IMF said 11 email accounts were compromised in a February 2024 breach
- Organization
- International Monetary Fund (IMF)
- Exploit
- Hacking
- Industry
- International Financial Institution
The International Monetary Fund disclosed on 15 March 2024 that it had been the target of a cyberattack detected on 16 February. The fund said an investigation carried out with the assistance of independent cybersecurity experts established that 11 IMF email accounts had been compromised.
The affected mailboxes were re-secured, and the fund said it had no indication of any further compromise beyond those accounts at that point. The investigation into how the intrusion happened was still under way when the statement was issued.
The IMF did not name a suspected attacker and declined to say what information the intruders may have reached, citing security considerations. None of the compromised accounts belonged to the fund's senior leadership, according to Reuters reporting cited by The Record.
The fund uses Microsoft 365 for email. Security Affairs reported that the IMF said the incident did not appear to be connected to the compromise of Microsoft corporate systems disclosed around the same period. The intrusion was the second significant cyber incident the IMF has publicly acknowledged, following a breach in 2011.