cyberattacks

Axa operations in Asia hit by cyberattack, including Philippines

Gelo Gonzales

This is AI generated summarization, which may have errors. For context, always refer to the full article.

Axa operations in Asia hit by cyberattack, including Philippines

AXA PH. The Axa.com.ph is currently down as of Monday afternoon, May 17

Gelo Gonzales/Rappler

The stolen data may include customer medical reports, copies of ID cards, bank account statements, claim forms, payment records, and contracts

French insurer Axa was hit by a ransomware attack, the company announced Sunday, May 16.

The attack specifically hit its Asia Assistance division, affecting IT operations in Thailand, Malaysia, Hong Kong and the Philippines.

“As a result, certain data processed by Inter Partners Asia (IPA) in Thailand has been accessed,” the company said in a Reuters report. It also plans to notify corporate clients and individuals if they had been affected.

The attack was first reported by The Financial Times (paywall) on Saturday, May 15, before Axa confirmed the report a day later. Three terabytes of data were said to have been stolen by a ransomware group called Avaddon.

BleepingComputer also reported seeing a Distributed Denial of Service (DDoS) attack against AXA’s global websites that rendered the sites inaccessible for a time on Saturday. The site also said that some of the data stolen include customer medical reports which include sexual health diagnoses, copies of ID cards, bank account statements, claim forms, payment records, contracts, and more.

The group is said to be using DDoS attacks as an additional mechanism to force victims to pay aside from the ransomware.

The Philippine site Axa.com.ph remains inaccessible at the time of publication.

BleepingComputer said that Avaddon has given Axa about 10 days to cooperate, after which they would leak the data.

Just a week ago, The Federal Bureau of Investigation (FBI) and the Australian Cyber Security Centre (ACSC) had given warnings about a wave of Avaddon attacks.

A week ago, ransomware group DarkSide hit the US’ Colonial Pipeline and Japan’s Toshiba. The Irish health service was also hit with a cyberattack on Friday, May 14. – Rappler.com

Add a comment

Sort by

There are no comments yet. Add your comment to start the conversation.

Summarize this article with AI

How does this make you feel?

Loading
Download the Rappler App!
Clothing, Apparel, Person

author

Gelo Gonzales

Gelo Gonzales is Rappler’s technology editor. He covers consumer electronics, social media, emerging tech, and video games.