and cracks down on all forms of cyber attack in accordance with law, allows no country or individual to engage in cyber attack and other illegal activities on Chinese soil or using Chinese infrastructure," the spokesperson of the Chinese Embassy in the Philippines said.
"The Chinese government all along firmly opposes and cracks down on all forms of cyber attack in accordance with law, allows no country or individual to engage in cyber attack and other illegal activities on Chinese soil or using Chinese infrastructure," the spokesperson of the Chinese Embassy in the Philippines said.
It also called the remarks of some Philippine officials linking the cyber attacks to the issue in the West Philippine Sea as "irresponsible".
It also called the remarks of some Philippine officials linking the cyber attacks to the issue in the West Philippine Sea as "irresponsible".
"Some Filipino officials and media maliciously speculated about and groundlessly accused China of engaging in cyber attacks against the Philippines, even went as far as connecting these cyber attacks with the South China Sea disputes. Such remarks are highly irresponsible," the Embassy said.
"Cybersecurity is a global challenge that requires collective response from the international community. China calls on all countries to jointly safeguard cybersecurity through dialogue and cooperation," it added.
"Some Filipino officials and media maliciously speculated about and groundlessly accused China of engaging in cyber attacks against the Philippines, even went as far as connecting these cyber attacks with the South China Sea disputes. Such remarks are highly irresponsible," the Embassy said.
"Cybersecurity is a global challenge that requires collective response from the international community. China calls on all countries to jointly safeguard cybersecurity through dialogue and cooperation," it added.
Meanwhile, the Philippine Coast Guard (PCG) assured the public that their website is secure.
Coast Guard spokesman Rear Admiral Armand Balilo told ABS-CBN News that they have already instructed the agency’s Information and Technology personnel to be more vigilant and make some precautionary measures to protect their website.
"Sa amin naman mukang walang effect pa. Yung mga IT expert naman natin ay on the lookout palagi. Maging vigilant at gumawa ng precautionary measures... So far intact pa po at wala pang unusual kaming nakikita at tayo naman ay gagawin natin lahat para manatiling secure yung ating website," Balilo said.
Meanwhile, the Philippine Coast Guard (PCG) assured the public that their website is secure.
Coast Guard spokesman Rear Admiral Armand Balilo told ABS-CBN News that they have already instructed the agency’s Information and Technology personnel to be more vigilant and make some precautionary measures to protect their website.
"Sa amin naman mukang walang effect pa. Yung mga IT expert naman natin ay on the lookout palagi. Maging vigilant at gumawa ng precautionary measures... So far intact pa po at wala pang unusual kaming nakikita at tayo naman ay gagawin natin lahat para manatiling secure yung ating website," Balilo said.
RELATED VIDEO
Read More:
DICT
hacking
cyber attacks
cyber security
Department of Information and Communications Technology
ANC
ADVERTISEMENT
ADVERTISEMENT