Chinese hackers said to have accessed law enforcement targets
Cyber marauders sought more than just information on activists -- they wanted access to FBI, DOJ investigations on spies in the U.S.
CSO - In January 2010, Google shocked the cyber world by confessing it had been the target of an advanced persistent threat lasting months and mounted by hackers connected to China's People Liberation Army.
"[We] have evidence to suggest that a primary goal of the attackers was accessing the Gmail accounts of Chinese human rights activists," Google Senior Vice President and Chief Legal Officer David Drummond wrote in blog post at the time.
Now, more that three years after that posting on what came to be known as Operation Aurora, it appears that the cyber marauders were after more than just information on activists. They were also after information on investigations on Chinese spies in the United States being conducted by the FBI and U.S. Department of Justice.
The Aurora hackers gained access on Google's servers to a database that contained information on U.S. surveillance targets, the Washington Post reported on Monday, citing former and current government officials as sources for the story.
Such information would be invaluable to China because it would allow its intelligence operatives to destroy information before counter intelligence agents got their hands on it and allow the spies to evade capture and prosecution.
The database included years of surveillance information, including thousands of court orders issued to law enforcement officials around the nation seeking to monitor suspects' email, as well as classified orders targeting foreign subjects and issued under the Foreign Intelligence Surveillance Act.
The incident set off a tiff between Google, the DOJ and FBI, the Post reported, because the federal agencies wanted to access the company's technical logs and other information about the breach to assess the potential damage done to its counter espionage efforts.
Google representative Jay Nancarrow said in an email that the company is not commenting on the matter at this time.
Google wasn't a lone target in Operation Aurora. More than 20 companies were attacked, including Adobe Systems, Juniper Networks, Rackspace, Yahoo, Symantec, Northrop Grumman, Morgan Stanley and Dow Chemical.
Last month, a Microsoft executive said that the Aurora bandits had also breached his company's servers snooping for accounts it had lawful wiretap orders on. Since that time, the executive has recanted those remarks.
"I was referring to statements in the media from the January 2010 timeframe," Dave Aucsmith, senior director for Microsoft's Institute for Advanced Technology, said in a statement.
"My comments were not meant to cite any specific Microsoft analysis or findings about motive or attacks, but I recognize that my language was imprecise," he added.
Matt Thomlinson, Microsoft's general manager for trustworthy computing and security added in an email, "The so-called 'Aurora' attacks did not breach the MS network."
The Chinese government has denied being behind Aurora. It has noted that cyber attacks and espionage are against Chinese law and has done all it can to combat such online activities.
While an attack on the database is feasible, because of the breadth of Aurora, it's unlikely it was a specific target, reasoned Jeffrey Carr, CEO of Taia Global and author of "Inside Cyber Warfare: Mapping the Cyber Underworld."
"Google was only one of 20-plus companies attacked at the same time by the same group," he said in an interview. "So I would be surprised if the database was the objective of the attack. It was likely a crime of opportunity."
It's also an object lesson for organizations dealing with cloud storage that's operated by a third party, added Alan Brill, senior managing director for Kroll Advisory Solutions.
"There's more trust being given to cloud services than some of them deserve," he said in an interview. "It has become so easy [to store data somewhere else] that you might store something somewhere without thinking whether or not you really ought to do that."
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Who's Spying on You? You're aware of the threats of malware to your business but what about the ever-changing ground rules? Cybercriminals today are launching attacks against...
- Mobile Policy Checklist Here's what to consider when putting together a mobile policy designed to support a highly productive workforce.
- Mobile Applications Case Study: 8 Billion Transactions a Day The story documents how the online brokerage company tradeMONSTER created a custom mobile app and the success gleaned from this initiative. Also covered...
- Who's afraid of the big (data) bad wolf? Survive the big data storm by getting ahead of integration and governance functional requirements This paper provides a detailed review of the best practices clients should consider before embarking on their big data integration projects.
- Mobile Apps and Devices Slash Customer Cycle Time Consolidated Engineering Laboratories' field employees used to collect data on triplicate forms that were sometimes hard to read and difficult to manage. After...
- Cloud Knowledge Vault Learn how your organization can benefit from the scalability, flexibility, and performance that the cloud offers through the short videos and other resources... All Cybercrime and Hacking White Papers | Webcasts