Showing posts with label cyberattack. Show all posts
Showing posts with label cyberattack. Show all posts

Monday, May 27, 2019

CYBERATTACK - American Towns

"American towns under cyberattack from an NSA-built software" PBS NewsHour 5/26/2019

Excerpt

SUMMARY:  Over the last few weeks, the city of Baltimore essentially went offline after a cyberattack was followed by a ransom demand which the city refused to pay.  According to the New York Times, ‘EternalBlue,’ the software that wreaked havoc in Baltimore and other cities, was actually created by the National Security Agency.  New York Times reporter Scott Shane joins Hari Sreenivasan for more.

Monday, April 02, 2018

CYBER SECURITY - Ransomware

"Why ransomware attacks target local governments like Atlanta" PBS NewsHour 3/30/2018

Excerpt

SUMMARY:  Nine days ago, a cyberattack brought Atlanta [Georgia] to a virtual standstill.  Now the city says it is slowly making progress restoring its computer network.  Officials have not said whether they paid a $51,000 ransom to a group known as SamSam, which is thought to be behind the hack.  Hari Sreenivasan learns more from Allan Liska of the security firm Recorded Future.

Monday, December 19, 2016

OPINION - Shields and Ponnuru 12/16/2016

"Shields and Ponnuru on the ‘dark cloud' of Russian cyberattacks" PBS NewsHour 12/16/2016

Excerpt

SUMMARY:  Reports emerged this week that the CIA is confident Russia attempted to sway election results through cyberattacks.  Syndicated columnist Mark Shields and Ramesh Ponnuru of the The National Review join Judy Woodruff to discuss what Russia's interference suggests about the future of our democracy, the president-elect's Cabinet picks of Rex Tillerson and Rick Perry and President Obama's legacy on Syria.

JUDY WOODRUFF (NewsHour):  And now to the analysis of Shields and Ponnuru.  That's syndicated columnist Mark Shields and Ramesh Ponnuru of The National Review.  David Brooks is away.

Welcome to both of you.

Let's start out, Mark, by talking about this back and forth.  Every day, there's a new piece of information about it did between what Donald Trump is saying about whether the Russians were involved in this hacking of the Democratic National Committee and what the CIA and now the FBI, President Obama weighed in today on this.  What are we to make of all this?

MARK SHIELDS, syndicated columnist:  I think what we're to make of it is, to me what's fascinating is not what Donald Trump is in no particular position to know, but what's most alarming to me is Donald Trump will become President of the United States, he won the election.  This is not about who won the election.  He will become the 45th President the 20th of January.

It is about whether the sovereignty and self-determination of the United States was compromised by an organized at the highest Russian levels, which means the imprimatur of Mr. Putin, espionage, sabotage of the American democratic system.  And there is an office in this country that's higher than that of President and it's [a] 'patriot,' and John McCain is filling that right now, and John McCain is saying, these are questions that must be answered, that these are questions that demand an answer.

And the idea, as Mitch McConnell, the Republican Senate Majority Leader, says, sending it to the Intelligence Committee is a way of sending it to limbo because we had — we spent $40 million in five years in the Intelligence Committee investigating torture at Abu Ghraib, we have yet to get a report about it.  That's a nice way of saying, oh, it's national security, we can' t talk about it.  We will not get a 9/11 Commission.  But I think John McCain and the Armed Services Committee with Jack Reed, the Democrat, with Lindsey Graham and others, and Tim Kaine in a pretty damn good committee, I think you will get an honest hearing and we need it.

The idea people are so concerned about a $500,000 contribution to the Clinton Foundation changing and influencing American policy somehow indirectly, and incurious about Russia's involvement and sabotaging an American election is unforgivable to me and irrational.

JUDY WOODRUFF:  Ramesh, do you think this will be investigated thoroughly?

RAMESH PONNURU, The National Review:  I think this controversy is expanding in all directions.  You're going to have an investigation.  You're going to have a report from the administration.

