Menu Customer section

Uncategorized 3 min

Cyber incidents in Czechia in July: ransomware hits public services and healthcare as sophisticated banking vishing emerges


July confirmed that ransomware groups are targeting the Czech economy across all sectors, from public administration and healthcare to energy and culture. Analysts recorded 22 documented threats, with the most aggressive campaign carried out by Titan against IT and consulting firms. A sophisticated campaign targeting mobile banking also emerged, using Czech-language vishing to impersonate bank employees. These findings come from an analysis by ComSource, a Czech company specialising in cybersecurity, network infrastructure and data analytics.

“The July data shows that ransomware groups are not limited to manufacturing or the financial sector. They are systematically targeting the entire Czech economy, including municipal authorities, hospitals and cultural institutions. This is a clear sign of coordinated escalation rather than isolated incidents,” says Jaroslav Cihelka, cybersecurity expert and co-owner of ComSource.

Ransomware targeted public administration and healthcare

On 16 July, The Gentlemen targeted municipal and city authorities, threatening to publish sensitive data unless a ransom was paid. The same group attacked the energy sector on 10 July and, unusually, major cultural institutions on 23 July, putting both their operations and valuable art and visitor databases at risk. Healthcare, a particularly vulnerable sector because of the sensitivity of patient data, was targeted by sophisticated ransomware attacks from Qilin on 7 and 13 July.

“Attacks on hospitals or the energy sector are more than a financial problem for the organisation affected. These are attacks on critical infrastructure, where system failures can directly threaten people’s health or energy supplies. Czech companies and institutions in these sectors should treat investment in cyber defence as a priority, not an optional expense,” warns Jaroslav Cihelka of ComSource.

IT services faced the most concentrated campaign

The most intense wave of attacks affected information technology and professional services. Between 11 and 13 July, Titan hit several consulting firms, data management companies and IT service providers. Manufacturing and industrial services faced attacks from three groups: Akira, Krybit and DeadLock. The links between operational technology and IT in manufacturing businesses make these attacks particularly risky.

“Targeting companies that manage data and IT infrastructure for other organisations is a particularly dangerous trend. A single successful breach of a consulting or data services company can open the door to dozens of other clients. The supply chain is thus becoming one of the weakest links in Czech cyber defence,” warns Jaroslav Cihelka of ComSource.

A new threat: vishing that impersonates bank staff

In July, the financial sector faced a sophisticated threat from WindTapper. The group combined Czech-language vishing, in which attackers impersonated bank employees over the phone, with advanced WindRelay malware capable of relaying payment-card NFC data in real time between a victim and the attacker’s payment terminal.

“WindTapper shows where social engineering is heading. Attackers hire Czech speakers to make their calls sound credible and combine this with malware that can exploit the victim’s physical payment card in real time. Technical protection alone cannot stop such a sophisticated attack. Above all, people need to know how to respond when they receive a suspicious call from someone claiming to represent their bank,” adds Jaroslav Cihelka of ComSource.

At the same time, xplogs22 ran phishing campaigns across multiple sectors, using contract-themed lures to distribute SnakeKeylogger and XWorm malware to retail, energy, manufacturing and financial services organisations. During the period covered, ComSource’s analysis also recorded 215 new detections of leaked credentials from botnet and phishing sources, and more than 77,000 phishing events overall. The vast majority were identified and blocked.

“The combination of ransomware, targeted phishing and new forms of mobile fraud confirms that threats overlap and attackers share both experience and tools. Critical infrastructure sectors such as energy, healthcare and public administration face the highest-impact attacks, while IT services and manufacturing experience the greatest number of incidents. Both demand sustained attention,” concludes Jaroslav Cihelka of ComSource.

The analysis of the Czech cyber threat landscape was prepared in cooperation with Group-IB, whose key partner in the Czech Republic is ComSource. Group-IB is a leading global provider of cybersecurity solutions, specialising in cyberattack prevention, fraud investigation and digital asset protection. The company operates in dozens of countries and is known for its research into threat intelligence, phishing and organised cybercrime.


Loading…