Hackers Are Going After COVID-19 Vaccine s Rollout
id="article-body" class="row" section="article-body">
The hacking campaign posed as a cold storage container company. Pfizer's vaccine needs to be stored at extremely low temperatures.
Sarah Tew/CNET
For the most up-to-date news and information about the coronavirus pandemic, visit the [ WHO website].
Hackers aren't just looking to steal information on the [/health/covid-19-vaccine-facts-hidden-costs-when-you-can-get-vaccinated-choosing-vaccine-brands/ vaccines for COVID-19]. They're also going after its distributors and suppliers, security researchers warned in a report released Thursday.
Researchers from [ IBM's X-Force team detailed a global hacking campaign] targeting government agencies, tour đài loan từ hà nội tech companies and energy suppliers in countries like Germany, Italy, South Korea and Taiwan. The companies and agencies are all connected to the Cold Chain Equipment Optimization Platform, a partnership between UNICEF, the vaccine alliance Gavi and other organizations to help with vaccine distribution.
Editors' top picks
Subscribe to CNET Now for the day's most interesting reviews, news stories and videos.
The attacks came as emails pretending to be from Haier Biomedical, a Chinese company that says it's the world's only complete cold chain provider. The cold chain is a crucial part of [ ] as the vaccine needs to be stored at a temperature of -70 degrees Celsius (-94 degrees Fahrenheit).
Haier Biomedical is working with CCEOP, the World Health Organization and tour đài loan từ hà nội the United Nations to help with the COVID-19 vaccine's rollout, and the hackers sent emails to targets asking for price quotes, [/tags/ibm/ IBM's] researchers said.
A Haier Biomedical representative said the company was investigating the security concerns, and is taking the threats seriously.
Now playing:
Watch this:
Vaccines, antibody tests, treatments: The science of...
6:02
The emails contained a malicious attachment that would ask people to enter their passwords to view the files, which the hackers would steal. It's unclear if any of the attacks were successful, tour đài loan but the purpose was likely to gather information for future attempts, IBM's researchers said.
"Moving laterally through networks and remaining there in stealth would allow them to conduct cyber espionage and collect additional confidential information from the victim environments for future operations," said Claire Zaboeva, a cyberthreat analyst at IBM's X-Force and co-author of the report.
The [/tags/hacking/ hacking] targets included the European Commission's Directorate-General for Taxation and Customs Union, which would be in direct contact with several countries and could open pathways for more targeted attacks.
See also
[/health/senior-us-leaders-just-got-the-covid-19-vaccine-heres-where-you-stand-in-line/ COVID-19 vaccines are almost here. Who could get them first -- and last]
[/health/covid-19-reinfection-can-you-get-the-coronavirus-more-than-once-what-we-know-so-far/ COVID-19 reinfection: Can you get the coronavirus more than once? What we know so far]
[/how-to/best-antivirus/ The best Windows 10 antivirus protection for 2020]
The hackers also sent malware-laced emails to companies making solar panels, which provide power for cold storage containers in countries without access to electricity, and to IT companies in South Korea and Germany that support pharmaceutical manufacturers.
"A breach within any part of this global alliance could result in the exposure of numerous partner computing environments worldwide," IBM's researchers said.
The report didn't indicate who was behind this hacking campaign, but suggested that it's likely a nation-state because of how sophisticated the targeting is. In [ ][ ] have launched cyberattacks against pharmaceutical companies developing COVID-19 vaccines.
On Wednesday, The Wall Street Journal reported that [ North Korean hackers have targeted] at least six pharmaceutical companies in the US, UK and South Korea that have been working on vaccines.
The US Cybersecurity and Infrastructure Security Agency released a [ statement on the hacking campaign], urging companies involved with [/coronavirus/ coronavirus] vaccines to review IBM's report.
[#comments Comments]
[/topics/security/ Security]
[/coronavirus/ Coronavirus]
[/tags/ibm/ IBM]
[ Notification on Notification off Storage]