US investigators say SolarWinds hack is ‘likely Russian in origin’
Full article586 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The investigators said the hacking operation was intelligence-focused, and found fewer than 10 government agencies have been compromised.
U.S. government agencies investigating a sophisticated espionage operation that uses tampered software made by SolarWinds said for the first time Tuesday that the hacking is “likely Russian in origin,” calling it “a serious compromise that will require a sustained and dedicated effort to remediate.”
The statement from multiple federal agencies — one of the most detailed official comments yet from investigators — also indicated that the espionage operation was targeted. While the malicious software update went to some 18,000 government and private-sector customers, U.S. officials said “a much smaller number have been compromised by follow-on activity on their systems.” That includes “fewer than” 10 U.S. government agencies, said the statement from the FBI, the Cybersecurity and Infrastructure Security Agency, Office of the Director of National Intelligence and the National Security Agency.
The alleged Russian hacking operation has roiled Washington, prompting investigations on Capitol Hill and federal cybersecurity officials to work over the holidays to determine the scope of the breach. The apparent espionage campaign is likely to be a big early test for cybersecurity policy in the presidency of Joe Biden, who has vowed a response. “Cyberattacks must be treated as a serious threat by our leadership at the highest level,” Biden said in December.
A handful of U.S. officials, including Secretary of State Mike Pompeo, had previously suggested Russia could be involved in the hack, but the interagency group investigating the incident had yet to do so. President Donald Trump has baselessly suggested China might be involved.
Russia has denied involvement in the SolarWinds hacking operation.
Russia-linked hackers’ history of alleged destructive behavior in cyberspace, including cyberattacks that cut power in Ukraine, had prompted some concerns about the intent of SolarWinds operation. The software is widely used in industrial organizations. However, U.S. investigators said Tuesday that the hacking “was, and continues to be, an intelligence gathering effort.”
The attackers behind the SolarWinds campaign have also challenged the defenses of America’s biggest tech and cybersecurity firms. The attackers were able to view Microsoft’s source code, and they stole the security tools that FireEye uses to test its clients’ defenses.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/solarwinds-fbi-dhs-russia-biden-trump/