71,000 cyber attacks made on FBR portals every month: Tarin

Published October 1, 2021
This file photo shows Finance Minister Shaukat Tarin. — Reuters/File
This file photo shows Finance Minister Shaukat Tarin. — Reuters/File

ISLAMABAD: Finance Minister Shaukat Tarin has informed the National Assembly that on an average the Federal Board of Revenue (FBR) portals were subjected to 71,000 cyber attacks every month.

This volume has, over a couple of years, increased sharply as tools and methods available with the hackers are more powerful and sophisticated, Mr Tarin said in a written reply to a question from PPP MNA Raza Rabani Khar placed before the assembly on Wednesday.

This was the first detailed reply from the finance minister regarding protecting the data of taxpayers.

The minister said FBR had been authorised to procure cyber and information security-related hardware, software and services to protect the organisation from future attacks.

In a written reply, he said during the last three years (Feb 18, 2019 to Feb 22, 202; March 23, 2021; April 13, 2021 to August 19, 2021), FBR’s systems were breached three times (around 0.001pc success rate).

Finance minister recommends annual budget for technology refresh

“The breach in 2019 was not detected till the investigation into the latest breach in August 2021. The breach was minor in nature and the infrastructure hosting the FBR website was hardened. Therefore, a cyber breach-related audit was not carried out to date.”

However, Mr Tarin said there was an ongoing investigation into the current breach with the help of a third party. This third party is helping scan the entire FBR network, including all machines located in the field formations, in order to determine the possible point of the initial breach.

He said once this has been determined and remedial actions have been taken, a full third-party security audit will be carried out to determine any remaining vulnerabilities.

A full action plan to counter the vulnerabilities will be put together and its execution monitored.

“Therefore, a cyber breach-related audit was not carried out to date. Technology continues to evolve at breakneck speed and requires constant reinvestment.”

Historically, investment into technology at the FBR has remained restricted to specific periods directly related to financing being made available by donor agencies.

This method of investment creates technology debt in between such periods which can lead to vulnerabilities going unaddressed, which can consequently create opportunities for malicious actors such as what transpired during this recent event.

The minister said it was highly recommended that an annual budget for technology refresh be allocated to FBR, which would allow the organisation to keep its technology up to date and take full advantage of advancements taking place in that space. This should be equivalent to 0.05pc of the revenue collected which would have amounted to Rs2.4bn last year.

This amount would have been sufficient for the FBR to have upgraded much of its information security infrastructure which may have prevented the recent incident.

The threat landscape is always evolving at a faster pace as compared to organisations trying to protect themselves. Therefore, this initial procurement may protect the FBR for the immediate and medium future. However, a continued investment must be put in place to protect and allow the FBR to evolve into a data-driven digital organisation, he added.

Published in Dawn, October 1st, 2021

Opinion

Editorial

Hasty transition
Updated 05 May, 2024

Hasty transition

Ostensibly, the aim is to exert greater control over social media and to gain more power to crack down on activists, dissidents and journalists.
One small step…
05 May, 2024

One small step…

THERE is some good news for the nation from the heavens above. On Friday, Pakistan managed to dispatch a lunar...
Not out of the woods
05 May, 2024

Not out of the woods

PAKISTAN’S economic vitals might be showing some signs of improvement, but the country is not yet out of danger....
Rigging claims
Updated 04 May, 2024

Rigging claims

The PTI’s allegations are not new; most elections in Pakistan have been controversial, and it is almost a given that results will be challenged by the losing side.
Gaza’s wasteland
04 May, 2024

Gaza’s wasteland

SINCE the start of hostilities on Oct 7, Israel has put in ceaseless efforts to depopulate Gaza, and make the Strip...
Housing scams
04 May, 2024

Housing scams

THE story of illegal housing schemes in Punjab is the story of greed, corruption and plunder. Major players in these...