Juniper, Symantec investigating after Google attack
IDG News Service - Juniper Networks and Symantec said Thursday that they were investigating a widespread cyber-espionage incident that has hit dozens of technology companies, including Google and Adobe.
Sources familiar with the situation say that 34 companies, most of them large Fortune 500 names, were hit by a sophisticated cyber-attack, first uncovered by Google last month. The attackers used a previously unknown "zero-day" attack on Internet Explorer, and possibly other techniques, to break into company networks and steal sensitive information.
The Washington Post reports that Yahoo, Dow Chemical and Northrop Grumman were also attacked.
Juniper and Symantec both acknowledged that they were investigating incidents, but stopped short of saying they had been hacked or of providing any details.
"As the world's largest security provider, we are the target of cyber-attacks on a regular basis. As we do with all threats, we are thoroughly investigating this one to ensure we are providing appropriate protection to our customers," Symantec said in a statement.
"Juniper Networks recently became aware of, and is currently investigating, a cyber security incident involving a sophisticated and targeted attack against a number of companies," a company spokeswoman said in an e-mail message. "We take these incidents seriously and as with any investigation of this nature, we do not disclose details."
Although IT administrators have long cited China as the source of many cyber-attacks, it is extremely difficult to say whether this malicious traffic is actually originating in China or merely passing through. The fact that Google seems to think that China is behind the attacks -- a strong enough conviction that it has threatened to stop doing business in China -- is exceptional, however.
Google discovered a command and control server being used to send instructions to hacked machines, and was able to notify and identify other victims based on that information. According to Google the companies that were targeted include the Internet, finance, technology, media and chemical businesses.
The search engine company may suspect Chinese government sponsorship of the attacks, but the company's chief legal counsel David Drummond told U.S. National Public Radio Thursday that the company doesn't have definitive evidence that the Chinese government was involved.
Human rights groups, government agencies and defense contractors have been targeted by this type of attack in the past, but the fact that so many major international companies could be hit is a wake-up call to U.S. businesses.
"It shows that even the biggest and the most sophisticated companies will always come in second place when they're matched with a big foreign intelligence service," said James Lewis a director with the Center for Strategic and International Studies.
Northorp Grumman said it does not comment on specific attacks. "Northrop Grumman, like most industries and government organizations, is at risk of cyber attacks ranging from the most complex to the simple hacker," a company spokeswoman said via e-mail.
Yahoo wouldn't say whether it had been hit. Dow Chemical could not be reached immediately for comment.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Digital Transformation: Creating New Business Models Where Digital Meets Physical
- Individuals and businesses alike are embracing the digital revolution. Social networks and digital devices are being used to engage government, businesses and civil...
- Make the Connection: Better Network Connectivity Drives Transformation
- Network connectivity is more than just plumbing. Leading organizations today see high-performance network connectivity as a critical enabler of competitive advantage, and not...
- Virtualizing Government Infrastructure
- All server virtualization solutions are not created equal. The more-with-less agenda for government agencies is tailor-made for server virtualization, which is evolving into...
- Moving Service Management to SaaS
- Today, organizations can enjoy similarly substantial benefi ts by migrating their IT service management functions to a software-as-a-service model. This paper shows how...
- Achieving 360 Degree Network Visibility with Nimsoft
- 360° network visibility is critical for ensuring continuous availability of networks, servers, and applications-anything less could
have costly bottom-line implications.
All Networking White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Unified Communications 101
- What's the best way to implement a unified communications solution for your organization?
- Try the OptiView® XG on your network - FREE
- The OptiView® XG is the first dedicated tablet with automated network and application analysis -- fastest way to root cause. XG raises the...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and... All Networking Webcasts