Deutsche Welle (English edition)

Cyberattac­k on US Department of Energy a 'grave threat'

-

The attack is part of the huge SolarWinds hack that has hit other government agency systems and critical infrastruc­ture. The US cybersecur­ity agency has warned it poses a serious risk.

The US Department of Energy (DoE) said on Thursday it was responding to a cyber breach on its networks. The incident is part of a massive hack campaign that has struck at least two other US government agencies.

Malware "has been isolated to business networks only," an Energy Department spokeswoma­n Shaylyn Hynes said in a statement.

Nukes not affected

She denied an earlier report by US media outlet Politico that the attack had impacted US national security, including the National Nuclear Security Administra­tion, which manages the country's nuclear weapons stockpile.

Software that DoE officials identified as being vulnerable to the attack has been disconnect­ed from the department's network, Hynes added.

The nation's cybersecur­ity agency on Thursday warned that the hack presented a "grave" risk to government and private networks.

Federal agencies and "critical infrastruc­ture" were put at

risk by the sophistica­ted attack that was hard to detect and will be difficult to undo, the Cybersecur­ity and Infrastruc­ture Security Agency said in an unusual warning message.

Homeland Security, the agency's parent department, defines critical infrastruc­ture as any "vital" assets to the US or its economy. This includes power plants and financial institutio­ns.

Fears over widespread network access

According to officials cited in the Politicore­port, hackers did more damage to networks at the DoE's Federal Energy Regulatory Commission, or FERC, than

any other branch of the agency. It also said the department's Sandia and Los Alamos labs were hacked.

FERC regulates the transmissi­on of gas and power between states but has no control over the US or regional power grids.

Senator Deb Fischer, a Republican who is the chair of the subcommitt­ee that oversees nuclear forces, said she was confident in the security of US nuclear weapons but was "troubled" that hackers accessed NNSA's network.

The hack "reinforces the need to modernize our nuclear enter

prise in order to ensure it remains safe, secure, and effective in the face of evolving threats," said Fischer, who has requested a briefing from the DoE.

What do we know about the SolarWinds breach?

Hackers accessed federal agencies through holes in software from US-based company SolarWinds. Malicious code was hidden in updates to its Orion software in March that could give hackers the same views as in-house IT crews. Some 18,000 SolarWinds' clients are thought to have downloaded the compromise­d updates.

The Department of Homeland

Security said on Thursday the hackers also used other techniques to gain access to networks.

Russian hackers are believed to be behind the attack.

In addition to the DoE, two federal department­s, the US Treasury and the Department of Commerce, have been hit.

Further US government department­s, including the Defense and Justice department­s, are assuming that the nonclassif­ied networks have been accessed.

Microsoft also affected

Microsoft on Thursday said it detected a malicious version of the software from SolarWinds inside the company. Its investigat­ion so far showed no evidence hackers had used Microsoft systems to attack customers, reported news agency Reuters.

"Like other SolarWinds customers, we have been actively looking for indicators of this actor and can confirm that we detected malicious Solar Winds binaries in our environmen­t, which we isolated and removed," a Microsoft spokespers­on said, adding that the company had found "no indication­s that our systems were used to attack others."

kmm/sms (Reuters, AP, AFP)

 ??  ?? Critical infrastruc­ture were put at risk by the sophistica­ted attack that was hard to detect and will be difficult to undo
Critical infrastruc­ture were put at risk by the sophistica­ted attack that was hard to detect and will be difficult to undo

Newspapers in English

Newspapers from Germany