Supply chain β›“ Supply Chain

Private and Government Organizations in Vietnam Third-Party Breach (December 2020)

πŸ“… 2020-12-01 🏒 Vietnam Certification Authority
Primary Source β†—

Incident Details

Operation SignSight: Supply-chain attack against a certification authority in Southeast Asia. ESET researchers have uncovered a supply-chain attack on the website of a government in Southeast Asia. Award-winning news, views, and insight from the ESET security community. Just a few weeks after the supply-chain attack on the Able Desktop software , another similar attack occurred on the website of the Vietnam Government Certification Authority (VGCA): ca.gov.vn . The attackers modified two of the software installers available for download on this website and added a backdoor in order to compromise users of the legitimate application. Third-party company: Vietnam Certification Authority.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Vietnam Certification Authority
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2020-12-01 Breach occurred
  2. 2020-12-01 Publicly disclosed