Skip to main content

Hackers have told the FBIK their version of the story with egov

Submitted by fbrk_news on
Хакеры рассказали ФБРК свою версию истории с egov

The FBRK interviewed members of the hacker group DATASUCKERS, which had previously claimed attacks on Dodo Pizza and Tez Tour. Separately, we asked them about reports of the hacking of eGov and leaks of Kazakhstanis' data.

The interviewee could not confirm a direct hack of eGov. But he said that back in 2023, according to his information, it was possible to automatically retrieve records from the State database "Individuals".

HOW DATA COULD HAVE BEEN OBTAINED

As an example, the interviewee showed FBRK the format of a response that, according to him, could be obtained from the system three years ago.



The response contained an IIN, full name, gender, date of birth, a person's status, age and details of valid documents.

When asked how long it would theoretically take to collect the data of all citizens in this way, the interviewee replied that it all depends on the capabilities of the system itself.

"How an IIN is constructed has long been known. I think a couple of days. It depends on the system itself, how many requests per second it can process and return."

He clarified that he was referring specifically to the situation in 2023 and that he does not currently know whether such 

"I have no idea how eGov itself was hacked. Maybe also parsing, I'm leaning towards that."


WHAT HAPPENED WITH THE DATA OF 15 MILLION KAZAKHSTANIS

Earlier, FBRK wrote about a darknet forum user under the nickname shymzz13, who put up for sale a database supposedly containing the data of 15 million residents of Kazakhstan.

The listing mentioned a file of 2.7 GB and 47 million rows. The seller claimed that the array contained passport data, phone numbers, email addresses, information about places of work, scans of documents and passwords, and that the information itself had allegedly been obtained after hacking eGov.

Later, the Ministry of Artificial Intelligence and Digital Development stated that the hack of government systems had not been confirmed. The ministry also noted that part of the published information did not correspond to the structure of eGov data.

The story was later examined by experts from the International Fact-Checking Association GFCN and NoFake.kz. They noted that the listing offering the data for sale alone does not prove either the existence of the entire claimed database or its origin from eGov.

The FBRK interviewee also believes that the reports of a new leak are a continuation of the old story.

"The new eGov leak is a fake made from the old one."

WHY THE TOPIC IS RELEVANT AGAIN 

Recently, users have been reporting that the voluntary refusal to receive bank loans and microcredits they set up in eGov is allegedly being removed without their consent. In itself, this does not indicate a hack and does not confirm a connection with previous leaks.

Problems with government services have already attracted attention. On 21 August, eGov and a number of government websites temporarily became unavailable. Later their operation was restored, and the cause was cited as increased activity of external internet traffic and the triggering of protective mechanisms.

The issue of data protection is broader than just one eGov. 

Earlier, FBRK wrote that Kazakhstan ranked first in Central Asia by the number of publications of databases linked to leaks. According to the company F6, the country accounted for 57% of such publications in the region, and the volume of compromised records amounted to around 25 million rows.

In the case of the database of 15 million Kazakhstanis, the eGov hack was not officially confirmed. The FBRK interviewee also does not claim otherwise and calls parsing only one of the possible versions of how the data was obtained.

We will report on what goals this hacker group pursues in our following materials. Follow our publications. 

To be continued… 

Наша редакция участвует в партнёрской сети «Все СМИ».