• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechHackers

COVID-19 vaccine distribution effort targeted by hackers

By
Frank Bajak
Frank Bajak
and
Bloomberg
Bloomberg
Down Arrow Button Icon
By
Frank Bajak
Frank Bajak
and
Bloomberg
Bloomberg
Down Arrow Button Icon
December 3, 2020, 7:17 PM ET

IBM security researchers say they have detected a cyberespionage effort using targeted phishing emails to try to collect vital information on the World Health Organization’s initiative for distributing COVID-19 vaccine to developing countries.

The researchers said they could not be sure who was behind the campaign, which began in September, or if it was successful. But the precision targeting and careful efforts to leave no tracks bore “the potential hallmarks of nation-state tradecraft,” they said in a blog post Thursday.

The campaign’s targets, in countries including Germany, Italy, South Korea and Taiwan, are likely associated with the development of the “cold chain” needed to ensure coronavirus vaccines get the nonstop sterile refrigeration they need to be effective for the nearly 3 billion people who live where temperature-controlled storage is insufficient, IBM said.

“Think of it as the bloodline that will be supplying the most vital vaccines globally,” said Claire Zaboeva, an IBM analyst involved in the detection.

The U.S. Cybersecurity and Infrastructure Security Agency later issued an advisory encouraging Operation Warp Speed, the Trump administration’s vaccine program, and other organizations involved in vaccine storage and transport, to review IBM’s findings.

Whoever is behind the operation could be motivated by a desire to learn how the vaccines are best able to be shipped and stored — the entire refrigeration process — in order to copy it, said Nick Rossmann, the IBM team’s global threat intelligence lead. Or they might want to be able to undermine a vaccine’s legitimacy or launch a disruptive or destructive attack, he added.

In the ploy, executives with groups likely associated with the initiative known as Covax — created by the Gavi Vaccine Alliance, the World Health Organization and other U.N. agencies — were sent spoofed emails appearing to come from an executive of Haier Biomedical, a Chinese company considered the world’s main cold-chain supplier, the analyst said.

The phishing emails posed as requests for price quotations and bore malicious attachments that prompted recipients to enter credentials that could have been used to harvest sensitive information about partners vital to the vaccine-delivery platform.

Targets included the European Commission’s Directorate-General for Taxation and Customs Union and companies that make solar panels for powering portable vaccine refrigerators. Other targets were petrochemical companies, likely because they produce dry ice, which is used in the cold chain, Zaboeva said.

The EU agency has been busy revising new import and export regimes for coronavirus vaccines and would be a gold mine for hackers seeking stepping stones into partnering organizations, she said.

Covax has struggled to raise enough money to compete for vaccine contracts against the world’s wealthiest nations in the race to secure doses as fast as they can be produced. But the UN and Gavi have invested millions in cold-chain equipment across Africa and Asia. The investment, in the works well before the pandemic, was accelerated to prepare for an eventual global rollout of coronavirus vaccines.

Whoever was behind the phishing operation likely sought “advanced insight into the purchase and movement of a vaccine that can impact life and the global economy,” the blog post said. Coronavirus vaccines will be one of the world’s most sought-after products as they are distributed, so theft may also be a danger.

In the U.S., the FBI has been working with other federal agencies and private industry to protect vaccine development and delivery, Tonya Ugoretz, the agency’s deputy assistant director for cyber readiness and intelligence, said Thursday at the online Aspen Cyber Summit.

The aim is to ward off not just cyberthreats but also more traditional human-centric espionage by adversaries who may seek to steal intellectual property for financial gain, to benefit another country or to “undermine confidence in U.S. efforts to provide an effective vaccine,” she said.

On the same panel, Marene Allison, the chief information security officer (CISO) at Johnson & Johnson, said that while she was confident that major pharmaceutical companies like hers developing coronavirus vaccines have strong defenses in place against hackers, some third parties involved in the process may not.

There have been reports that Johnson & Johnson has been targeted by North Korean hackers, but Allison said that doesn’t mean the attempts have been successful.

“I and all CISOs in health care are seeing attempted penetrations by nation-state actors, not just North Korea, every single minute of every single day,” she said.

