A multi-stage cyberattack against small and midsize Hungarian businesses is continuing, with criminals posing as the country’s prosecutor’s office in emails that lead recipients to a fake site and then deliver ransomware. Hungary’s National Cyber Security Institute, part of the National Security Special Service, issued a warning on Sept. 3, by which time many businesses had already received the messages.
Dénes Fodor, incident-response and cyber-intelligence team lead at White Hat IT Security, described the initial stages as unusually polished: the Hungarian-language text was convincing and the sequence of steps appeared carefully planned. The attackers used email accounts registered with Microsoft Outlook, helping messages evade spam filters and appear plausible. Links directed users to a site closely resembling the prosecutor’s office.
The fake page used a company’s real tax number to retrieve information from public company databases and some less accurate data that may have been obtained illegally. The system then generated a fabricated indictment that looked authentic. White Hat’s reverse engineering indicated that at least 550 people clicked through from the emails and about 340 likely downloaded the infected file. The ransomware encrypted data on a targeted company computer and demanded cryptocurrency worth the equivalent of 1,000 euros.
The first ransomware’s encryption was not robust. White Hat specialists broke it and built a free decryption program that affected users can obtain from the company’s website. Cybersecurity researcher Judit Erős said the gap between the sophisticated setup and the amateur flaws in the malware suggested someone might be learning how to conduct such attacks, possibly with guidance.
A second wave followed. Criminals retained the convincing email, lookalike website and backend that generated plausible fake indictments from authentic data, but replaced the ransomware that had been easy to crack. Experts said the new program showed signs of the technical step-up they had anticipated.
Security specialists warn victims against paying: ransom payments can encourage repeat attacks, while a free decryption tool may become available hours or days later. They urge businesses to seek cybersecurity expertise for prevention as well as incident response, and to handle breaches transparently. Concealing an incident can damage trust and relationships with business partners.