ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

International Criminal Court says September cyber attack was a cyber espionage operation

The International Criminal Court said that a major cyber attack that targeted its network in September was, in fact, a cyber espionage operation carried out by an unknown state actor.In a post shared on Twitter in September, the International Criminal Court said it detected suspicious activities in its internal rework and took immediate steps to respond to the incident and mitigate its impact.“Additional response and security measures are now ongoing, with the assistance of the host country authorities,” the post read.ICC said that it was in the process of recovering its systems and mitigating the impact of the attack, along with prioritising that the “core work of the Court continues.”“The Court is thankful to the Host Country for the excellent cooperation and the immediate response and support provided in relation to this incident. Looking forward, the Court will be building on existing work presently underway to strengthen its cyber security framework, including accelerating its use of cloud technology.“In this context, support from States Parties and stakeholders remains critical to further enhance institutional resilience. under challenging circumstances,” ICC added.In a recent update posted on its website, ICC said that its internal investigation revealed that threat actors targeted its systems and network for espionage purposes.“The evidence available thus far indicates a targeted and sophisticated attack with the objective of espionage. The attack can therefore be interpreted as a serious attempt to undermine the Court’s mandate.“Based on the forensic analysis carried out, the Court has already taken and will continue to take all necessary steps to address any compromise to data belonging to individuals, organisations and States. Should evidence be found that specific data entrusted to the Court has been compromised, those affected would be contacted immediately and directly by the Court. For the Court, the safety of its data and maintaining trust with all of its stakeholders are paramount,” ICC said.ICC has so far not been able to identify the identity of the threat actors who infiltrated its network, however, it said that an ongoing criminal investigation is carried out by the Dutch law enforcement authorities. ICC has also reinforced its risk management framework and taken necessary actions to respond to potential repercussions from the recent cyber attack.“This latest attack comes at the time of broader and heightened security concerns for the Court: several elected officials, including Judges of the Court and the Prosecutor, have had criminal proceedings initiated against them; the Court has recently undergone daily and persistent attempts to attack and disrupt its systems; and the Court averted an almost successful attempt to infiltrate a hostile intelligence officer into the Court under the guise of an intern,” the International Criminal Court added.Commenting on the news, William Wright, CEO of Closed Door Security, said, “Given the information held by the ICC, this was never just a chance attack. It was more likely planned by a nation state actor that knew exactly what they wanted and how to get it. We therefore shouldn’t take the statements too seriously that there is no evidence of data being compromised.“Whether data was exfiltrated, or simply viewed, some sophisticated nation-state adversaries can enter and exit systems without leaving a trace. This means we may not understand the full extent of this attack until the criminals make it public or use it against the ICC.“This attack is another clear reminder that as cyber space becomes the playing field for all forms of criminals, organisations must improve their cyber defences.“It’s not clear how criminals initially breached the ICC’s network, but the attack would most likely have been executed via phishing or by exploiting an unpatched vulnerability. Prioritising security against these attack vectors is essential. This involves training employees frequently on security threats, while also keeping up to date with patch cycles and running pen tests on networks to unearth unknown weaknesses,” Wright added.

Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543