Kaustkiy and Cryptolulz666 gained access to the systems of the Dutch Chamber of Commerce, a website that is owned by an HK company.
About 200 users' data were acquired by the hacker, but he chose to provide the details of only half of them as evidence of the attack.
The hacker acknowledged that he was targeting organisations in Hong Kong and that this was not a random choice.
He emphasised that if administrators disregard the security pillars, a seemingly insignificant vulnerability like SQL Injection could have grave repercussions.
Source: https://securityaffairs.com/54726/data-breach/dutch-chamber-of-commerce-hacked.html
TPRM report: https://scoringcyber.rankiteo.com/company/dutchchamhk
"id": "the1121181123",
"linkid": "dutchchamhk",
"type": "Breach",
"date": "12/2016",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization’s existence"
{'affected_entities': [{'customers_affected': 200,
'industry': 'Business Services',
'location': 'Hong Kong',
'name': 'Dutch Chamber of Commerce',
'type': 'Organization'}],
'attack_vector': 'SQL Injection',
'data_breach': {'number_of_records_exposed': 200,
'type_of_data_compromised': 'User Data'},
'description': 'Kaustkiy and Cryptolulz666 gained access to the systems of '
'the Dutch Chamber of Commerce, a website owned by an HK '
"company. About 200 users' data were acquired by the hacker, "
'but he chose to provide the details of only half of them as '
'evidence of the attack. The hacker acknowledged that he was '
'targeting organizations in Hong Kong and that this was not a '
'random choice. He emphasized that if administrators disregard '
'the security pillars, a seemingly insignificant vulnerability '
'like SQL Injection could have grave repercussions.',
'impact': {'data_compromised': 'User Data'},
'lessons_learned': 'Administrators should not disregard security pillars as '
'seemingly insignificant vulnerabilities like SQL '
'Injection can have grave repercussions.',
'motivation': 'Targeting organizations in Hong Kong',
'threat_actor': ['Kaustkiy', 'Cryptolulz666'],
'title': 'Data Breach at Dutch Chamber of Commerce',
'type': 'Data Breach',
'vulnerability_exploited': 'SQL Injection'}