World

Pompeo blames Russia for massive US cyberattack

40 customers hit by malware that allows attackers network access to govt systems, electric power grids

Updated 5 years ago · Published on 19 Dec 2020 5:00PM

Pompeo blames Russia for massive US cyberattack
US Secretary of State Mike Pompeo says the government can say 'pretty clearly' that Russians are behind the cyberattack. – December 19, 2020

WASHINGTON – Russia was "pretty clearly" behind a devastating cyberattack on several US government agencies that also hit targets worldwide, Secretary of State Mike Pompeo said.

Microsoft said late Thursday that it had notified more than 40 customers hit by the malware, which security experts say could allow attackers unfettered network access to key government systems and electric power grids and other utilities.

"There was a significant effort to use a piece of third-party software to essentially embed code inside of US government systems," Pompeo told The Mark Levin Show yesterday.

"This was a very significant effort, and I think it's the case that now we can say pretty clearly that it was the Russians that engaged in this activity."

Roughly 80% of the affected customers are located in the US, Microsoft president Brad Smith said in a blog post, with victims also found in Belgium, Britain, Canada, Israel, Mexico, Spain and the United Arab Emirates.

"It's certain that the number and location of victims will keep growing," Smith said, echoing concerns voiced this week by US officials on the serious threat from the attack.

"This is not 'espionage as usual', even in the digital age," Smith said.

"Instead, it represents an act of recklessness that created a serious technological vulnerability for the US and the world."

John Dickson of the security firm Denim Group said many private sector companies that could be vulnerable were scrambling to shore up security, even to the point of considering rebuilding servers and other equipment.

"Everyone is in damage assessment now because it's so big," Dickson said. 

"It's a severe body blow to confidence both in government and critical infrastructure."

The threat comes from a long-running attack that is believed to have injected malware into computer networks using enterprise management network software made by the Texas-based IT company SolarWinds, with the hallmarks of a nation-state attack.

James Lewis, vice-president at the Centre for Strategic and International Studies, said the attack may end up being the worst to hit the US, eclipsing the 2014 hack of US government personnel records in a suspected Chinese infiltration.

"The scale is daunting. We don't know what has been taken so that is one of the tasks for forensics," Lewis said.

"We also don't know what's been left behind. The normal practice is to leave something behind so they can get back in, in the future."

NSA warning 

The National Security Agency called for increased vigilance to prevent unauthorised access to key military and civilian systems.

Analysts have said the attacks pose threats to national security by infiltrating key government systems, while also creating risks for controls of key infrastructure systems, such as electric power grids and other utilities.

The US Cybersecurity and Infrastructure Security Agency (CISA) said government agencies, critical infrastructure entities, and private sector organisations had been targeted by what it called an "advanced persistent threat actor".

CISA did not identify who was behind the malware attack, but private security companies pointed a finger at hackers linked to the Russian government.

Pompeo had also suggested Moscow's involvement on Monday, saying the Russian government had made repeated attempts to breach US government networks.

President-elect Joe Biden expressed "great concern" over the computer breach while Republican Senator Mitt Romney blamed Russia and slammed what he called "inexcusable silence" from the White House.

Romney likened the cyberattack to a situation in which "Russian bombers have been repeatedly flying undetected over our entire country".

CISA said the computer intrusions began at least as early as March this year, and the actor behind them had "demonstrated patience, operational security and complex tradecraft".

"This threat poses a grave risk," CISA said Thursday, adding that it "expects that removing this threat actor from compromised environments will be highly complex and challenging for organisations".

Hackers reportedly installed malware on software used by the US Treasury Department and the Commerce Department, allowing them to view internal email traffic. 

The Department of Energy, which manages the country's nuclear arsenal, confirmed it had also been hit by the malware but had disconnected affected systems from its network.

"At this point, the investigation has found that the malware has been isolated to business networks only, and has not impacted the mission essential national security functions of the department, including the National Nuclear Security Administration," said agency spokesman Shaylyn Hynes.

SolarWinds said up to 18,000 customers, including government agencies and Fortune 500 companies, had downloaded compromised software updates, allowing hackers to spy on email exchanges.

Russia has denied involvement. – AFP, December 19, 2020

Related News

Malaysia / 6mth

SMEs most vulnerable to data breaches and hacking – expert

Opinion / 1y

The Trump dilemma and reclaiming balance: The urgent need for fair global trade

Malaysia / 2y

Beware of ‘wedding invites’ carrying malware, says Bukit Aman

Malaysia / 2y

Sanctions on 4 Malaysia-based companies still in place, says US official

Business / 2y

US court orders J&J, Kenvue to pay US$45 million over death of baby powder user

World / 2y

Aid for Ukraine held hostage by US politics

Spotlight

Malaysia

RM245m Penang Hill cable car project 32 per cent complete - CM

By Ian McIntyre

Malaysia

Six locals charged over alleged kidnapping of Singaporean couple in Johor

Malaysia

PM: No political, racial or religious shield for those found guilty in TH, Felda probes

Malaysia

Singapore security guard jailed 14 days, fined RM7,000 for insulting Islam

Health

Dengue cases soar 56% to 58,079 as nation records 55 deaths

Malaysia

NGOs urge BERSAMA to put Indian community agenda on political radar

By Alfian Z.M. Tahir

Health

MOH warns seniors against unproven hydrogen inhalers

Malaysia

Former Tabung Haji CEO remanded seven days as MACC RCI probe deepens

Malaysia

21 held in KLIA-Nilai crackdown on alleged online love scam syndicate

You may be interested

World

UAE suspends all trade with Iran after renewed missile fire, deepening Tehran’s isolation

World

Harry and Meghan reportedly set for extended return to Britain, six years after royal exit

World

China-Indonesia talks put South China Sea, defence and investment in focus

World

Singapore caregiver jailed nearly 10 years, caned eight strokes for torturing schoolchildren

World

Iran’s two-pronged strategy: The eradication of US forces in the Gulf and political defeat in Washington

World

South Korea estimates North Korea has up to 120 nuclear weapons

World

Fei-Fei Li warns US AI backlash could undermine global leadership and innovation

World

China expands Philippine sea presence as Japan-Philippines maritime ties deepen