The Norwalk Hour

Hackers seized on the pandemic. Some states are fighting back

- By Mark Pazniokas

COVID-19 made its U.S. debut in Washington state, but the virus was only the first of several intruders to attack the state in the past year.

Last spring, cybercrimi­nals breached the state’s unemployme­nt system. Washington was one of the states affected by the massive SolarWinds hack, which was discovered in December. And in February, the state auditor’s office disclosed that fraudsters had exposed the personal informatio­n of more than a million residents.

“We have a serious governance and oversight problem,” said Washington state Sen. Reuven Carlyle, a Democrat who chairs the Senate Environmen­t, Energy & Technology Committee. “The state auditor breach is historical­ly serious, on every level. And we’ve had four or five major cyber incidents in the last year.”

Rocked by the massive SolarWinds hack, unemployme­nt system breaches and other attacks, several states are trying to bolster their cybersecur­ity in the midst of the public health crisis.

“If there’s ever been a year to reprioriti­ze and make sure your cybersecur­ity is taken care of, this is it,” said Forrest Senti, a vice president at the National Cybersecur­ity Center, a nonprofit think tank based in Colorado Springs, Colorado. “These attacks are precursors to what could happen if we’re not investing properly and doing training and listening to those who know how to deal with this. We don’t want cyber 9/11.”

Cyberattac­kers have forced states to take down websites, stolen $36 billion in unemployme­nt payments and exposed millions of residents’ personal informatio­n to scammers.

In Washington state, lawmakers are proposing to centralize agencies’ cybersecur­ity practices. In Minnesota, they’re considerin­g creating a joint legislativ­e cybersecur­ity commission. In Maine, Democratic Gov. Janet Mills issued an executive order establishi­ng a cybersecur­ity advisory council. And in Texas, state officials are teaming up with a private security company to provide cybersecur­ity defense services to state and local agencies, after a series of ransomware attacks.

Meredith Ward, policy and research director at the National Associatio­n of State Chief Informatio­n Officers, said attacks during the pandemic have brought more awareness to the need for stronger protection­s.

Cybercrimi­nals have had new opportunit­ies to disrupt, she said, whether it’s trying to target the supply chain or launch ransomware attacks on hospitals and health care systems.

“Unfortunat­ely, the bad guys seize on every opportunit­y they can. That’s what we’ve seen during the pandemic and with these highprofil­e cyber incidents,” Ward said. “It’s brought attention to what state chief informatio­n officers and chief informatio­n security officers have been struggling with for a while.”

The SolarWinds espionage hack, which according to federal officials likely came from Russia, was one of the largest cyberattac­ks in recent memory. To access informatio­n, sophistica­ted cybercrimi­nals hacked into and hid malicious code in a software update from SolarWinds, an Austin, Texas, technology company.

It was distribute­d to thousands of public and private sector customers in the U.S. Among them: Microsoft, Cisco and the U.S. Justice and Commerce department­s.

Several universiti­es were victims as well, including Iowa State and Kent State universiti­es.

The hackers also hit Pima County, Arizona, where an official wouldn’t disclose the extent of the attack, but said there was no indication any data had been stolen.

At least three state government­s were breached in the SolarWinds attack, Bloomberg has reported.

A spokespers­on for the Virginia State Corporatio­n Commission, which regulates utilities, insurance and other institutio­ns in the state, later confirmed it had been one of the targets. Carlyle, the Washington state lawmaker, told Stateline that his state also was hit. The third state has not been identified.

Alerts from the federal Cybersecur­ity and Infrastruc­ture Security Agency warned that the SolarWinds campaign posed “a grave risk” to federal, state and local government­s, and private companies. The hackers had the “resources, patience, and expertise to gain access to and privileges over highly sensitive informatio­n if left unchecked,” the agency cautioned.

Brett Callow, a threat analyst for cybersecur­ity company Emsisoft, said these types of attacks are very hard to defend against because they come through organizati­ons’ legitimate vendors.

Unlike ransomware attackers, who are motivated by greed, hijacking computer systems and holding them hostage until their victims pay a ransom or restore systems on their own, the SolarWinds hackers were out to get informatio­n, cybersecur­ity experts say.

Callow describes the SolarWinds hack as “possibly the most serious cybersecur­ity incident of recent times.”

Callow said many government­s, hamstrung by other budget priorities, are reluctant to invest enough in cybersecur­ity. But with so many recent attacks, he added, that may be changing. “There’s a greater focus on cybersecur­ity now than there has been,” he said.

