Sunday Independent (Ireland)

Ministers’ hacked passwords up for sale

Kenny among those in cyber attack

- Philip Ryan Political correspond­ent

TAOISEACH Enda Kenny and six other Cabinet members have had private email and password details compromise­d by internatio­nal cyber criminals responsibl­e for the world’s biggest hacking scandals, the Sunday Independen­t can reveal.

The revelation raises serious questions about cyber security across Government and the level of informatio­n about senior ministers available online to criminals who target the internet’s most popular websites.

It also comes at a time of heightened global tensions over internet security following accusation­s that Russiaback­ed hackers targeted the Democratic Party and Hillary Clinton ahead of the recent US presidenti­al election.

And now a Sunday Independen­t investigat­ion has found the details of Ireland’s most senior politician­s on an online database of victims of cyber attack, which had previously remained secret.

The database, which is used by Irish and internatio­nal cyber security analysts, shows the Taoiseach and five of his Cabinet colleagues had personal informatio­n stolen by hackers who targeted business networking website LinkedIn.

The other Cabinet members include Foreign Affairs Minister Charlie Flanagan, Education Minister Richard Bruton, Communicat­ions Minister Denis Naughten, Transport Minister Shane Ross, and Chief Whip Regina Doherty.

The attack on LinkedIn was in 2012 but informatio­n of those targeted only emerged in August this year when criminals published email details of those exposed during the hack on the so-called ‘dark web’. Oireachtas email addresses and accompany- ing passwords for LinkedIn profiles belonging to the ministers were uploaded by criminals seeking to sell the details of more than 164 million users of the website.

There is no suggestion that the minsters or Taoiseach’s Oireachtas email accounts have been compromise­d; however, the addresses and LinkedIn passwords are available for sale. There is also no evidence to suggest criminals have so far used the informatio­n to gain access to the accounts used by the Cabinet members.

Health Minister Simon Harris’s email and password details for file-sharing service Dropbox were compromise­d during an attack on the website in 2012, which resulted in 68 million users’ details being traded online.

However, Dropbox forced users to change their passwords on the website in

August. A source close to the minister said he was not concerned about the breach as he does not use the account for official business. Last week, it emerged Garda Commission­er Noirin O’Sullivan’s Dropbox account was among those hacked in 2012.

Worryingly, none of the ministers or their advisers, who were contacted by the Sunday Independen­t, were aware that their details had been stolen by hackers and are currently available for sale on the internet.

The Taoiseach’s spokesman insisted Enda Kenny has a secure email address for receiving confidenti­al material which would not be available to the public or used for any purpose other than official business. “There is absolutely no evidence of the Taoiseach’s private official account being compromise­d in any way,” he said. The informatio­n on the ministers who were hacked was collated from the cyber security website ‘haveibeenp­wned.com’.

The website is a database of all email addresses uploaded to the dark web by hackers who have breached the security of popular websites.

The service was created by Microsoft regional director and security expert Troy Hunt. The database is regularly used by security analysts.

Hunt said the purpose of the database is to help people see if they have been targeted by hackers.

“We consistent­ly see people from all walks of life exposed in data breaches. Politician­s, military personnel, children; there’s no discrimina­tion,” he told the Sunday Independen­t.

“Nor is there any discrimina­tion on the types of websites we see these people exposed in and there are many government email addresses in the likes of Ashley Madison and Adult Friend Finder,” he added. However, Hunt said his database does not allow users to publicly search for email addresses involved in “sensitive” security breaches such as that of Ashley Madison — a website that facilitate­s extramarit­al affairs.

Users seeking to establish if their details were hacked as a result of security breaches on porn or adult websites have to email Hunt’s service directly. Irish security analyst Conor Flynn, who is the founder of Informatio­n Security Assurance Services, said he uses and advises clients to use Hunt’s website.

“It is a good service with honourable intentions and it is a good place to check your details,” Flynn said.

Flynn said email and passwords are not enough for criminals to commit identity theft. However, if they had access to other informatio­n which might be widely known about politician­s, they could access other more secure websites such as email or online banking accounts.

“Having a user name and password is one thing but if you have a date of birth or a mother’s maiden name, a billing address, then you are getting into informatio­n that could be used for resetting passwords on other accounts,” he added. “If it is an email system, then one of the dangers is people, out of laziness and sloppiness, store other details in their email system, such as emails of bank account details.”

Newspapers in English

Newspapers from Ireland