NATIONAL NEWS

Hack Against US Is ‘Grave Threat,’ Cybersecurity Agency Says

Dec 17, 2020, 4:47 PM

The U.S. Treasury Building as seen from the Bank of America offices in Washington, DC. (Photo by Ch...

The U.S. Treasury Building as seen from the Bank of America offices in Washington, DC. (Photo by Chip Somodevilla/Getty Images)

(Photo by Chip Somodevilla/Getty Images)

WASHINGTON (AP) — Federal authorities expressed increased alarm Thursday about a long-undetected intrusion into U.S. and other computer systems around the globe that officials suspect was carried out by Russian hackers. The nation’s cybersecurity agency warned of a “grave” risk to government and private networks.

The hack compromised federal agencies and “critical infrastructure” in a sophisticated attack that was hard to detect and will be difficult to undo, the Cybersecurity and Infrastructure Security Agency said in an unusual warning message. The Department of Energy acknowledged it was among those that had been hacked.

The attack, if authorities can prove it was carried out by Russia as experts believe, creates a fresh foreign policy problem for President Donald Trump in his final days in office.

Trump, whose administration has been criticized for eliminating a White House cybersecurity adviser and downplaying Russian interference in the 2016 presidential election, has made no public statements about the breach.

President-elect Joe Biden, who will inherit the potentially difficult U.S.-Russia relationship, spoke up forcefully about the hack, declaring that he and Vice President-elect Kamala Harris “will make dealing with this breach a top priority from the moment we take office.”

“We need to disrupt and deter our adversaries from undertaking significant cyberattacks in the first place,” he said. “We will do that by, among other things, imposing substantial costs on those responsible for such malicious attacks, including in coordination with our allies and partners.”

“There’s a lot we don’t yet know, but what we do know is a matter of great concern,” he said. He thanked administration “public servants” who he said were “working around-the-clock to respond to this attack.”

CISA officials did not respond to questions and so it was unclear what the agency meant by a “grave threat” or by “critical infrastructure” possibly targeted in the attack that the agency previously said appeared to have begun last March. Homeland Security, the agency’s parent department, defines such infrastructure as any “vital” assets to the U.S. or its economy, a broad category that could include power plants and financial institutions.

The agency previously said the perpetrators had used network management software from Texas-based SolarWinds t o infiltrate computer networks. Its new alert said the attackers may have used other methods, as well.

Over the weekend, amid reports that the Treasury and Commerce departments were breached, CISA directed all civilian agencies of the federal government to remove SolarWinds from their servers. The cybersecurity agencies of Britain and Ireland issued similar alerts.

A U.S. official previously told The Associated Press that Russia-based hackers were suspected, but neither CISA nor the FBI has publicly said who is believed to be responsible. Asked whether Russia was behind the attack, the official said: “We believe so. We haven’t said that publicly yet because it isn’t 100% confirmed.”

Another U.S. official, speaking Thursday on condition of anonymity to discuss a matter that is under investigation, said the hack was severe and extremely damaging although the administration was not yet ready to publicly blame anyone for it.

“This is looking like it’s the worst hacking case in the history of America,” the official said. “They got into everything.”

At the Department of Energy, the initial investigation revealed that malware injected into its networks via a SolarWinds update has been found only on its business networks and has not affected national security operations, including the agency that manages the nation’s nuclear weapons stockpile, according to its statement. It said vulnerable software was disconnected from the DOE network to reduce any risk.

The intentions of the perpetrators appear to be espionage and gathering information rather than destruction, according to security experts and former government officials. If so, they are now remarkably well situated.

Thomas Bossert, a former Trump Homeland Security adviser, said in an opinion article in The New York Times that the U.S. should now act as if the Russian government had gained control of the networks it has penetrated. “The actual and perceived control of so many important networks could easily be used to undermine public and consumer trust in data, written communications and services,” he wrote.”

Members of Congress said they feared that taxpayers’ personal information could have been exposed because the IRS is part of Treasury, which used SolarWinds software.

Tom Kellermann, cybersecurity strategy chief of the software company VMware, said the hackers are now “omniscient to the operations” of federal agencies they’ve infiltrated “and there is viable concern that they might leverage destructive attacks within these agencies” in reaction to U.S. response.

Among the business sectors scrambling to protect their systems and assess potential theft of information are defense contractors, technology companies and providers of telecommunications and the electric grid.

