World

US, allies point finger at China for Microsoft, global hacking spree

Relations between both countries further sour as Washington accuses Beijing of harbouring cybercriminals in government

Updated 2 years ago · Published on 20 Jul 2021 2:30PM

US, allies point finger at China for Microsoft, global hacking spree

WASHINGTON – The United States yesterday accused Beijing of carrying out a massive hack of Microsoft and charged four Chinese nationals as it rallied allies in rare joint condemnation of “malicious” cyber activity from China.

In comments likely to further strain worsening relations between Washington and Beijing, US Secretary of State Antony Blinken said that the March hack of Microsoft Exchange, a top email server for corporations around the world, is part of a “pattern of irresponsible, disruptive and destabilising behavior in cyberspace, which poses a major threat to our economic and national security”.

China’s State Security Ministry, or MSS, “has fostered an ecosystem of criminal contract hackers who carry out both state-sponsored activities and cybercrime for their own financial gain”, Blinken said in a statement.

In a simultaneous announcement, the US Department of Justice said four Chinese nationals have been charged with hacking the computers of dozens of companies, universities and government bodies in the US and abroad between 2011 and 2018.

Pointing to the indictment, Blinken said the US “will impose consequences on (Chinese) malicious cyber actors for their irresponsible behaviour in cyberspace.”

President Joe Biden told reporters the US will complete an investigation before taking any countermeasures and drew parallels with the murky but prolific cybercrime attributed by Western officials to Russia.

“The Chinese government, not unlike the Russian government, is not doing this themselves, but are protecting those who are doing it, and maybe even accommodating them being able to do it,” Biden told reporters.

Nato solidarity

Biden, like his predecessor Donald Trump, has ramped up pressure on China, seeing the rising Asian power’s increasingly assertive moves at home and abroad as the main long-term threat to the US.

In a step the Biden administration hailed as unprecedented, the US coordinated its statement yesterday with allies – the European Union, Britain, Australia, Canada, New Zealand, Japan and Nato.

“The cyberattack on Microsoft Exchange Server by Chinese state-backed groups was a reckless but familiar pattern of behaviour,” British Foreign Secretary Dominic Raab said.

Nato issued a statement condemning malicious cyber activity and offering “solidarity” over the Microsoft hacking without directly assigning blame, while noting that allies US, Britain and Canada found China to be responsible.

State Department spokesman Ned Price said it is the first time that Nato – the Western military alliance whose members include Hungary and Turkey, which have comparatively cordial relations with Beijing – has condemned cyber activity from China.

It comes weeks after Nato took up China at a summit attended by Biden.

“We know we’ll be stronger, we know we’ll be more effective when we act collectively,” Price said, saying the US is not ruling out further action.

Biden has promised a strategy driven by alliances to face Beijing, drawing a contrast with Trump’s predilection for harsh rhetoric.

Billions seen lost

Frank Cilluffo, director of Auburn University’s McCrary Institute for Cyber and Critical Infrastructure Security, praised the “breadth and depth of international cooperation” in clearly attributing responsibility to China.

“In addition to the indictments, we need to follow through to ensure there are consequences to induce changes in the Chinese government’s behaviour and hopefully move toward levelling the cyber playing field,” he said.

The Microsoft hack, which exploited flaws in the Microsoft Exchange service, affected at least 30,000 US organisations including local governments, as well as organisations worldwide.

“Responsible states do not indiscriminately compromise global network security nor knowingly harbour cybercriminals – let alone sponsor or collaborate with them,” Blinken said in his statement.

“These contract hackers cost governments and businesses billions of dollars in stolen intellectual property, ransom payments, and cybersecurity mitigation efforts, all while the MSS had them on its payroll.”

Accusations of cyberattacks against the US have recently focused on Russia, rather than China.

US officials say that many of the attacks originate in Russia, although they have debated to what extent there is state involvement. Russia denies responsibility.

This year has seen a slew of prominent ransomware strikes that have disrupted a major US pipeline, a meat processor, and the software firm Kaseya, which affected 1,500 businesses.

Last week, Washington offered US$10 million (RM42.25 million) for information about foreign online extortionists. – AFP, July 20, 2021

Related News

Business / 1w

US court orders J&J, Kenvue to pay US$45 million over death of baby powder user

Business / 1mth

Malaysia bids to become Southeast Asian digital hub in collaboration with Microsoft

World / 1mth

Not made in China: Australia eyes other big opportunities in Asia

World / 1mth

Navigating maritime anxieties between Australia and Asean

World / 2mth

Aid for Ukraine held hostage by US politics

Malaysia / 2mth

Govt to send Malaysians to study TVET in China - Ahmad Zahid

Spotlight

Malaysia

Chow wants to meet Guan Eng over ‘missed investment’ remarks

By Ian McIntyre

Malaysia

How will Sarawak's 'region' status benefit the poor, asks activist

By Stephen Then

Malaysia

Dr Mahathir's sons say they are not subject of MACC probe

Malaysia

Despite hikes, Penang water tariffs 'among lowest in country’

By Ian McIntyre

Malaysia

4-way fight for Kuala Kubu Baharu

By Noel Achariam

Malaysia

BN chief Zahid hopeful MCA will help campaign for KKB