Public Announcement
HIFRNM: The cyberattack that the Fund is dealing with is taking place immediately before the planned migration of the system infrastructure; the analyses by the expert teams show that there has been no leakage of data outside the Fund’s databases.
HIFRNM informs the public, in relation to the remarks from the audit report that were published during today by several media outlets, that the information released consists of remarks relating to 2021 and on which the Fund has been acting since last year.
The final report on the audit performed by the auditors of the State Audit Office, delivered on 23 January 2023, namely last month, indicates that “during 2022 a procedure was initiated for the public procurement of services for the rental of a private cloud for a primary and secondary data centre in the Fund and the migration of applications and data, by which the situation was expected to be overcome”.
The public procurement was announced on 30.09.2022, while the contract was concluded on 09.12.2022, whereby the selected company began work on 1 January 2023. According to the plan and specification, the first phase, namely the migration of the system infrastructure, was to be carried out during this week, when the attack in fact occurred, after which phase the migration of the application and data infrastructure would have begun.
The analysis by the expert technical teams established that during the cyberattack there was no leakage of data outside the Fund’s databases.
The technical teams are giving priority to restoring the salary payment system for health workers as quickly as possible, as well as other forms of payment, namely sick leave, maternity leave and reimbursements.
In the interest of transparent and precise information for the public, as soon as possible, and once more information is established, the Fund will inform the public in a timely manner.