2 ms·
Bitmarck may not be able to protect all data, but it can protect its reputation. Rest is silence. In January 2023, there was already a security breach where t
by Borrible 3y ago
Bitmarck may not be able to protect all data, but it can protect its reputation.
Rest is silence.
In January 2023, there was already a security breach where they managed to make sure that no one in the broader public was interested.
Bitmarck's customers, some statutory health insurers in Germany, are also keeping quiet, of course.
They own the store and have been trying to 'sell' the German version of an electronic health record system to the wider population.
A system neither physicians nor the population does exactly crave to be part of, if it's not secure.
To 'cite' parts of a translation by deepl of the German Wikipedia article:
'January 2023
In January 2023, unauthorized access to Bitmarck's instance of the collaboration tool Jira occurred using stolen credentials. This was possible because employee credentials were successfully compromised and also because two-factor authentication was not used. In the process, a data set containing personal data and access data of insured persons was also stolen. Bitmarck, on the other hand, claimed in its statement of January 19, 2023, that there was no leak of data, neither from the provider itself, nor from customers or insured persons. The data set, which can be found on the Internet, was already published on January 17 and proved the opposite. It contains the data of the compromised Jira instance and was created on January 16. The dataset contains three different versions (December 2020 as well as two from April 2021), with the latest version containing about 330,000 entries. Medical data is not included in it, but personal data such as date of birth, insurance numbers and health card serial numbers as well as password data is.
In addition, the attacker managed to gain access to numerous other systems - including e-mail and remote desktop services for Windows Server, according to research by Heise. The editors noticed that the passwords were short and simple. In addition, the passwords for different systems were quite similar. Both of these contradict the practice that has been known for years for the basic protection of IT systems and thus also the recommendations of the BSI, among others. The successfully compromised Bitmarck employee used a single SSH key for full root access to 1,100 servers. Heise had contact with the attacker and found that he was not well versed and did not seem to have been aware of the scope of his attack, targeting unprotected targets in an untargeted manner. The Bitmarck had therefore been fortunate that the damage was far less than would have been technically possible.'
https://de-m-wikipedia-org.translate.goog/wiki/Bitmarck?_x_tr_sl=auto&_x_tr_tl=de&_x_tr_hl=de&_x_tr_pto=wapp https://de-m-wikipedia-org.translate.goog/wiki/Bitmarck?_x_t...
I take it, the second job in April is based on information distilled from the first one in January.
There is a reason, you don't and will not find much about the affair even in German public.