In a first, US blames Russia for cyberattacks on energy grid

(Shutterstuck image)
Updated 16 March 2018
Follow

In a first, US blames Russia for cyberattacks on energy grid

WASHINGTON: The Trump administration on Thursday blamed the Russian government for a campaign of cyberattacks stretching back at least two years that targeted the US power grid, marking the first time the United States has publicly accused Moscow of hacking into American energy infrastructure.
Beginning in March 2016, or possibly earlier, Russian government hackers sought to penetrate multiple US critical infrastructure sectors, including energy, nuclear, commercial facilities, water, aviation and manufacturing, according to a US security alert published Thursday.
The Department of Homeland Security and FBI said in the alert that a “multi-stage intrusion campaign by Russian government cyber actors” had targeted the networks of small commercial facilities “where they staged malware, conducted spear phishing, and gained remote access into energy sector networks.” The alert did not name facilities or companies targeted.
The direct condemnation of Moscow represented an escalation in the Trump administration’s attempts to deter Russia’s aggression in cyberspace, after senior US intelligence officials said in recent weeks the Kremlin believes it can launch hacking operations against the West with impunity.
It coincided with a decision Thursday by the US Treasury Department to impose sanctions on 19 Russian people and five groups, including Moscow’s intelligence services, for meddling in the 2016 US presidential election and other malicious cyberattacks. Russia in the past has denied it has tried to hack into other countries’ infrastructure, and vowed on Thursday to retaliate for the new sanctions.

’Unprecedented and extraordinary’
US security officials have long warned that the United States may be vulnerable to debilitating cyberattacks from hostile adversaries. It was not clear what impact the attacks had on the firms that were targeted.
But Thursday’s alert provided a link to an analysis by the US cybersecurity firm Symantec last fall that said a group it had dubbed Dragonfly had targeted energy companies in the United States and Europe and in some cases broke into the core systems that control the companies’ operations.
Malicious email campaigns dating back to late 2015 were used to gain entry into organizations in the United States, Turkey and Switzerland, and likely other countries, Symantec said at the time, though it did not name Russia as the culprit.
The decision by the United States to publicly attribute hacking attempts of American critical infrastructure was “unprecedented and extraordinary,” said Amit Yoran, a former US official who founded DHS’s Computer Emergency Response Team.
“I have never seen anything like this,” said Yoran, now chief executive of the cyber firm Tenable, said.
A White House National Security Council spokesman did not respond when asked what specifically prompted the public blaming of Russia. US officials have historically been reluctant to call out such activity in part because the United States also spies on infrastructure in other parts of the world.
News of the hacking campaign targeting US power companies first surfaced in June in a confidential alert to industry that described attacks on industrial firms, including nuclear plants, but did not attribute blame.
“People sort of suspected Russia was behind it, but today’s statement from the US government carries a lot of weight,” said Ben Read, manager for cyber espionage analysis with cybersecurity company FireEye Inc.

Engineers targeted
The campaign targeted engineers and technical staff with access to industrial controls, suggesting the hackers were interested in disrupting operations, though FireEye has seen no evidence that they actually took that step, Read said.
A former senior DHS official familiar with the government response to the campaign said that Russia’s targeting of infrastructure networks dropped off after the publication in the fall of Symantec’s research and an October government alert, which detailed technical forensics about the hacking attempts but did not name Russia.
The official declined to say whether the campaign was still ongoing or provide specifics on which targets were breached, or how close hackers may have gotten to operational control systems.
“We did not see them cross into the control networks,” DHS cybersecurity official Rick Driggers told reporters at a dinner on Thursday evening.
Driggers said he was unaware of any cases of control networks being compromised in the United States and that the breaches were limited to business networks. But, he added, “We know that there is intent there.”
It was not clear what Russia’s motive was. Many cybersecurity experts and former US officials say such behavior is generally espionage-oriented with the potential, if needed, for sabotage.
Russia has shown a willingness to leverage access into energy networks for damaging effect in the past. Kremlin-linked hackers were widely blamed for two attacks on the Ukrainian energy grid in 2015 and 2016, that caused temporary blackouts for hundreds of thousands of customers and were considered first-of-their-kind assaults.
Senator Maria Cantwell, the top Democrat on the Senate Energy and Natural Resources Committee, asked the Trump administration earlier this month to provide a threat assessment gauging Russian capabilities to breach the US electric grid.
It was the third time Cantwell and other senators had asked for such a review. The administration has not yet responded, a spokesman for Cantwell’s office said on Thursday.
Last July, there were news reports that the Wolf Creek Nuclear Operating Corp, which operates a nuclear plant in Kansas, had been targeted by hackers from an unknown origin.
Spokeswoman Jenny Hageman declined to say at the time if the plant had been hacked but said that there had been no operational impact to the plant because operational computer systems were separate from the corporate network. Hageman on Thursday said the company does not comment on security matters.
John Keeley, a spokesman for the industry group the Nuclear Energy Institute, said: “There has been no successful cyberattack against any US nuclear facility, including Wolf Creek.”


Indonesia strips citizenship of ex-officers who joined Russian mercenary forces

Updated 10 sec ago
Follow

Indonesia strips citizenship of ex-officers who joined Russian mercenary forces

  • Muhammad Rio, Satria Kumbara went viral after claiming they were fighting in Ukraine
  • Both were dishonorably discharged, Indonesian police and navy have separately confirmed

JAKARTA: Indonesia has revoked the citizenship of former security forces personnel who joined Russian mercenary forces, the government said, addressing the cases of a former policeman and a navy officer who have reportedly joined the fighting in Ukraine.

Muhammad Rio, a former member of Indonesia’s paramilitary police force Brimob in Aceh province, said he was recruited by Russia’s Wagner Group in videos and photos that have widely circulated since last week. 

His case followed that of former Indonesian marine Satria Kumbara, who also went viral last year after uploading clips on TikTok, where he claimed to be fighting alongside Russian forces in Ukraine. 

Their Indonesian citizenships have been revoked, said Law Minister Supratman Andi Atgas. 

“Anyone, be it a Brimob officer or a civilian, who joins a foreign military without the president’s permission will automatically lose his citizenship … That is clearly stipulated in the law,” he told reporters. 

According to Atgas, the Indonesians who joined Russian mercenary forces did so discreetly, had their own contacts and never reported to the local Indonesian Embassy following their arrival, which makes them “difficult to track down.” 

After the latest case of Rio made headlines across Indonesia, Aceh police spokesperson Joko Krisdiyanto issued a statement over the weekend, saying that the ex-policeman had deserted his post since Dec. 8 and left Indonesia on Dec. 18.  

On Jan. 7, he sent photos and videos to a group chat comprising fellow police officers, “showing that the concerned person has joined the Russian mercenary division, while also describing the registration process and the salary received in Russian ruble converted to Indonesian rupiah.” 

He was slapped with a dishonorable discharge on Jan. 9 over a series of misconduct, including his alleged involvement with the Russian military, Krisdiyanto said. 

The Indonesian Navy has also confirmed that ex-marine Kumbara was dishonorably discharged in 2023.