Pakistan warns key ministries of ‘severe’ ransomware attacks, urges security system upgrades

Members of a Computer Emergency Response Team (CERT) in Islamabad engaged in an international online drill on March 11, 2020 to test preparedness against cyber attacks. (AN photo/File)
Short Url
Updated 10 August 2025
Follow

Pakistan warns key ministries of ‘severe’ ransomware attacks, urges security system upgrades

  • The ransomware encrypts victim files, appends extension, and demands ransom in exchange for decryption keys
  • The advisory comes after the ransomware targeted some organizations, including the Pakistan Petroleum Limited

ISLAMABAD: Pakistan’s National Cyber Emergency Response Team (NCERT) has issued an advisory to 39 key ministries and institutions and warned them of a “severe risk” posed by the ongoing ‘Blue Locker’ malware attacks, an NCERT spokesperson said on Sunday, confirming that a few Pakistani organizations had already been affected by the ransomware.

NCERT, which handles cybersecurity threats, alerts and coordination for government ministries and institutions, advisory came after the ransomware targeted some organizations in the South Asian country, according NCERT spokesman Imran Haider.

“Pakistan Petroleum has been impacted severely and some other organizations were also attacked, but our deployed system is detecting and blocking it continuously,” he told Arab News.

Blue Locker ransomware can impact Windows-based desktops, laptops and servers as well as network shares, cloud-synced storage and backup systems accessible during the attack, according to an Aug. 9 NCERT advisory seen by Arab News.

“The Blue Locker ransomware encrypts victim files, appends the .blue (dot blue) extension, and demands ransom in exchange for decryption keys,” it said, adding that the attack may initiate through trojanized downloads, phishing emails, unsafe file-sharing platforms and compromised websites.

“It has the potential for severe data loss, operational disruption, and reputational harm.”

Once executed, the ransomware may disable antivirus software, spread laterally across the network, and exfiltrate sensitive information, according to the advisory.

As a precaution, organizations must keep all systems updated with the latest security patches, apply multi-factor authentication, filter malicious emails or web content, avoid downloading software from untrusted sources, train staff on threat detection, and monitor systems and maintain offline backups of critical data.

“Immediate isolation of any infected system and prompt reporting to the cybersecurity team are essential to prevent further spread,” NCERT said.

Independent cybersecurity experts say Pakistani government bodies lack structures, policies and constant vigilance needed to counter increasingly sophisticated cyber threats.

Tariq Malik, a cybersecurity expert and former Chief Technology Officer with Pakistan’s army, said the country’s ministries and government departments were “ill-prepared” to handle such attacks.

“They do not have such structure and clear policies to deal with such sophisticated attacks,” he told Arab News. “Government departments need to start using the technology as a whole not only as personal computers and need proper safety mechanisms and trainings.”

Ammar Jaffery, president of the Pakistan Information Security Association (PISA), said the nature of cybersecurity has changed from reactive to proactive, and organizations now need to continuously train their staff to deal with daily emerging challenges.

“Hackers are always ahead of experts, so it’s not just about capability but about continuous learning, where organizations must recognize that cyber threats are growing daily, weekly and monthly,” he told Arab News.

“Therefore, organizations should regularly check their systems and create ongoing awareness among their technical and general staff.”

Key ministries and departments should have their own cybersecurity teams, according to Jaffery.

“They should train their Security Operations Center (SOC) teams and ensure up-to-date Security Information and Event Management (SIEM) systems, and especially their own CERT which acts like a watchman guarding your home — are always on alert,” he said.


Australia says father and son carried out Sydney beach attack as Pakistan condemns violence

Updated 5 sec ago
Follow

Australia says father and son carried out Sydney beach attack as Pakistan condemns violence

  • Australian authorities say at least 15 people were killed in the shooting, including a 10-year-old girl
  • Pakistan says it stands in solidarity with Australia, condemns terrorism in all forms and manifestations

ISLAMABAD: Australian authorities said on Monday a father and son carried out a mass shooting at Sydney’s Bondi Beach during a Jewish festival, as Pakistan expressed solidarity with Australia and condemned the attack that claimed at least 15 lives.

Police said the 50-year-old father was shot dead at the scene while his 24-year-old son was wounded and taken into custody after the gunmen opened fire on crowds gathered for a Hanukkah celebration at the popular beach.

“We want to get to the bottom of this,” New South Wales police commissioner Mal Lanyon said on Monday. “We want to understand the motives behind it.”

A 10-year-old girl was among the 15 dead in Australia’s worst mass shooting for almost 30 years, while 42 more were rushed to hospital with gunshot wounds and other injuries.

Pakistan’s government said it stood with Australia following the shooting, reiterating its opposition to such incidents amid renewed militant violence at home.

Prime Minister Shehbaz Sharif expressed condolences to the victims and said Pakistan condemned “terrorism in all its forms and manifestations.”

President Asif Ali Zardari also conveyed sympathy to the victims’ families and wished the injured a speedy recovery.

“Pakistan itself a victim of terrorism, stands in solidarity with & condemns violence against innocent civilians,” he said.

Pakistan has faced a resurgence in militant attacks in recent months, particularly in its northwest. On Sunday, Sharif praised security forces after they killed 13 militants in two separate operations in the Mohmand and Bannu districts, according to a statement from his office.

Australian police said the attackers fired from a raised boardwalk overlooking the beach, sending people fleeing in panic. Authorities later discovered what they described as an improvised explosive device in a vehicle parked near the scene, which they believe was linked to the attackers.

Prime Minister Anthony Albanese said tougher gun controls may be needed, including limits on the number of firearms an individual can own, after police confirmed the father held licenses for six weapons believed to have been used in the attack.

Mass shootings have been rare in Australia since sweeping gun law reforms were introduced after the 1996 Port Arthur massacre, but Albanese said the latest attack required authorities to reassess whether existing controls remained sufficient.

With input from AFP