During the a press conference, President Obama said there would be a report tying loose ends, tying it all together before he leaves office.  And then you're going to have the hearings over the configuration of Trump Secretary of State nominee, Rex Tillerson, where I believe the number one topic and probably number two topic as well is going to be the administration's intentions toward Russia.

Trump is going to be our third President in a row coming into office wanting friendly relations with Russia.  But, of course, this incredible backdrop now is going to color everything.

Tuesday, August 30, 2016

ELECTION THREAT - Russian Hack of Voting System

"FBI WARNS OF ELECTION HACK" by Ellen Nakashima, San Diego Union-Tribune 8/30/2016

NOTE: This is from the online edition of the newspaper, therefore no article link.

Agency alerted Arizona officials that Russians were behind assault on state’s voting system

The FBI is investigating a series of suspected foreign hacks of state election computer systems and websites, and has warned states to be on the alert for potential intrusions.

Hackers have targeted voter registration systems in Illinois and Arizona, and the FBI alerted Arizona officials in June that Russians were behind the assault on the system in that state.

The bureau described the threat as “credible” and significant, “an eight on a scale of one to 10,” Matt Roberts, a spokesman for Arizona Secretary of State Michele Reagan, said Monday.  As a result, Reagan shut down the state’s voter registration system for nearly a week.

It turned out that the hackers had not compromised the state system or even any county system.  They had, however, stolen the user name and password of a single elections official in Gila County.

Roberts said FBI investigators did not specify whether the hackers were criminals or employed by the Russian government.  Bureau officials on Monday declined to comment.

The Arizona incident is the latest indication of Russian interest in U.S. elections and party operations, and follows the discovery of a high profile penetration into Democratic National Committee computers.  That hack produced embarrassing emails that led to the resignation of DNC Chairwoman Debbie Wasserman Schultz and sowed dissension on the eve of Hillary Clinton’s nomination as the party’s presidential candidate.

The Russian campaign is also sparking intense anxiety about the security of this year’s elections.  Earlier this month, the FBI warned state officials to be on the lookout for intrusions into their elections systems.  The “flash” alert, which was first reported by Yahoo News, said investigators had detected attempts to penetrate election systems in several states and listed internet protocol addresses and other technical fingerprints associated with the hacks.  In addition to Arizona, Illinois officials discovered an intrusion into their elections system in July.  Although the hackers did not alter any data, the intrusion marks the first successful compromise of a state voter registration database, federal officials said.

“This was a highly sophisticated attack most likely from a foreign (international) entity,” said Kyle Thomas, director of voting and registration systems for the Illinois State Board of Elections, in a message that was sent to all election authorities in the state.

The Illinois hackers were able to retrieve voter records, but the number accessed was “a fairly small percentage of the total,” said Ken Menzel, general counsel for the Illinois elections board.

State officials alerted the FBI, he said, and the Department of Homeland Security also was involved.  The intrusion in Illinois led to a week-long shutdown of the voter registration system.

The FBI has told Illinois officials that it is looking at foreign government agencies and criminal hackers as potential culprits, Menzel said.

At least two other states are looking into possible breaches, officials said.  Meanwhile, states across the nation are scrambling to ensure that their systems are secure.

Until now, countries such as Russia and China have shown little interest in voting systems in the United States.  But experts said that if a foreign government gained the ability to tamper with voter data — for instance by deleting registration records — such a hack could cast doubt on the legitimacy of U.S. elections.

“I’m less concerned about the attackers getting access to and downloading the information.  I’m more concerned about the information being altered, modified or deleted.  That’s where the real potential is for any sort of meddling in the election,” said Brian Kalkin, vice president of operations for the Center for Internet Security, which operates the MS-ISAC, a multistate information-sharing center that helps government agencies combat cyberthreats and works closely with federal law enforcement.

Nonetheless, the Senate minority leader, Harry Reid of Nevada, asked the FBI Monday to investigate evidence suggesting that Russia may try to manipulate voting results.  In a letter to FBI Director James Comey, Reid wrote that the threat of Russian interference “is more extensive than is widely known and may include the intent to falsify official election results.” Recent classified briefings from senior intelligence officials, Reid said, have left him fearful that President Vladimir Putin’s “goal is tampering with this election.”