A group led by CEOs in the electric power industry said it held a “situational awareness call” earlier this week to help electric companies and public power utilities identify whether the compromise posed a threat to their networks.

And dozens of smaller institutions that seemed to have little data of interest to foreign spies were nonetheless forced to respond to the hack.

The Helix Water District, which provides drinking water to the suburbs of San Diego, California, said it provided a patch to its SolarWinds software after it got an advisory the IT company sent out about the hack to about 33,000 customers Sunday.

“While we do utilize SolarWinds, we are not aware of any district impacts from the security breach,” said Michelle Curtis, a spokesperson for the water district.

_____

With contributions from Associated Press writers Matthew Lee in Washington, Matt O’Brien in Providence, Rhode Island and Frank Bajak in Boston.

KSL 5 TV Live

National News

FILE - The logo for Boeing appears on a screen above a trading post on the floor of the New York St...

Alex Veiga, The Associated Press

Boeing locks out its private firefighters around Seattle over pay dispute

Boeing has locked out its private force of firefighters who protect its aircraft-manufacturing plants in the Seattle area and brought in replacements after the latest round of negotiations with the firefighters' union failed to deliver an agreement on wages.

11 hours ago

An illustration depicts the far side of the moon, with Earth behind it. (NASA via CNN Newsource)...

Ashley Strickland, CNN

New mission could shed light on the secrets of the moon’s ‘hidden side’

Over the past few years, competing countries have turned the moon into a hotspot for activity not witnessed since the Apollo 17 astronauts departed from the lunar surface in 1972.

15 hours ago

Shug the zebra appears to be in good health after almost six days on the loose, according to local ...

Paradise Afshar, CNN

Escaped zebra captured after nearly a week on the lam

A zebra’s almost week-long Washingtonian adventure came to an end on Friday, when the animal was recaptured after escaping from a trailer on the highway, according to local authorities.

17 hours ago

An SUV is stranded in a ditch along a stretch of street flooding during a severe storm Thursday in ...

Mary Gilbert, CNN Meteorologist and Joe Sutton, CNN

Evacuations ordered, homes damaged in Texas as rivers surge to Hurricane Harvey levels. And more rain is on the way

Flooding is intensifying in Texas, where more rain is expected over the weekend in the wake of strong storms and downpours that swept away vehicles, damaged homes and triggered evacuations.

20 hours ago

ROHNERT PARK, CALIFORNIA - APRIL 17: In an aerial view, a sign is posted on the exterior of a Red L...

Nathaniel Meyersohn, CNN

What went wrong at Red Lobster

All you can eat shrimp, might be the downfall of the seafood restaurant chain that is considering bankruptcy.

2 days ago

The loose zebra that's in King County in Washington....

Gene Johnson, Associated Press

Zebra remains on the loose in Washington state as officials close trailheads

A zebra that escaped from a trailer east of Seattle last weekend remained on the lam Friday.

2 days ago

Sponsored Articles

Side view at diverse group of children sitting in row at school classroom and using laptops...

PC Laptops

5 Internet Safety Tips for Kids

Read these tips about internet safety for kids so that your children can use this tool for learning and discovery in positive ways.

Women hold card for scanning key card to access Photocopier Security system concept...

Les Olson

Why Printer Security Should Be Top of Mind for Your Business

Connected printers have vulnerable endpoints that are an easy target for cyber thieves. Protect your business with these tips.

Modern chandelier hanging from a white slanted ceiling with windows in the backgruond...

Lighting Design

Light Up Your Home With These Top Lighting Trends for 2024

Check out the latest lighting design trends for 2024 and tips on how you can incorporate them into your home.

Technician woman fixing hardware of desktop computer. Close up....

PC Laptops

Tips for Hassle-Free Computer Repairs

Experiencing a glitch in your computer can be frustrating, but with these tips you can have your computer repaired without the stress.

Close up of finger on keyboard button with number 11 logo...

PC Laptops

7 Reasons Why You Should Upgrade Your Laptop to Windows 11

Explore the benefits of upgrading to Windows 11 for a smoother, more secure, and feature-packed computing experience.

Stylish room interior with beautiful Christmas tree and decorative fireplace...

Lighting Design

Create a Festive Home with Our Easy-to-Follow Holiday Prep Guide

Get ready for festive celebrations! Discover expert tips to prepare your home for the holidays, creating a warm and welcoming atmosphere for unforgettable moments.

Hack Against US Is ‘Grave Threat,’ Cybersecurity Agency Says