Sunday, March 31, 2013
After Cyberattack, Sven Olaf Kamphuis Is at Heart of Investigation
Sunday, March 24, 2013
Cyberattack Hits South Korean Banking Networks
Nicole Perlroth contributed reporting from San Francisco, and David E. Sanger from Washington.
Thursday, October 25, 2012
Cyberattack on Saudi Oil Firm Disquiets U.S.
Saturday, October 13, 2012
Panetta Warns of Dire Threat of Cyberattack on U.S.
Elisabeth Bumiller reported from New York, and Thom Shanker from Washington.
Thursday, October 4, 2012
Bits Blog: Google Warns of New State-Sponsored Cyberattack Targets
In June, many Google users were surprised to see an unusual greeting at the top of their Gmail inbox, Google home page or Chrome browser. “Warning: We believe state-sponsored attackers may be attempting to compromise your account or computer.”
On Tuesday, tens of thousands more Google users will begin to see that message. The company said that since it started alerting users to malicious — probably state-sponsored — activity on their computers in June, it has picked up thousands more instances of cyberattacks than it anticipated.
Mike Wiacek, a manager on Google’s information security team, said in an interview on Tuesday that since Google started to alert users to state-sponsored attacks three months ago, it had gathered new intelligence about attack methods and the groups deploying them. He said the company was using that information to warn “tens of thousands of new users” that they may have been targets, starting on Tuesday.
By Tuesday afternoon, several people — many of them American journalists and foreign policy experts — had already taken to Twitter to say they had seen the warning. Noah Schactman, the editor of Wired’s national security blog “Danger Room,” tweeted: “Aaaaand I just got Google’s ‘you may be a victim of a state-sponsored attack’ notice. #WhatTookYouSoLong?” Daveed Gartenstein-Ross, a senior fellow at the Foundation for Defense of Democracies, also reported getting the message. As did Joshua Foust, a fellow at the American Security Project, a nonprofit research organization, who has written extensively about Afghanistan.
Mr. Wiacek noted that Google had seen an increase in state-sponsored activity coming from the Middle East. He declined to call out particular countries, but he said the activity was coming from “a slew of different countries” in the region.
Those findings triangulate with recent discoveries by security researchers that Middle Eastern states, including Iran, Qatar, the United Arab Emirates and Bahrain, have used spyware to monitor citizens and activists overseas.
Last week, several American banks were hit with cyberattacks by hackers claiming Middle Eastern ties. Security researchers have said they have noticed an increase in cyberattacks originating in the region. “We absolutely have seen more activity from the Middle East, and in particular Iran has been increasingly active as they build up their cybercapabilities,” George Kurtz, the president of CrowdStrike, a computer security company, said in a recent interview.
Mr. Wiacek said there were several steps Google users, especially those who get its warning, could take to protect themselves, like changing their e-mail and account passwords, enabling Google’s two-step authentication service and running their computer software updates.
Wednesday, August 1, 2012
The Lede Blog: Iranian Scientist Claims U.S. Cyberattack Was ... Loud
The United States has a rather bizarre history of blasting rock music into the ears of presumed enemies, so it seemed plausible when a prominent security expert reported Monday that a new cyberattack on Iran’s atomic program included workstations erupting in booms of “Thunderstruck” by AC/DC, an Australian rock band.
In a blog post, Mikko Hypponen, the chief research officer of F-Secure, a computer security company based in Finland, cited “a series of e-mails” he had received from “a scientist working at the Atomic Energy Organization of Iran.” He admitted he was unable to confirm any details of the alleged attack but said the sender was using the correct e-mail address, aeoi.org.ir.
Mr. Hypponen quoted the scientist as saying the music hit “in the middle of the night with the volume maxed out.”
His report created a sensation as blogs and news reports around the globe repeated the claim. ForeignPolicy.com went further, noting on its blog that the United States had repeatedly blasted loud music at supposed foes.
For instance, it noted that American troops in 1989 had tried to force the Panamanian president, Manuel Noriega, from his refuge in the Vatican embassy by bombarding it with loud music. The blog told of military DJs taking requests and creating a playlist that included AC/DC’s “You Shook Me All Night Long.”
More recently, Foreign Policy said, the United States Psychological Operations Company “admitted to the use of heavy metal in Iraq as a mechanism to break uncooperative prisoners’ resistance.” And the International Committee of the Red Cross, it noted, had reported the use of similar tactics against Guantánamo inmates.
Alas, the Iranian episode seems too good to be true.
Specialists in cyberwarfare said the e-mails could have easily been faked, including the seeming return address from the Iranian atomic program. Simple logic, one expert noted, suggested that an Iranian scientist writing such a report to a foreigner might quickly join the ranks of the martyrs. Finally, the tone of the alleged e-mails from the Iranian scientist seemed suspicious in their self-congratulatory tone about the success of the computer attack and its heavy-metal explosion.
“I doubt it,” a senior administration official who closely follows the Iranian program said of the cyber claim.
Sunday, July 29, 2012
The Lede Blog: Iranian Scientist Claims U.S. Cyberattack Was ... Loud
The United States has a rather bizarre history of blasting rock music into the ears of presumed enemies, so it seemed plausible when a prominent security expert reported Monday that a new cyberattack on Iran’s atomic program included workstations erupting in booms of “Thunderstruck” by AC/DC, an Australian rock band.
In a blog post, Mikko Hypponen, the chief research officer of F-Secure, a computer security company based in Finland, cited “a series of e-mails” he had received from “a scientist working at the Atomic Energy Organization of Iran.” He admitted he was unable to confirm any details of the alleged attack but said the sender was using the correct e-mail address, aeoi.org.ir.
Mr. Hypponen quoted the scientist as saying the music hit “in the middle of the night with the volume maxed out.”
His report created a sensation as blogs and news reports around the globe repeated the claim. ForeignPolicy.com went further, noting on its blog that the United States had repeatedly blasted loud music at supposed foes.
For instance, it noted that American troops in 1989 had tried to force the Panamanian president, Manuel Noriega, from his refuge in the Vatican embassy by bombarding it with loud music. The blog told of military DJs taking requests and creating a playlist that included AC/DC’s “You Shook Me All Night Long.”
More recently, Foreign Policy said, the United States Psychological Operations Company “admitted to the use of heavy metal in Iraq as a mechanism to break uncooperative prisoners’ resistance.” And the International Committee of the Red Cross, it noted, had reported the use of similar tactics against Guantánamo inmates.
Alas, the Iranian episode seems too good to be true.
Specialists in cyberwarfare said the e-mails could have easily been faked, including the seeming return address from the Iranian atomic program. Simple logic, one expert noted, suggested that an Iranian scientist writing such a report to a foreigner might quickly join the ranks of the martyrs. Finally, the tone of the alleged e-mails from the Iranian scientist seemed suspicious in their self-congratulatory tone about the success of the computer attack and its heavy-metal explosion.
“I doubt it,” a senior administration official who closely follows the Iranian program said of the cyber claim.