Reid argued that the connections between some of Donald Trump’s former and current advisers and the Russian leadership should, by itself, prompt an investigation.  He referred indirectly in his letter to a speech given in Russia by one Trump adviser, Carter Page, a consultant and investor in the energy giant Gazprom, who criticized U.S.  sanctions policy toward Russia.

“Trump and his people keep saying the election is rigged,” Reid said.  “Why is he saying that?  Because people are telling him the election can be messed with.”  Trump’s advisers say they are concerned that unnamed elites could rig the election for Clinton.  Reid argued that if Russia concentrated on “less than six” swing states, it could alter results and undermine confidence in the electoral system.  That would pose challenges, given that most states have paper backups, but he noted that hackers could keep people from voting by tampering with the rolls of eligible voters.

James Clapper, the director of national intelligence, has told Congress that manipulation or deletion of data is the next big cyberthreat — “the next push on the envelope.”  Tom Hicks, chairman of the federal Election Assistance Commission, an agency set up by Congress after the 2000 Florida recount to maintain election integrity, said he is confident that states have sufficient safeguards in place to ward off attempts to manipulate data.  For example, if a voter’s name were deleted and did not show up on the precinct list, the individual could still cast a provisional ballot, Hicks said.  Once the voter’s status was confirmed, the ballot would be counted.

Hicks also said the actual systems used to cast votes “are not hooked up to the internet” and so “there’s not going to be any manipulation of data.”  However, more than 30 states have some provisions for online voting, primarily for voters living overseas or serving in the military.

This spring, a DHS official cautioned that online voting is not yet secure.

“We believe that online voting, especially online voting in large scale, introduces great risk into the election system by threatening voters’ expectations of confidentiality, accountability and security of their votes and provides an avenue for malicious actors to manipulate the voting results,” said Neil Jenkins, an official in the department’s Office of Cybersecurity and Communications.

Private-sector researchers are also concerned about potential meddling by Russians in the U.S. elections system.  Rich Barger, chief information officer at ThreatConnect, said that several of the IP addresses listed in the FBI alert trace back to a website-hosting service called King Servers that offers Russia-based technical support.  Barger also said that one of the methods used was similar to a tactic employed in other intrusions suspected of being carried out by the Russian government, including one this month on the World Anti-Doping Agency.

“The very fact that (someone) has rattled the doorknobs, the very fact that the state election commissions are in the cross hairs, gives grounds to the average American voter to wonder: Can they really trust the results?” Barger said.

Nakashima writes for The Washington Post.  The New York Times contributed to this report.

Monday, November 24, 2014

CYBER ATTACKS - Outdated Internet Browsers

"Your outdated Internet browser is a gateway for cyber attacks" PBS NewsHour 11/18/2014

Excerpt

JUDY WOODRUFF (NewsHour):  Major U.S. government agencies have been the target of cyber-attacks of late.  The State Department is the latest.  During the past week, officials had to temporarily shut down an unclassified e-mail system after a suspected hacking.  In recent months, the White House, the Postal Service and the National Weather Service all have been targeted.

Meanwhile, as the holiday season approaches, retailers and the business world are on the lookout for breaches.

A new book breaks down the pervasiveness of what’s happening.

Jeffrey Brown has our conversation.

JEFFREY BROWN (NewsHour):  Hardly a week goes by anymore without a report of some major cyber-breach, whether it’s targeting retailers, the government, or any and all of us.  The attacks are generated in a new netherworld of crime, some of it individualized, even chaotic, other parts of it extremely well-organized.

Writer and journalist Brian Krebs has uncovered some major breaches, including the one on Target that compromised the credit card data of tens of millions of people.  He writes about all of this on his blog Krebs on Security and now in his new book, “Spam Nation.”

And welcome to you.

BRIAN KREBS, Author, “Spam Nation”:  Thank you.

JEFFREY BROWN:  You are peering a world of cyber-crime that few of us ever see.  What does it look like?

BRIAN KREBS:  It’s a pretty dark place.

