A cyberespionage campaign blamed on China was more sweeping than previously known, with suspected state-backed hackers exploiting a device meant to boost Internet security to penetrate the computers of critical US entities.
The hack of Pulse Connect Secure networking devices came to light in April, but its scope is only now starting to become clear.
The hackers targeted telecommunications giant Verizon and the Metropolitan Water District of Southern California, the US’ largest water agency.
News broke earlier this month that the New York City subway system, the country’s largest, was also breached.
Security researchers said that dozens of other high-value entities that have not yet been named were also targeted as part of the breach of Pulse Secure, which is used by many companies and governments for secure remote access to their networks.
It is unclear what sensitive information, if any, was accessed.
Some of the targets said that they did not see any evidence of data being stolen.
That uncertainty is common in cyberespionage and it can take months to determine data loss, if it is ever discovered.
However, even if sensitive information was not compromised, experts say that it is worrisome that hackers managed to gain footholds in networks of critical organizations whose secrets could be of interest to China for commercial and national security reasons.
“The threat actors were able to get access to some really high-profile organizations, some really well-protected ones,” said Charles Carmakal, head technology officer of Mandiant, whose company first publicized the hacking campaign in April.
China has a long history of using the Internet to spy on the US and presents a “prolific and effective cyberespionage threat,” the US Office of the Director of the National Intelligence said in its most recent annual threat assessment.
The Chinese government has denied any role in the Pulse hacking campaign and the US government has not made any formal attribution.
In the Pulse campaign, security experts said sophisticated hackers exploited never-before-seen vulnerabilities to break in and were hyper diligent in trying to cover their tracks once inside.
“The capability is very strong and difficult to defend against, and the profile of victims is very significant,” BAE Systems Applied Intelligence head of cyber Adrian Nish said. “This is a very targeted attack against a few dozen networks that all have national significance in one way or another.”
The US Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency issued an April alert about the Pulse hack saying that it was aware of “compromises affecting a number of US government agencies, critical infrastructure entities and other private sector organizations.”
The new details of the Pulse Secure hack come at a time of tension between the US and China.
US President Joe Biden has made checking China’s growth a top priority, and said the country’s ambition of becoming the wealthiest and most powerful country in the world is “not going to happen under my watch.”
BLOODSHED: North Koreans take extreme measures to avoid being taken prisoner and sometimes execute their own forces, Ukrainian President Volodymyr Zelenskiy said Ukrainian President Volodymyr Zelenskiy on Saturday said that Russian and North Korean forces sustained heavy losses in fighting in Russia’s southern Kursk region. Ukrainian and Western assessments say that about 11,000 North Korean troops are deployed in the Kursk region, where Ukrainian forces occupy swathes of territory after staging a mass cross-border incursion in August last year. In his nightly video address, Zelenskiy quoted a report from Ukrainian Commander-in-Chief Oleksandr Syrskyi as saying that the battles had taken place near the village of Makhnovka, not far from the Ukrainian border. “In battles yesterday and today near just one village, Makhnovka,
The foreign ministers of Germany, France and Poland on Tuesday expressed concern about “the political crisis” in Georgia, two days after Mikheil Kavelashvili was formally inaugurated as president of the South Caucasus nation, cementing the ruling party’s grip in what the opposition calls a blow to the country’s EU aspirations and a victory for former imperial ruler Russia. “We strongly condemn last week’s violence against peaceful protesters, media and opposition leaders, and recall Georgian authorities’ responsibility to respect human rights and protect fundamental freedoms, including the freedom to assembly and media freedom,” the three ministers wrote in a joint statement. In reaction
BARRIER BLAME: An aviation expert questioned the location of a solid wall past the end of the runway, saying that it was ‘very bad luck for this particular airplane’ A team of US investigators, including representatives from Boeing, on Tuesday examined the site of a plane crash that killed 179 people in South Korea, while authorities were conducting safety inspections on all Boeing 737-800 aircraft operated by the country’s airlines. All but two of the 181 people aboard the Boeing 737-800 operated by South Korean budget airline Jeju Air died in Sunday’s crash. Video showed the aircraft, without its landing gear deployed, crash-landed on its belly and overshoot a runaway at Muan International Airport before it slammed into a barrier and burst into flames. The plane was seen having engine trouble.
REVELRY ON HOLD: Students marched in Belgrade amid New Year’s events, saying that ‘there is nothing to celebrate’ after the train station tragedy killed 15 Thousands of students marched in Belgrade and two other Serbian cities during a New Year’s Eve protest that went into yesterday, demanding accountability over the fatal collapse of a train station roof in November. The incident in the city of Novi Sad occurred on Nov. 1 at a newly renovated train facility, killing 14 people — aged six to 74 — at the scene, while a 15th person died in hospital weeks later. Public outrage over the tragedy has sparked nationwide protests, with many blaming the deaths on corruption and inadequate oversight of construction projects. In Belgrade, university students marched through the capital