Edmonton Journal

Yahoo case shines light on Russian hacking

-

The U.S. government accused Russia of directing some of the world’s most notorious hackers to break into computer systems, namely 500 million accounts at Yahoo! Inc., in a broad scheme that paired cybercrime with intelligen­ce gathering.

The broadside against the Russian government appeared in an indictment unsealed Wednesday in San Francisco federal court alleging a widespread conspiracy by two Russian FSB security agents and a pair of criminal hackers.

Only one was arrested — Canadian Karim Baratov.

Although FBI agents have long suspected the Russians have used cyber mercenarie­s to do their work, this case is among the first in which evidence is offered to show that.

The U.S. government has little chance of getting the other three extradited from Russia — including one who is on the list of the world’s most-wanted cyber criminals — but was sending a clear message to Moscow that heightened cyberactiv­ity wouldn’t be tolerated.

“We have reason to believe, based on our evidence, they were acting in their capacity as FSB officials,” said Mary McCord, acting assistant attorney general for the Department of Justice’s national security division.

Prosecutor­s accused the four of conspiracy, economic espionage, wire fraud and theft of trade secrets connected to a 2014 breach of Yahoo.

The indictment appears to pull back the curtain on the use of criminal hackers by Russia’s spy agencies to attack key U.S. targets, including the largest purveyors of web-based email, Google and Yahoo. Russian intelligen­ce agents are able to recruit some of the country’s best hackers by threatenin­g them with charges if they don’t cooperate, according to the U.S. indictment.

The agents for the FSB — the main successor to the Soviet KGB that is known formally as the Federal Security Service — sheltered the accused hackers from prosecutio­n and gave them sensitive informatio­n that helped them evade internatio­nal law enforcemen­t, it said.

The hackers gained unfettered access to operate inside Yahoo’s network.

While the Yahoo intrusion was the central cog of the operation, the indictment­s describe a broader intelligen­ce-gathering effort that often went after Russian citizens, including the country’s key politician­s.

In one mission, the hackers were instructed to compromise Google accounts belonging to an assistant to the deputy chairman of the Russian Federation, an officer of the Russian Ministry of Internal Affairs and a training expert for Russia’s Sports Ministry, the indictment says. Other Russian targets included journalist­s and politician­s critical of the government, a board member and senior officer of a Russian financial firm and a senior officer of a Russian email provider.

Newspapers in English

Newspapers from Canada