JEFFREY BROWN:  It is?

BRIAN KREBS:  Yes, absolutely.

But it’s not as dark as you might imagine.  If you’re somebody who doesn’t know their way around, there are plenty of people willing to show you the way.  They might take a cut of the action to help you do that, but it’s not as dark…

Monday, October 06, 2014

CYBER ATTACK - Major Assault on JPMorgan Chase

"Hackers’ Attack Cracked 10 Financial Firms in Major Assault" by Matthew Goldstein, Nicole Perlroth, and David E. Sanger; New York Times 11/3/2014

The huge cyberattack on JPMorgan Chase that touched more than 83 million households and businesses was one of the most serious computer intrusions into an American corporation.  But it could have been much worse.

Questions over who the hackers are and the approach of their attack concern government and industry officials.  Also troubling is that about nine other financial institutions — a number that has not been previously reported — were also infiltrated by the same group of overseas hackers, according to people briefed on the matter.  The hackers are thought to be operating from Russia and appear to have at least loose connections with officials of the Russian government, the people briefed on the matter said.

It is unclear whether the other intrusions, at banks and brokerage firms, were as deep as the one that JPMorgan disclosed on Thursday.  The identities of the other institutions could not be immediately learned.

The breadth of the attacks — and the lack of clarity about whether it was an effort to steal from accounts or to demonstrate that the hackers could penetrate even the best-protected American financial institutions — has left Washington intelligence officials and policy makers far more concerned than they have let on publicly.  Some American officials speculate that the breach was intended to send a message to Wall Street and the United States about the vulnerability of the digital network of one of the world’s most important banking institutions.

“It could be in retaliation for the sanctions” placed on Russia, one senior official briefed on the intelligence said.  “But it could be mixed motives — to steal if they can, or to sell whatever information they could glean.”

The JPMorgan hackers burrowed into the digital network of the bank and went down a path that gave them access to information about the names, addresses, phone numbers and email addresses of account holders.  They never made it into where the more critical financial information and personal information are stored.

The bank’s security team, which first discovered the attack in late July, managed to block the hackers before they could compromise the most sensitive information about tens of millions of JPMorgan customers, said several security experts and others briefed on the matter.  The attack was not completely halted until the middle of August and it was only in recent days that the bank began to tally its full extent.

American officials say they have been working with JPMorgan since the intrusion was detected, chiefly through the Treasury, the Secret Service and intelligence agencies that seek to find the source of the attacks.  But that is slow work and one official cautioned against leaping to conclusions about the identities or the motives of the attackers.

“We’ve been wrong before,” he said.

JPMorgan, the nation’s largest bank, has begun contacting customers and making clear that no money was taken from any accounts.  There has been no evidence of any fraudulent use of customer information.  Most of the household accounts belong to United States residents.  The hackers ended up with the addresses, email addresses and phone numbers of everyone who logged into JPMorgan’s websites and mobile applications in the recent past.

Still, the recent attacks on the financial firms raise the possibility that the banks may not be up to the job of defending themselves.  The attacks will also stoke questions about regulations governing when companies must inform regulators and their customers about a breach.

“It was a huge surprise that they were able to compromise a huge bank like JPMorgan,” said Al Pascual, a security analyst with Javelin Strategy and Research.  “It scared the pants off many people.”

Several financial regulators have warned that a coordinated attack on the banking system could set off another financial crisis.

On Friday, George Jepsen, the Connecticut attorney general, opened an investigation into the breach at JPMorgan, while Benjamin M. Lawsky, New York’s top financial regulator, began calling bank officials to warn them to take the threat more seriously.

“There needs to be far more urgency,” Mr. Lawsky said in an interview.

JPMorgan has also been working with law enforcement, including the F.B.I., since shortly after detecting the intrusion, which affected about 90 of the bank’s computer servers.  The bank said it believed that its systems were now secure and that the threat of the hackers’ returning was over.

“To date, we have not seen any unusual fraud activity related to this incident,” said Kristin Lemkau, a bank spokeswoman.  “We have identified and closed the known access paths.  We have no evidence that the attackers are still in our system.  We have apologized to our customers.”

