The government’s computer emergency team, BGD e-GOV CIRT, issued a national cybersecurity alert on Friday. Its trigger is a post: on 31 July a hacker group announced that a “storm of cyber attacks” would hit Bangladesh’s cyberspace on 15 August. The group calls itself hacktivist, claims to be Indian, and names Bangladesh and Pakistan as its targets. CIRT’s alert, signed by project director Mohammad Saiful Alam Khan, tells banks and financial institutions, health services, critical information infrastructure and all government and private organisations to expect attacks and prepare.
What they have done so far
CIRT says its research has identified several groups of the same ideology that attack Bangladeshi organisations continuously, and it lists recent claims: on 1 August a group claimed attacks on a payment gateway, a law-enforcement agency and the banking sector; on 3 July a group claimed a one-hour DDoS attack on a transport service; on 27 June a government college’s website was defaced, with a sample published; and on 24 June the same was done to a health-sector site. This is the pattern of the “hacktivist” groups that have traded attacks across the India–Bangladesh–Pakistan triangle for years: defacements, denial-of-service floods, and claims that are larger than the damage.
What CIRT recommends
- Monitor network infrastructure 24 hours, especially outside office hours, and watch for data being moved out.
- Put a web application firewall in front of incoming HTTP/HTTPS traffic to filter malicious requests and patterns.
- Secure DNS, NTP and network middleboxes, which are used to amplify DDoS attacks.
- Validate all user input on web applications.
- Keep backups of websites.
- Enforce HTTPS with SSL/TLS.
- Run up-to-date software.
- Report anything suspicious to CIRT.
What is actually at risk
Two things should be said plainly. First, the threat is real and the date is a symbolic one — the anniversary of the 1975 assassination and India’s Independence Day — which is exactly the kind of date such groups pick. Second, the realistic damage from groups of this kind is embarrassment: defaced pages on government sites that have not been patched since they were built, and an hour or two of downtime on services that lack DDoS protection. The systems that would cause real harm if breached — the interbank network, mobile money, the power grid’s control systems — are not the ones a hacktivist crew reaches with a defacement kit. The alert’s value is that it makes a thousand IT managers apply the updates they have been postponing, which defends against the serious attackers as well as the loud ones.
Update: 15 August passed with a handful of DDoS attempts and defacements of minor sites reported; CIRT reported no breach of critical systems.




