Hackers have been identified who sent phishing emails to more than 100 employees of a German company and its European suppliers, a security firm announced on Monday.

The hacking attempt was part of an apparently coordinated effort to steal data about individuals involved in the German government's efforts to secure face masks and other necessary protective materials from international sources, according to a report published by IBM's X-Force Incident.
The suspicious activity began on March 30, from a Russia-based IP address, and appears to be ongoing, according to the report. The phishing emails direct targets to fake Microsoft Corp. login pages.
The German company and its suppliers were not named, and it was unclear whether any of the fraudulent emails were effective. However, the IBM report highlights the heightened risks of intrusion for organizations involved in work , from procuring medical equipment to developing vaccines.
The US Department of Homeland Security and the Federal Bureau of Investigation said in May that hackers working for the Chinese government were trying to steal research data on potential Covid-19 vaccines from US companies and government agencies. The World Health Organization revealed in April that it had identified increasing attacks targeting the accounts of senior officials, including WHO Director-General Tedros Adhanom Ghebreyesus and Bruce Aylward, a senior WHO envoy who led a Covid-19 response team in China.
The IBM did not attribute the attack attempts it discovered to a specific country or group. The possible motives for hacking individuals involved in the pandemic response vary, from gathering information about other countries to criminal goals looking for ways to capitalize on the surge in demand for medical equipment and supplies.
