Cyberattack triggers parking platform rebuild


By CY LEE
A Petaling Jaya City Council enforcement officer using a mobile device to check a vehicle’s parking status. The cyberattack on Flexi Parking caused its outage nationwide from June 29 to July 2.

Enhanced safeguards introduced following disruption to services across multiple local councils

A CYBERATTACK on June 29 halted parking payments, compound settlements and enforcement functions on the Flexi Parking platform, affecting public-sector and privately operated sites from Peninsular Malaysia to Sabah.

Instead of restoring services on the compromised network, Flexi Parking developer Leading Innovative Technologies & Systems Sdn Bhd (LITS) opted to rebuild its entire system.

ALSO READ: Compensation in spotlight after parking system outage

LITS chief executive officer Lai Thiam Sin said the company could have cleaned the affected servers and restored services within hours.

“However, we did not know what the intruder knew, and decided it was safer to shut everything down and rebuild,” he told StarMetro.

Lai showing the Flexi parking app operating as normal, with real-time parking information displayed on LITS’ operations dashboard behind him at the company’s headquarters in Shah Alam.
Lai showing the Flexi parking app operating as normal, with real-time parking information displayed on LITS’ operations dashboard behind him at the company’s headquarters in Shah Alam.

LITS built new virtual servers, migrated its code, reconstructed the supporting network, moved operations to a new virtual private network (VPN) and reset passwords and security keys.

“We did not want them to know where the rest of the servers were, so we shut everything down and moved to a new VPN,” Lai explained.

ALSO READ: ‘Need for sustained defences to battle threats’

“The compromised servers were isolated, decommissioned and imaged for forensic examination,” he said.

CyberSecurity Malaysia (CSM) was carrying out a post-mortem on the incident, he added.

When contacted, a CSM spokesperson declined to comment on matters concerning the LITS Flexi Parking cyber incident as it fell within the company’s purview.

What transpired

Lai said the breach occurred while LITS was migrating ageing virtual servers and software to newer cloud infrastructure on June 28.

He said some folder permissions were inadvertently left open during the time.

He likened the migration to moving house and leaving the gate open.

The attacker gained access to a legacy server at about 9am the following day, he said.

“During migration, you open up a lot of things. That is where the intruders came in.

“We left our credentials inside the servers to transfer files. Some older codes were removed and we were attacked through those codes,” said Lai.

A security key left on the server for file transfers had probably enabled the intrusion, he said, although access was confined to that machine.

“Once we disconnected it from the rest of the network, the attacker could not reach the other servers,” he added.

The attackers used backend administrative tools to send unauthorised app notifications and deface a local council enforcement page, said Lai.

CLICK TO ENLARGE
CLICK TO ENLARGE

Initially believing it to be a website defacement, LITS removed unfamiliar files from its servers.

However, monitoring alerts later showed databases were being deleted.

“Our monitoring bots alerted us that databases were disappearing.

“We immediately shut everything down to stop it from spreading.

“Our priority was to protect users’ information and the other servers,” Lai said.

He said preliminary checks on database logs found no evidence that attackers had viewed or downloaded users’ data.

“The logs showed they were trying to delete databases and tables rather than download them,” he said.

Lai said the findings remained preliminary, pending CSM’s post-mortem.

He also disputed the attacker’s claim of accessing data belonging to seven million users.

LITS has 5.7 million registered users across Flexi Parking, Smart Selangor Parking and Sabah Smart Parking.

Lai said the figure cited by the attacker likely came from a login table containing about 6.5 million to 6.7 million entries because users appeared multiple times if they were using the apps in different local council jurisdictions.

The table contained login timestamps and user identification numbers, but not names, email addresses, identity card numbers or passwords, he added.

Lai said a screenshot shared by the attacker appeared to show root access to an older server.

Beefing up security

Following the incident, LITS changed its migration and backup procedures, so backup systems now retrieve data from cloud servers instead of relying on credentials stored on them.

The company has also strengthened

server monitoring, enhanced detection of suspicious Internet protocol addresses and unusual server activity.

LITS has also reviewed its login systems, coding practices, backup procedures, software deployment processes and legacy files, Lai said.

“Penetration testing was done before the rebuilt platform was brought back online.

“When we started building Flexi Parking and expanded council by council, some older codes remained,” he said.

Flexi Parking platform and application suffered a 61-hour disruption following a cyberattack on June 29.
Flexi Parking platform and application suffered a 61-hour disruption following a cyberattack on June 29.

The company also plans to brief local authorities’ information technology personnel on lessons from the attack

and security measures that could strengthen connected systems.

“There are many lessons from this incident.

“Some of the security measures we introduced could also benefit the local councils,” Lai said.

Shah Alam City Council (MBSA), in a statement responding to StarMetro’s questions, said it took note of LITS’ explanation concerning the recovery and security improvements introduced after the outage.

MBSA said it would continue monitoring the measures and ensure the service provider complied with security requirements and contractual terms.

StarMetro also contacted Subang Jaya City Council and Kajang Municipal Council for comments on revenue losses, compounds issued during the outage and possible compensation from LITS, but both had yet to respond at press time.

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Next In Metro News

Illegal traders at strata developments get reprieve
Low-cost housing schemes need professional property management to address issues
PJ property owners urged to go digital for assessment payments
Don’t let Johor become scam hub
3km walkways planned for four Shah Alam LRT hubs by end of December
MyAduan Johor set for year-end launch
Training company marks 30 years by providing AI course to 116 youths�
‘Need for sustained defences to battle threats’
Compensation in spotlight after parking system outage
Keeping the kopitiam culture alive

Others Also Read