Romanian friends have told me that this is really due to corruption.
Specifically:
- government gives IT/data contracts to cronies
- cronies don't actually do any real security work to protect the data
- things like this happen
Same thing is rampant in other Eastern European countries as well. Tips on how to address this for those of us that are publicly minded?
Somebody vibed an explainer dashboard with what surfaced online about the incident https://ancpi-atac.mariuscomper.uk/en/
It is not corruption. Or not just corruption.
A close relative, government employee, was in charge of building a new application. They have nobody in that entire organization of several thousands people that know how to write specifications for an IT application, nobody that knows how to design, test and deploy it. This is because some government employees have decent salaries, but in IT the private sector is paying a lot more, so almost anyone remotely competent is going to the private sector. So in this case an organization of non-IT people had to deal with the contract and all the associated problems - there is no need to guess, it did not go well. That kind of project could have been done properly with ~ 10% of the budget in the same timeline.
I have a friend that worked as a developer in such a government IT project. The project cost was ~ 5-10 times what was worth, a chain of sub-contractors did the work, less than ten competent people doing the project, charged by the bid winner for over 100 people and actual staff was around 70 at most, for a short period of time.
Both projects above are in Romania. Lack of competent people in the projects, especially in decision roles, was the main problem.
They said this in the article:
> Sources told Risky Business that the hacker entered using valid credentials
This is the same in the UK too. Governments everywhere are the same. It's just humans motivated by greed and easily corruptible.
"It's corruption and cronies" is a generic cop-out answer that doesn't explain anything.
Like whenever someone gets caught in a compromising situation they say they "were hacked", as if saying that means anything.
It's always amusing how this is always attributed to the corruption.
It's even more funny on Reddit when you can see the person who is blaming cronies in his Romania but has posts of him doing some blue-collar work in the Midwest.
As a Romanian I can tell you that most of the corruption happens through "dedicated contracts", or outright syphoning.
In this case I expect an underpaid employee, and at most an incompetent nephew of someone. They had no reason to have an .authorized_keys file in the webroot of the website, and yet they did.
If you want to know what "dedicated contracts" look like in practice they are overly specific requirements than can only match a single business. The best example that comes to mind was when one county needed to buy busses (or vans) and the maximum length admitted was bellow the most common options, but as luck would have it a nephew of a cousing of someone with decision power (or something like that) just so happened to be the one importing cars that precisely matched the specs.