HomeYoutubeWhy is the hacking attack on the US government worrying experts?

Why is the hacking attack on the US government worrying experts?

The US government is grappling with breaches at top federal agencies, following a hacking campaign that appears to be behind Russia.

Investigators are trying to determine the extent to which the government has been affected by the security incident, as well as the damage that has been caused.

Why is the hacking attack on the US government worrying experts?

It is worth noting that cybersecurity experts are expressing their strong concern about hacking into the US government, with some even describing it as a wake-up call.


On December 13, the Commerce Department discovered it had been hit by a data breach, after Reuters first reported that hackers breached the service through third-party software vendor SolarWinds.

New details about the hacking attack, proving that the scale of the breach is much larger than initially estimated. As many as 18,000 SolarWinds customers – out of 300,000 – may be using software containing the vulnerability that allowed the attackers to infiltrate the Commerce Department.

Solawinds

The massive hacking attack on the US government revealed this week has security experts worried about who was targeted, and who is behind it.

One reason the attack is so concerning is who might have been targeted by the espionage campaign. At least two U.S. agencies have confirmed they were compromised so far: the Department of Commerce and the Department of Agriculture. The Department of Homeland Security's cybersecurity division was also compromised.

Why is the hacking attack on the US government worrying experts?

However, the actual number of victims is estimated to be much higher, raising concerns that the U.S. military, the White House, or public health agencies responding to the COVID-19 may have also been targeted. The Justice Department, the National Security Agency, and the U.S. Postal Service have also been cited by security experts as possible victims.

All federal civilian agencies have been ordered to review their systems in an emergency directive from DHS officials.

Among the victims of the attack is cybersecurity firm FireEye, which said companies across the broader economy were also vulnerable to espionage. The software vulnerability that allowed the espionage has been found in the technology and telecommunications industries, as well as consulting firms and energy companies, according to FireEye.

Security experts say this is just the beginning. In the coming days, we may learn that many more companies and services have been breached than have been reported so far, and it remains unknown what information may have been lost or stolen.

Why is the hacking attack on the US government worrying experts?

Another reason for concern is that the attackers appear to have been highly skilled and determined. The possibility that agents of a foreign government may be responsible for the breaches is a worrying sign not only of the attackers’ capabilities, but also of their motivations. These cybercriminals chose each of their victims for a specific purpose that remains unknown.

A third cause for concern is the unusual and creative way in which the attackers conducted their business: the initial attack took the form of legitimate software updates issued by SolarWinds. By enabling otherwise trusted software updates, the attackers cleverly exploited normal and recommended best practices for software updates. Thousands of companies and government agencies could have been exposed simply for doing the right thing.

Why is the hacking attack on the US government worrying experts?

Once they reached a target, attackers would wait patiently until they had collected enough data about authorized users to spoof them, which would allow hackers to move around a victim's network for months without being detected.

The extent of access the hackers gained, as well as the length of time they were able to gather information, could make this a “far worse cyberattack than the Office of Personnel Management breach” that the U.S. government disclosed in 2015, said Jamie Barnett, a retired admiral and senior vice president of cybersecurity firm RigNet. That breach, attributed to Chinese hackers, resulted in the theft of vast amounts of personal data from millions of federal employees and security clearance applicants.

The increasing frequency and intensity of state-sponsored hacking activity has led cybersecurity leaders to call for a global cyber treaty. For example, MicrosoftBrad Smith said at an event hosted by the Ronald Reagan Foundation and Institute on Tuesday: “We need a set of binding rules. The world’s democracies must ensure that their citizens are not at risk from cyberattacks.”

Many experts also express concern about the increasing dependence of many businesses on third-party suppliers, pointing out that society may be making it too easy to access or share data, especially in the context of the pandemic, when a large percentage of people are resorting to remote work.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS