Major cyber attacks strike worldwide

This image provided by the Twitter page of @fendifille shows a computer at Greater Preston CCG as Britain's National Health Service is investigating "an issue with IT" on Friday. (AP)
Updated 13 May 2017
Follow

Major cyber attacks strike worldwide

LONDON/MADRID: A global cyberattack leveraging hacking tools widely believed by researchers to have been developed by the US National Security Agency hit international shipper FedEx, disrupted Britain’s health system and infected computers in nearly 100 countries on Friday.
Cyber extortionists tricked victims into opening malicious malware attachments to spam e-mails that appeared to contain invoices, job offers, security warnings and other legitimate files.
The ransomware encrypted data on the computers, demanding payments of $300 to $600 to restore access. Security researchers said they observed some victims paying via the digital currency bitcoin, though they did not know what percent had given in to the extortionists.
Researchers with security software maker Avast said they had observed 57,000 infections in 99 countries with Russia, Ukraine and Taiwan the top targets.
The most disruptive attacks were reported in Britain, where hospitals and clinics were forced to turn away patients after losing access to computers.
International shipper FedEx Corp. said some of its Windows computers were also infected. “We are implementing remediation steps as quickly as possible,” it said in a statement.
Still, only a small number of US-headquartered organizations were hit because the hackers appear to have begun the campaign by targeting organizations in Europe, said Vikram Thakur, research manager with security software maker Symantec.
By the time they turned their attention to the United States, spam filters had identified the new threat and flagged the ransomware-laden e-mails as malicious, Thakur said.
The US Department of Homeland Security said late on Friday that it was aware of reports of the ransomware, was sharing information with domestic and foreign partners and was ready to lend technical support.
Telecommunications company Telefonica was among many targets in Spain, though it said the attack was limited to some computers on an internal network and had not affected clients or services. Portugal Telecom and Telefonica Argentina both said they were also targeted.
Private security firms identified the ransomware as a new variant of “WannaCry” that had the ability to automatically spread across large networks by exploiting a known bug in Microsoft’s Windows operating system.
“Once it gets in and starts moving across the infrastructure, there is no way to stop it,” said Adam Meyers, a researcher with cybersecurity firm CrowdStrike.
The hackers, who have not come forward to claim responsibility or otherwise been identified, likely made it a “worm,” or self spreading malware, by exploiting a piece of NSA code known as “Eternal Blue” that was released last month by a group known as the Shadow Brokers, researchers with several private cybersecurity firms said.
“This is one of the largest global ransomware attacks the cyber community has ever seen,” said Rich Barger, director of threat research with Splunk, one of the firms that linked WannaCry to the NSA.
The Shadow Brokers released Eternal Blue as part of a trove of hacking tools that they said belonged to the US spy agency.

Microsoft on Friday said it was pushing out automatic Windows updates to defend clients from WannaCry. It issued a patch on March 14 to protect them from Eternal Blue.
“Today our engineers added detection and protection against new malicious software known as Ransom:Win32.WannaCrypt,” Microsoft said in a statement. It said the company was working with its customers to provide additional assistance.
SENSITIVE TIMING
The spread of the ransomware capped a week of cyber turmoil in Europe that kicked off a week earlier when hackers posted a huge trove of campaign documents tied to French candidate Emmanuel Macron just 1-1/2 days before a run-off vote in which he was elected as the new president of France.
On Wednesday, hackers disputed the websites of several French media companies and aerospace giant Airbus.
Also, the hack happened four weeks before a British parliamentary election in which national security and the management of the state-run National Health Service (NHS) are important campaign themes.
Authorities in Britain have been braced for possible cyberattacks in the run-up to the vote, as happened during last year’s US election and on the eve of this month’s presidential vote in France.
But those attacks — blamed on Russia, which has repeatedly denied them — followed an entirely different modus operandi involving penetrating the accounts of individuals and political organizations and then releasing hacked material online.
On Friday, Russia’s interior and emergencies ministries, as well as the country’s biggest bank, Sberbank, said they were targeted. The interior ministry said on its website that around 1,000 computers had been infected but it had localized the virus.
The emergencies ministry told Russian news agencies it had repelled the cyberattacks while Sberbank said its cybersecurity systems had prevented viruses from entering its systems.

NEW BREED OF RANSOMWARE
Although cyber extortion cases have been rising for several years, they have to date affected small-to-mid sized organizations, disrupting services provided by hospitals, police departments, public transportation systems and utilities in the United States and Europe.
“Seeing a large telco like Telefonica get hit is going to get everybody worried. Now ransomware is affecting larger companies with more sophisticated security operations,” Chris Wysopal, chief technology officer with cybersecurity firm Veracode, said.
The news is also likely to embolden cyber extortionists when selecting targets, Chris Camacho, chief strategy officer with cyber intelligence firm Flashpoint, said.
“Now that the cyber criminals know they can hit the big guys, they will start to target big corporations. And some of them may not be well prepared for such attacks,” Camacho said.
In Spain, some big firms took pre-emptive steps to thwart ransomware attacks following a warning from Spain’s National Cryptology Center of “a massive ransomware attack.”
Iberdrola and Gas Natural, along with Vodafone’s unit in Spain, asked staff to turn off computers or cut off Internet access in case they had been compromised, representatives from the firms said.
In Spain, the attacks did not disrupt the provision of services or networks operations of the victims, the government said in a statement.
 


Epstein files reveal links to cash, women, power in Africa

Updated 26 February 2026
Follow

Epstein files reveal links to cash, women, power in Africa

  • Documents attest to Epstein’sclose ties with Karim Wade, son of former Senegalese president Abdoulaye Wade
  • They also reveal his ties to Nina Keita, niece of Ivorian president Alassane Ouattara

PARIS: Jeffrey Epstein built close ties with powerful figures in Senegal and Ivory Coast, files released by the US government last month show, detailing the late sex offender’s influence network across Africa.
Emails, scheduled meetings, investment projects, and loans reviewed by AFP attest to the disgraced New York financier’s close relationship with Karim Wade, son of former Senegalese president Abdoulaye Wade.
They also reveal his ties to Nina Keita, niece of Ivorian president Alassane Ouattara.
Wade and Epstein met in 2010 through Emirati businessman Sultan Ahmed bin Sulayem, who recently resigned as CEO of port giant DP World after mounting pressure over his close friendship with Epstein.
The pair quickly struck up a rapport.
“Thanks for coming. I think there are many things to consider... I feel confident that we will have fun,” Epstein wrote to Wade on November 15, 2010 after their first meeting in Paris.
“Have a safe trip back to your paradise Island,” Wade replied.
While Wade’s exchanges show no link to Epstein-related sex trafficking crimes, they do reveal conversations on potential business ventures in various sectors, such as finance and energy.
Nicknamed the “Minister of Heaven and Earth” for the multiple portfolios he held including international cooperation, energy, and air transport, Wade was a powerful figure in Senegal until April 2012, when his father’s bid for a third term sparked deadly riots.
Epstein saw him as “one of the most important players in africa” and invited him to meet close contacts such as Ehud Barak, then Israel’s defense minister.
He also put him in touch with Chinese businessman Desmond Shum to discuss “offshore banking.”
The US Department of Justice documents show Shum and Wade met in Beijing on May 9, 2011.
That same month, Wade planned an African tour through Senegal, Mali, and Gabon for Epstein.

‘You will not suffer’ 

Epstein and Wade’s relationship became even more apparent after the latter’s fortunes reversed when his father left office in 2012.
That autumn, Epstein proposed that his “friend” — under the Dakar authorities’ scrutiny over his assets — use his house in Florida.
“You and your family are welcome to use my house in palm beach, staff is there, pool etc. you will not suffer,” Epstein wrote.
“Txs a lot Brother for the advise,” Wade replied a few weeks later to another email, in which Epstein urged him to “stay mentally strong.”
Numerous files suggest Epstein became financially involved on Karim Wade’s behalf after his arrest in 2013 and his 2015 sentencing to six years in prison for corruption.
Karim Wade’s lawyer, Mohamed Seydou Diagne, sent two invoices in May 2014 and July 2015 of $500,000 to one of Epstein’s companies.
Contacted by AFP on Monday, Diagne said he “did not consider it useful to comment.”
Other archives suggest that Epstein covered at least $50,000 in fees for the US lobbying firm Nelson Mullins, hired by Wade’s entourage to secure his release.
Epstein regularly exchanged emails with Robert Crowe, a partner at the firm who kept him informed of their efforts in the US and Senegal.
In a June 16, 2016 email thread where Epstein and Crowe discussed whether then Senegalese president Macky Sall would pardon Wade, Crowe writes: “He has told my friends high up at State that he was going to do it. They have been putting pressure on him!“
Karim Wade was released from prison eight days later, on June 24, and went into exile in Qatar, which he credited for efforts toward his release.
Jeffrey Epstein was told by Sultan Ahmed bin Sulayem and Nina Keita.

‘A very interesting person!’

The DOJ documents show Nina Keita was close to both Epstein and Karim Wade and that she acted as a regular intermediary while Wade was in prison.
Keita also helped put Epstein in contact with her uncle, president of Ivory Coast since May 2011, and his team.
“He thought you were a very interesting person! ... they were all very happy to have you here,” she wrote on January 20, 2012, after the financier’s visit to Abidjan.
She had booked him the “ministerial suite” of the luxury Hotel Ivoire for that trip.
Ahead of the visit, Epstein had said he hoped to see “very pretty girls there, as well as interesting places.”
“You will!” Keita replied.
Emails show Keita, a former model, at least once sent photos and the phone number of a young woman to Epstein.
He then met this woman at the Ritz hotel in Paris on August 31, 2011.
“ask sadia to send pictures of her sister. i prefer under 25,” Epstein wrote to Keita after the meeting.
Now the deputy general director of Ivorian petroleum stocks company GESTOCI, Keita also appears in a February 2019 will in which Epstein requested that debts owed to him by a number of people be canceled upon his death.
AFP received no response to its requests for comment from both Keita and the Ivorian presidency, or from Karim Wade, who was contacted through his entourage.
The mere mention of a person’s name in the Epstein files does not in itself imply wrongdoing.