In the age of fake news, as individuals we are being encouraged to check the sources of information that we use. One of the primary sources that we are often told can be trusted, is our own government, especially on political topics. In this instance, a governmental emergency early warning network was compromised by hackers in Australia.
What happened?
Australian emergency warning service The Early Warning Network, was recently hacked by an unknown group of attackers, who used the service to distribute a message to registered individuals: “EWN has been hacked. Your personal data is not safe. Trying to fix the security issues,”.
If this sounds like something out of the plot of a film, that’s because it’s not far off: In Die Hard 4 terrorist hackers released news about a fake attack on the Whitehouse, causing widespread panic and concern.
Why does it matter?
Luckily, in this instance, the hackers didn’t attempt to send out a fake emergency alert. However, emergency systems are designed to facilitate mass communication—particularly in situations where other sources of information may not be available for fact checking—so, misuse is a major concern.
In short, an emergency system that no one trusts is useless.
What can we learn?
With information so easily obtainable online, it is important for trusted primary sources to stand out above the rest of the noise and maintain that trust.
This situation demonstrates one of the key risks of backup and emergency systems; they must be easy to use, resilient, and secure enough to avoid misuse by unauthorised parties. This will ensure the trust factor does not deteriorate.
Of course, such competing factors can often compromise each other without careful design.
All too often, security is solely focused only on confidentiality (keeping things secret), but it is important to remember that integrity (ensuring that information is correct) is equally a security concern. As governments and companies move more services—and methods of information dissemination online—they need to take great care to ensure the integrity of the data they release. Failure to do so, can result in reputational risks primarily but, in the long term, a breakdown of trust between official information and the intended recipients may cost lives.
For more information about this story.
Insights
Trust & Safety: A look ahead to 2025
Working within the Trust and Safety industry, 2024 has been PGI’s busiest year to date, both in our work with clients and our participation in key conversations, particularly around the future of regulation, the human-AI interface, and child safety.
Lies, damned lies, and AI - Digital Threat Digest
At their core, artificial systems are a series of relationships between intelligence, truth, and decision making.
A pointless digital jigsaw - Digital Threat Digest
Feeding the name of a new criminal to the online OSINT community is like waving a red rag to a bull. There’s an immediate scramble to be the first to find every piece of information out there on the target, and present it back in a nice network graph (bonus points if you’re using your own network graph product and the whole thing is a thinly veiled advert for why your Ghunt code wrap with its purple-backlit-round-edged-dynamic-element CSS is better than everyone else’s).