NATO has confirmed that its IT team is investigating allegations of an alleged data theft through a breach of its Communities of Interest (COI) Cooperation Portal . The NATO breach appears to have been carried out by a group of hackers known as SiegedSec .

The COI Cooperation Portal (dnbl.ncia.nato.int) is the military alliance's information sharing and cooperation environment, dedicated to supporting NATO organizations and member states
Yesterday, the hacking group “SiegedSec” published on Telegram some data that is supposed to be hundreds of documents stolen from the COI Cooperation Portal.
See also: SEC: Companies must report significant cyberattacks within 4 days
Cybersecurity firm CloudSEK analyzed the published data and found that it included 845 MB of files, 8,000 lines of sensitive information, documents , and user account access credentials .
The leaked data includes:
- Full name
- Company/Unit
- Working group
- Job title
- Business Email ID
- Residential address
- Photo
According to CloudSEK's analysis, the data leak, if confirmed, affects 31 nations that are members of the NATO alliance.
NATO says the claims and their authenticity are currently being investigated.
“We face malicious online activity on a daily basis, and NATO and Allies are responding to this reality by strengthening our ability to detect, deter and respond to such activities“.
See also: Cyberattack affects two ambulance services in Southern England

The SiegedSec hacking group, which earlier this year claimed a breach at software company Atlassian and leaked thousands of files, does not appear to have a financial motive. Instead, it is considered a hacktivist group, which seems more interested in leaking data and causing chaosto make a statement, or as it puts it, just for fun.
Regarding the alleged breach of the COI portal, SiegedSec states that it was done as a sign of protest against the attacks committed by NATO member countries on human rights.
“We would like to emphasize that this attack on NATO has nothing to do with the war between Russia and Ukraine, this is retaliation against NATO countries for attacks on human rights (- Also, document leaks are fun ^w&^ ),” SiegedSec wrote on their Telegram channel.
See also: Alphapo hack: Are Lazarus hackers behind it?
SiegedSec is a fairly active and dangerous hacking group. Although the exact details of the group's composition and origins remain unclear, its actions make it undoubtedly one of the most significant players in the cyberattack space. The group has demonstrated capabilities that include data, network compromise, and DDoS attacks.
Source: www.bleepingcomputer.com