But much remains unanswered about the intrusion, including just who the hackers are, which other financial institutions were hit and why the hackers went down a path inside JPMorgan’s computer system that contained troves of customer information, but not financial data.

The intrusion also highlights a possible gap in United States regulations.  Banks are not required to report data breaches and online intrusions unless the incident is deemed to have resulted in a financial loss to customers.  Breach notification laws differ by state, but most laws require only that companies disclose a breach if customer names were stolen in conjunction with other information like a credit card, Social Security number or driver’s license number.

In some states, companies can wait up to a month to inform customers of a breach.  Other state laws are more vague.

In California, for example, banks, companies and large organizations must inform the state attorney general’s office and consumers about a breach without unreasonable delay — a rule that some companies interpret liberally, officials say.  This year, Kamala Harris, the California attorney general, sued the Kaiser Foundation Health Plan, saying that it took more than a year for the foundation to disclose to some employees that their personal information may have been compromised.

For years, there have been attempts in Congress to force companies to inform customers more quickly when their information has been compromised, but recent bills have failed to muster enough support.  One bill, sponsored by Senator Edward J. Markey, Democrat of Massachusetts, would create a clearinghouse where companies could exchange information about attacks.

United States bank executives say privately that they already share intelligence informally about attacks, which are occurring frequently on their systems.

This summer, Treasury Secretary Jacob J. Lew called on Congress to pass legislation that he said would bolster the information sharing process.

“As it stands, our laws do not do enough to foster information sharing and defend the public from digital threats,” Mr. Lew said.

That the hackers were apparently able to move around JPMorgan’s computer system undetected for several weeks is perhaps the most troubling aspect of the recent breach, officials at other large banks say.

The hackers were able to attain high administrative privileges within JPMorgan’s network, rooting more than 90 servers and rummaging through customer databases with detailed information for 76 million households and seven million small-business online accounts.

As they looked around, according to one person with knowledge of the breach, the hackers gleaned some critical details of customers’ accounts.  With these, the hackers were able to determine whether the accounts fell within the private bank or in other business categories like mortgages.

Some people briefed on the results of the attack contend that it was only a matter of time before attackers could have gained access to customer funds and critical personal data.

Weeks into the attack, in mid-July, unusual behavior on the bank’s network was spotted, and the attackers were stopped before they had a chance to pull any customer data back to their servers abroad.

But they did make off with one file which has unnerved executives.  That file contained a list of every application and program deployed on standard JPMorgan computers that hackers can crosscheck with known, or new, vulnerabilities in each system in a search for a backdoor entry.

Swapping out those programs is costly and time-consuming, people say, because the bank would have to renegotiate licensing deals with technology suppliers and swap out programs and applications for hundreds of thousands of bank employees.

As one former employee explained:  “It’s as if they stole the schematics to the Capitol — they can’t just switch out every single door and window pane overnight.”

The attack came after a recent turnover within JPMorgan’s information security group.

A number of staff members followed Frank Bisignano, JPMorgan’s former co-chief operating officer, to First Data last year.  This year, First Data agreed to pay JPMorgan over accusations that by wooing other executives to the payment processor, Mr. Bisignano had violated the terms of his former employment contract.

By then, First Data had already hired JPMorgan’s chief information officer, Guy Chiarello; its cybersecurity czar, Anthony Belfiore; its head of compliance, Cindy Armine; and Tom Higgins, JPMorgan’s head of operation control.

Anish Bhimani, the bank’s chief information risk officer, remained.  Mr. Bhimani, who is well respected in the cybersecurity industry, is a co-author of a 1996 book on cybersecurity, “Internet Security for Business.”

Ms. Lemkau said the bank was pleased with its current cybersecurity personnel.  “This is the highest-quality team we have ever had,” she said.

Last December, JPMorgan hired Dana Deasy as chief information officer from BP. Greg Rattray, a former Air Force lieutenant colonel who specialized in cyberdefense was named the head of information security in June.

Challenges quickly followed.  That same month, hackers found a way into the bank’s systems.