NATIONAL NEWS

Tech Firms Say There’s Little Doubt Russia Behind Major Hack

Feb 23, 2021, 5:37 PM

SolarWinds CEO Sudhakar Ramakrishna attends a Senate Intelligence Committee hearing on Capitol Hill...

SolarWinds CEO Sudhakar Ramakrishna attends a Senate Intelligence Committee hearing on Capitol Hill on February 23, 2021 in Washington, DC. The hearing focused on the 2020 cyberattack that resulted in a series of major data breaches within several U.S. corporations and agencies and departments in the U.S. federal government. (Photo by Demetrius Freeman-Pool/Getty Images)

(Photo by Demetrius Freeman-Pool/Getty Images)

WASHINGTON (AP) — Leading technology companies said Tuesday that a months-long breach of corporate and government networks was so sophisticated, focused and labor-intensive that a nation had to be behind it, with all the evidence pointing to Russia.

In the first congressional hearing on the breach, representatives of technology companies involved in the response described a hack of almost breathtaking precision, ambition and scope. The perpetrators stealthily scooped up specific emails and documents on a target list from the U.S. and other countries.

“We haven’t seen this kind of sophistication matched with this kind of scale,” Microsoft President Brad Smith told the Senate Intelligence Committee.

Forensic investigators have estimated that at least 1,000 highly skilled engineers would have been required to develop the code that hijacked widely used network software from Texas-based SolarWinds to deploy malware around the world through a security update.

“We’ve seen substantial evidence that points to the Russian foreign intelligence agency and we have found no evidence that leads us anywhere else,” Smith said.

U.S. national security officials have also said Russia was likely responsible for the breach, and President Joe Biden’s administration is weighing punitive measures against Russia for the hack as well as other activities. Moscow has denied responsibility for the breach.

Officials have said the motive for the hack, which was discovered by private security company FireEye in December, appeared to be to gather intelligence. On what, they haven’t said.

At least nine government agencies and 100 private companies were breached, but what was taken has not been revealed.

White House press secretary Jen Psaki said Tuesday it would be “weeks not months” before the U.S. responds to Russia.

“We have asked the intelligence community to do further work to sharpen the attribution that the previous administration made about precisely how the hack occurred, what the extent of the damage is, and what the scope and scale of the intrusion is,” Psaki said. “And we’re still in the process of working that through now.”

FireEye CEO Kevin Mandia told the Senate that his company has had nearly 100 people working to study and contain the breach since they detected it, almost by accident, in December and alerted the U.S. government.

The hackers first quietly installed malicious code in October 2019 on targeted networks, but didn’t activate it to see if they could remain undetected. They returned in March and immediately began to steal the log-in credentials of people who were authorized to be on the network so they could have a “secret key” to move around at will, Mandia said.

Once detected “they vanished like ghosts,” he said.

“There’s no doubt in my mind that this was planned,” the security executive said. “The question really is where’s the next one, and when are we going to find it?”

Government agencies breached include the Treasury, Justice and Commerce departments, but the full list has not been publicly released. The president of Microsoft, which is working with FireEye on the response, said there are victims around the world, including in Canada, Mexico, Spain and the United Arab Emirates.

The panel, which also included Sudhakar Ramakrishna, the CEO of SolarWinds who took over the company after the hack occurred, and George Kurtz, the president and CEO of CrowdStrike, another leading security company, faced questions not just about how the breach occurred but also whether hacking victims need to be legally compelled to be forthcoming when they have been breached. Even now, three months after the breach was disclosed, the identity of most victims remains unknown.

Congress has considered in the past whether to require companies to report that they have been the victim of a hack, but it has triggered legal concerns, including whether they could be held liable by clients for the loss of data.

U.S. authorities are also considering whether to give additional resources and authority to the Cybersecurity and Infrastructure Agency or other agencies to be able to take a more forceful role in working to prevent future breaches.

Another measure that has been considered is to create a new agency, like the National Transportation Safety Board, that could quickly come in and evaluate a breach and determine whether there are problems that need to be fixed.

Sen. Ron Wyden, one of the most prominent voices on cyber issues in the Senate, warned that the U.S. must first make sure that government agencies breached in this incident have taken the required security measures.

