Cyber espionage; Insider attack; Social engineering; Spear-phishing; Unauthorized use of user privileges

Energy // Indonesia

Samin Tan, chairman of one of the world’s biggest mining companies, “was targeted by hackers who disguised themselves as Wikipedia researchers in order to retrieve explosive confidential documents from his computer,” according to The Times. According to The Guardian, hackers infected Tan’s laptop with malware as part of a plot to retrieve damning information on the firm, Bumi. Private security firm investigation discovered hackers emailed Tan posing as "Steve", a researcher associated with Wikipedia. "Steve" said Wikipedia wanted to publish an article on the chairman and asked for him to comment. The emails asking for comment “contained links to articles about Tan, which, when followed, are thought to have infected his computer. A whistleblower report emerged afterwards, "containing information thought only to be held on Tan's computer.”; http://www.guardian.co.uk/business/2013/jan/11/fake-wikipedia-researcher-hack-bumi-chairman