Sierra Leone: Government confirms cyberattack on 44 websites

More articles

Sierra Leone’s government has confirmed that 44 website addresses, including one belonging to a government institution, were affected by a cyberattack targeting the country’s national internet domain management system.

The Ministry of Communication, Technology and Innovation said the breach occurred on 25 September, when unauthorised access was gained to the CoCCA domain management system used to administer internet domains.

The incident exposed affected websites to the risk of being redirected to fraudulent pages, potentially allowing attackers to impersonate legitimate organisations and deceive internet users.

The ministry said the breach was detected and contained on the same day, with all affected website addresses restored to their correct settings within hours.

“Immediate measures” were also taken to prevent further unauthorised access, remove the threat and strengthen the system’s security, the ministry said in a press release issued on Friday.

A subsequent security review found no evidence of continuing unauthorised access as of 8 October. However, the authorities have yet to establish publicly how the attackers gained access or whether the incident resulted in financial losses, stolen information or other harm to users.

The government’s announcement follows a security report published by Google on 6 October, which identified Sierra Leone among several countries affected by a wider series of attacks involving national domain systems, including those of Ghana and American Samoa.

The incident has raised concerns about the security of Sierra Leone’s digital infrastructure, particularly the systems responsible for directing internet users to legitimate websites.

The country’s “.sl” domain is used by government institutions, commercial businesses and other organisations. If domain records are altered without authorisation, visitors attempting to access legitimate websites may instead be directed to malicious destinations.

The ministry did not identify the government website or the commercial websites affected. It also did not disclose whether any users had been successfully redirected to fraudulent websites.

Investigations remain ongoing, with the government saying it is working with local and international partners to monitor the system and introduce additional safeguards against future attacks.

While the authorities say the immediate threat has been contained, questions remain about the vulnerability that allowed the breach, the extent of any potential exposure and what measures will prevent a recurrence.

The ministry said the government remained committed to protecting the country’s digital infrastructure and would inform the public of significant developments.

For now, the government’s account indicates that the affected website addresses have been restored and that no continuing unauthorised access was identified in the subsequent review. The full impact of the incident, however, remains unclear as investigations continue.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisement -spot_img

Latest