“The impression that the American people might get from this hearing is that the hackers are such formidable adversaries that there was nothing that the American government or our biggest tech companies could have done to protect themselves,” said Wyden, an Oregon Democrat. “My view is that message leads to privacy-violating laws and billions of more taxpayer funds for cybersecurity.”

____

Associated Press writer Alan Suderman in Richmond, Virginia, contributed.

KSL 5 TV Live

National News

Donald Trump sits at a table a jury has been seated for his trial...

Jennifer Peltz, Michael R. Sisak, Jake Offenhartz and Alanna Durkin Richer

Jury of 12 people and 6 alternates is seated in Trump’s hush money trial in New York

A full jury of 12 people and six alternates has been seated Donald Trump's hush money case, setting the stage for expected opening statements next week in the first criminal trial of a former U.S. president.

2 hours ago

Maxwell Anderson, 33, has been charged with the killing and dismemberment of 19-year-old Sade Robin...

Zoe Sottile, Rebekah Riess and Eric Levenson

Additional human remains believed to be slain college student wash ashore on Lake Michigan

Additional human remains believed to be of a 19-year-old college student who went missing earlier following a first date washed ashore on a Lake Michigan beach in Wisconsin.

4 hours ago

FILE: Speaker of the House Mike Johnson (R-LA) speaks during a news conference following a closed-d...

Stephen Groves, Lisa Mascaro and Kevin Freking

Ukraine, Israel aid advances in rare House vote as Democrats help Republicans push it forward

The House has pushed a $95 billion national security aid package for Ukraine, Israel and other U.S. allies closer to passage.

4 hours ago

Nearly 4,000 of the new Tesla Cybertrucks are being recalled because the accelerator can become stu...

Chris Isidore and Peter Valdes-Dapena

Tesla recalls Cybertruck due to accelerator pedal that can stick

Tesla has been ordered to recall nearly 4,000 of its Cybertrucks due to an accelerator pedal that can stick in place when pressed down.

6 hours ago

LOS ANGELES, CALIFORNIA - FEBRUARY 04: Taylor Swift attends the 66th GRAMMY Awards at Crypto.com Ar...

Alli Rosenbloom and Elizabeth Wagmeister

Taylor Swift’s surprise double album ‘The Tortured Poets Department’ is daggers wrapped in a lullaby

Take your seat because Taylor Swift’s “Tortured Poets Department” meeting has officially been called into session and, surprise, it’s a 31-song mega double album.

8 hours ago

Zach Lemann, curator of animal collections for the Audubon Insectarium, prepares cicadas for eating...

Kevin McGill, Associated Press

Would you like a cicada salad? The monstrous little noisemakers descend on a New Orleans menu

They may look like little monsters. And their seemingly endless racket may be a nuisance. But as parts of the nation prepare for the emergence of trillions of noisy cicadas, bug experts say the little creatures can also be a tasty snack.

8 hours ago

Sponsored Articles

Women hold card for scanning key card to access Photocopier Security system concept...

Les Olson

Why Printer Security Should Be Top of Mind for Your Business

Connected printers have vulnerable endpoints that are an easy target for cyber thieves. Protect your business with these tips.

Modern chandelier hanging from a white slanted ceiling with windows in the backgruond...

Lighting Design

Light Up Your Home With These Top Lighting Trends for 2024

Check out the latest lighting design trends for 2024 and tips on how you can incorporate them into your home.

Technician woman fixing hardware of desktop computer. Close up....

PC Laptops

Tips for Hassle-Free Computer Repairs

Experiencing a glitch in your computer can be frustrating, but with these tips you can have your computer repaired without the stress.

Close up of finger on keyboard button with number 11 logo...

PC Laptops

7 Reasons Why You Should Upgrade Your Laptop to Windows 11

Explore the benefits of upgrading to Windows 11 for a smoother, more secure, and feature-packed computing experience.

Stylish room interior with beautiful Christmas tree and decorative fireplace...

Lighting Design

Create a Festive Home with Our Easy-to-Follow Holiday Prep Guide

Get ready for festive celebrations! Discover expert tips to prepare your home for the holidays, creating a warm and welcoming atmosphere for unforgettable moments.

Battery low message on mobile device screen. Internet and technology concept...

PC Laptops

9 Tips to Get More Power Out of Your Laptop Battery

Get more power out of your laptop battery and help it last longer by implementing some of these tips from our guide.

Tech Firms Say There’s Little Doubt Russia Behind Major Hack