Last month, Microsoft said it had detected mostly unsuccessful attempts by state-backed Russian and North Korean hackers to steal data from leading pharmaceutical companies and vaccine researchers. It gave no information on how many succeeded or how serious those breaches were. Chinese state-backed hackers have also targeted vaccine makers, the U.S. government said in announcing criminal charges in July.

Microsoft said most of the targets — located in Canada, France, India, South Korea and the United States — were researching vaccines and COVID-19 treatments. It did not name the targets.

On Wednesday, Britain became the first to country to authorize a rigorously tested COVID-19 vaccine, the one developed by American drugmaker Pfizer and Germany’s BioNTech.

Other countries aren’t far behind: Regulators not only in the U.S. but in the European Union and Canada also are vetting the Pfizer vaccine along with a shot made by Moderna Inc. British and Canadian regulators are also considering a vaccine made by AstraZeneca and Oxford University.

The logistical challenges of distributing vaccines globally are huge. The Pfizer-BioNTech one must be stored and shipped at ultra-cold temperatures of around minus 70 degrees Celsius (minus 94 degrees Fahrenheit).

Unlike the Moderna and Pfizer COVID-19 vaccines, Johnson & Johnson’s requires refrigeration but does not need to be frozen.

About the Authors
By Frank Bajak
See full bioRight Arrow Button Icon
By Bloomberg
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
Fortune Secondary Logo
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

sarandos
CommentaryMedia
What Netflix’s acquisition of Ben Affleck’s AI filmmaking company really shows
By Lin CherryMarch 6, 2026
60 minutes ago
anthropic research chart
AIJobs
Anthropic just mapped out which jobs AI could potentially replace. A ‘Great Recession for white-collar workers’ is absolutely possible
By Jake AngeloMarch 6, 2026
1 hour ago
Stressed Gen Z pharmacy worker
SuccessCareers
Pharmacy, biology, and education are among the worst-paying college majors—the ‘AI proof’ subjects pay Gen Z less than $50K after graduation
By Emma BurleighMarch 6, 2026
2 hours ago
Zuckerberg walks away from the courthouse surrounded by people in suits.
LawMeta
‘That’s not what we’re trying to do’: Mark Zuckerberg rejects claims that Facebook and Instagram are addictive at New Mexico social media trial
By Morgan Lee and The Associated PressMarch 6, 2026
2 hours ago
AIEntrepreneurs
Shark Tank’s Kevin O’Leary says if he were 25 today, he’d chase these two booming opportunities in the world of AI
By Marco Quiroz-GutierrezMarch 6, 2026
2 hours ago
tim cook
Big TechApple
Apple goes down market in its ‘big week’ of product rollouts with iPhone model that’s $200 cheaper than the base
By Shawn Chen and The Associated PressMarch 6, 2026
3 hours ago

Most Popular

placeholder alt text
Success
Uber CEO says his ‘really demanding’ work culture includes expecting employees to answer his emails over the weekend: ‘Don’t come here if you want to coast’
By Emma BurleighMarch 4, 2026
2 days ago
placeholder alt text
Economy
Trump's loss of $1.7 trillion in tariff revenue will send the national debt to $58 trillion by 2036, think tank projects
By Nick LichtenbergMarch 5, 2026
1 day ago
placeholder alt text
AI
OpenAI investor Vinod Khosla predicts today’s 5-year-olds won’t ever need to get jobs thanks to AI
By Sasha RogelbergMarch 4, 2026
2 days ago
placeholder alt text
Politics
Meet Markwayne Mullin, the new multimillionaire head of DHS, who owns a cattle ranch in Oklahoma
By Jacqueline MunisMarch 5, 2026
19 hours ago
placeholder alt text
Health
Palantir and other tech companies are stocking offices with nicotine products to increase worker productivity
By Catherina GioinoMarch 4, 2026
2 days ago
placeholder alt text
Politics
House votes 219-212 to halt Trump's attacks on Iran. "Donald Trump is not a king," says top Dem on Foreign Affairs Committee
By The Associated Press, Mary Clare Jalonick, Lisa Mascaro and Stephen GrovesMarch 5, 2026
19 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.