Ozys Reveals Deliberate Security Breach by Former CISO
In the aftermath of its platform hack, South Korean blockchain network Ozys has made a significant revelation. The breach, which resulted in the disappearance of $81.5 million of investors’ digital funds, was not a result of overlooked security measures. Instead, it was a deliberate act by their former Chief Information Security Officer (CISO) who intentionally weakened the firewall security of the blockchain protocol. The CISO altered the network’s firewall policies just two days before submitting a voluntary resignation request and left the company without any communication. The team was unaware of the security changes until January 10 when the cyber attack was discovered.
Stolen Funds Likely Linked to Lazarus Group
Ozys CEO Jinhan Choi also revealed that the infamous North Korea-backed cyberthreat team Lazarus Group may be involved in the company’s ordeal. The attack methodology used to breach the cross-chain service bears similarities to those employed by the state-backed cybercriminal group. In response, Ozys has notified the Korean National Intelligence Service and the Cyber Terror Investigation Unit of the National Police Agency to investigate further. The Lazarus Group has a history of targeting the crypto ecosystem and has previously stolen billions of dollars in digital assets from various platforms.
Collaboration with Law Enforcement and Improved Security Measures
Ozys is actively working with law enforcement agencies such as the Korea Internet Security Agency (KISA) and pursuing legal action against the former CISO. Additionally, they have engaged blockchain security firm Theori to audit their smart contracts code and prevent similar incidents in the future.
Hot Take: Former CISO’s Actions Highlight Insider Threats in Crypto
The deliberate weakening of Ozys’ network security by their former Chief Information Security Officer underscores the risks posed by insider threats in the crypto industry. This incident serves as a reminder that even with robust security measures in place, individuals with privileged access can compromise the integrity of blockchain networks. It is crucial for companies to implement strict security protocols and regularly monitor and audit their systems to detect and prevent such breaches. Collaboration with law enforcement and cybersecurity firms is essential to investigate incidents, hold responsible parties accountable, and strengthen overall industry security.