pwshub.com

White House forms emergency team to deal with China espionage hack

The Biden administration this week stood up a multi-agency team to confront a growing crisis involving Chinese cyberattacks of U.S. telecommunications companiesbelieved to be for intelligence gathering.

The breach now has affected “about 10 or 12” companies, two people familiar with the investigation said, speaking like others interviewed for this article on the condition of anonymity because of the matter’s sensitivity. The people did not specify if the companies were all American firms or if some were subsidiaries.

At least three major companies were breached: AT&T, Verizon and Lumen. All have declined to comment.

The U.S. government, the companies themselves and security firms that are helping investigate the intrusions still do not know how the attacker first penetrated the companies’ networks. That lack of a clear entry point is making it difficult to kick the attacker out, several people familiar with the matter said.

“It’s a sophisticated actor, and you need sophisticated ways to do that,” one person said. “The offense is better than the defense. ... It looks to be a widespread intelligence operation and one that [the government is] determined to address.”

The White House on Tuesday convened a meeting of deputy secretaries of key agencies to stand up what’s known as a “unified coordination group.” The group’s role is to ensure there is consistent interagency visibility into the response by the FBI, the Office of the Director of National Intelligence, and the Department of Homeland Security’s Cybersecurity and Information Security Agency (CISA).

The FBI, the White House National Security Council and CISA declined to comment on the ongoing investigation.

Similar coordination groups were formed to address the Chinese breach of Microsoft Exchange servers in early 2021, and before that, the Russian SolarWinds compromise that enabled the breaches of nine federal agencies, though not the Pentagon, officials said at the time.

Investigators are still working to understand the scope and nature of the compromise and what the hackers may have accessed or exfiltrated.

The breach was attributed privately by Microsoft to a group it dubbed Salt Typhoon, U.S. officials said. Microsoft discovered some of the intrusions last month.

Whether the latest breach is in fact the work of Salt Typhoon — thought by U.S. intelligence to be an arm of the Ministry of State Security, China’s foreign spy service — is not yet certain, officials say privately.

But a U.S. official said whether it turns out to be the work of a Chinese security agency or a contractor, signs point to the breach being directed by or linked to the Chinese government for espionage or counter-espionage purposes.

One U.S. official told The Washington Post last week that “there is some indication” the systems that track federal wiretap requests to telecommunications providers were targeted. However, investigators “don’t yet have 100 percent evidence that they were compromised,” the person familiar with the matter said.

On Thursday, the leaders of the House Select Committee on the Chinese Communist Party wrote to the chief executives of the three companies seeking a closed-door briefing on the breaches, including what specific measures the companies are taking to protect the federal wiretap requests.

Were China’s state-sponsored hackers to have gained access to information about federal requests for wiretaps, it would be “a golden opportunity” to thwart U.S. efforts to collect intelligence on Chinese government activities, one former senior U.S. intelligence official told The Post. It would enable adversaries to understand whom the U.S. government is interested in and undermine surveillance efforts, the former official said.

Source: washingtonpost.com

Related stories
1 month ago - Homeowners can get access to a large sum of cash at a fixed rate by borrowing against their property's value with a home equity loan.
2 weeks ago - Choosing the best place to stash your cash is tough. Here are our top picks for the best money market accounts right now.
5 hours ago - Article updated on Oct 11, 2024 Why You Can Trust CNET Money Our mission is to help...
3 days ago - Report finds Elon Musk’s platform is fueling falsehoods and conspiracy theories that risk undermining rescue efforts — and preparations for Hurricane Milton.
1 week ago - The best way to defend your home is to prevent a serious incident from occurring in the first place. Make burglars and other criminals think twice.
Other stories
55 minutes ago - Prime Day came and went, but there are still plenty of remaining deals that can help you save, such as this 60% discount on an Arlo Pro 5S security cam.
55 minutes ago - You're going to have to lose these habits if you want to make more progress on your fitness journey.
56 minutes ago - Samsung earbuds are known for their reliable performance and chic design. They don't tend to come cheap, but this Woot deal slashes the price to $152.
1 hour ago - Researchers point to evidence that scumbags visited the strategy boutique Researchers at Palo Alto's Unit 42 believe the INC ransomware crew is no more and recently rebranded itself as Lynx over a three-month period.…
2 hours ago - Modern home batteries are full of all sorts of interesting tech. Here are a few things that surprised me.