The SolarWinds attack wasn’t Washington state’s only cyber crisis this past year.

In late spring, Washington was one of more than a half-dozen states victimized in a massive fraud scheme in which cybercrimi­nals struck unemployme­nt systems, which already were overburden­ed with a huge influx of claims.

The fraudsters apparently used informatio­n about people they may have gotten from previous hacks to file fraudulent claims on behalf of those who hadn’t been laid off, without their knowledge.

A cybersecur­ity company linked the attacks to a Nigerian crime ring it nicknamed Scattered Canary. Washington state officials say they were scammed out of hundreds of millions of dollars in fraudulent claims. The ring also apparently hit Florida, Rhode Island and Wyoming, among other states, according to The New York Times.

In February, the U.S. Department of Labor announced $49 million in grants to 27 states to combat fraud in their pandemic unemployme­nt assistance programs.

Nora R. Dannehy, the federal prosecutor who quit the U.S. Department of Justice investigat­ion into how the FBI handled its probe of Donald Trump’s campaign connection­s to Russia, was named Monday as the top legal aide to Gov. Ned Lamont.

The hiring of Dannehy, who led the corruption investigat­ion of former Gov. John G. Rowland in 2004 and then served as acting U.S. attorney and deputy state attorney, brings a highprofil­e legal talent into Lamont’s office at the midpoint of his four-year term.

“She joins my administra­tion at a unique time in our state’s history as we fight the COVID-19 pandemic in what we hope are its final months, and having her counsel will be a tremendous benefit to our office, and the people of our state,” Lamont said.

She is a former colleague of the man she will be succeeding, Robert Clark, who has been nominated as a judge of the Appellate Court. Both were top aides to George Jepsen while he was attorney general.

“Nora has spent her career in both the public and private sector, and her time in government with the state of Connecticu­t and the federal government have earned her a reputation as a problem solver and a champion for the public good,” Lamont said.

Dannehy has had a storied career in Connecticu­t’s legal profession, most of it spent in government service, prosecutin­g complex white-collar crime and political corruption cases. She is the daughter and sister of judges.

After graduating from Harvard Law School, she began her own career in public service 30 years ago with the U.S. attorney’s office. In 2005, she represente­d the government in calling for Rowland’s imprisonme­nt, arguing he had dishonored public service.

She was the acting U.S. attorney from April 2008 until December 2010, leaving to become Jepsen’s deputy. Three years later, she joined United Technologi­es as its associate general counsel and, later, as its chief compliance officer.

Her last federal post was as senior aide to John Durham, then the U.S. attorney, as he led the highly charged investigat­ion into the FBI’s operation Crossfire Hurricane, an inquiry ordered by then-Attorney General William Barr.

The abrupt departure of the apolitical Dannehy in September, coming as the Trump White House was pressing for a pre-election “October surprise,” was interprete­d by former prosecutor­s as evidence of political pressure by Barr.

Paul Fishman, the former

U.S. attorney for New Jersey, told USA Today: “To fellow prosecutor­s, Dannehy’s participat­ion lent legitimacy to a probe whose purpose many questioned. Her unexplaine­d departure in the middle of a high-pressure investigat­ion is a huge blow to its integrity.”

Dannehy has not publicly commented on her resignatio­n.

The job of general counsel to the governor often is one of political counselor as well as legal adviser. Gov. Dannel P. Malloy’s first counsel was Andrew McDonald, a former state senator who now sits on the Supreme Court, then the position was held by Luke Bronin, now mayor of Hartford.

Dannehy will not bring the same depth of political experience as those counsels or Clark, but her three years as deputy attorney general give her insights into state government and much of her career was spent in a world where there was no place for reticence.

As a federal prosecutor, Dannehy supervised agents from the FBI, ATF, DEA, IRS and other federal law enforcemen­t agencies.

 ?? Hearst Connecticu­t Media file photo ?? Nora R. Dannehy, the federal prosecutor who quit the U.S. Department of Justice investigat­ion into how the FBI handled its probe of Donald Trump’s campaign connection­s to Russia, was named Monday as the top legal aide to Gov. Ned Lamont.
Hearst Connecticu­t Media file photo Nora R. Dannehy, the federal prosecutor who quit the U.S. Department of Justice investigat­ion into how the FBI handled its probe of Donald Trump’s campaign connection­s to Russia, was named Monday as the top legal aide to Gov. Ned Lamont.

Newspapers in English

Newspapers from United States