The Trentonian (Trenton, NJ)

In Yahoo breach, hackers may seek intelligen­ce, not riches

- By Brandon Bailey,

SAN FRANCISCO >> If a foreign government is behind the massive computer attack that compromise­d a half billion user accounts at Yahoo, as the company says, the breach could be part of a longterm strategy that’s aimed at gathering intelligen­ce rather than getting rich.

Yahoo says the breach involved users’ email addresses, passwords and other informatio­n — including birthdates — but not payment card or bank account numbers. Although the stolen data could still be used in financial crimes, such as identityth­eft,expertssay­aforeign intelligen­ce agency might combine the Yahoo files with informatio­n from other sources to build extensive dossiers on U.S. government or corporate officials in sensitive positions.

“With state-sponsored attacks, it’s not just financial informatio­n that’s of value,” said Lance Hoffman, co-director of the Cyberspace Security and Privacy Institute at George Washington University. “In the long run, if the state accumulate­s a lot of informatio­n on you, and especially if it corroborat­es that with other sources, it can assemble a pretty good profile.”

Government­s have also been known to hack email accounts to keep tabs on their own citizens or dissidents. Experts believe that was one motive behind a 2010 hacking of Google Gmail accounts used by Chinese human rights activists.

Yahoo hasn’t revealed the evidence that led it to blame a “statespons­ored actor” for the latest attack, which the Sunnyvale, California, company said occurred two years ago and was discovered only in recent weeks.

Some analysts warn that “state sponsored” can be a vague term. It might also be an easy excuse to deflect blame for a company’s own security lapses, by suggesting it had no hope of defeating hackers who had all the resources of a government intelligen­ce agency behind them, warned Gunter Ollmann, chief security officer at Vectra Networks, a San Jose, California, security firm.

Yahoo declined comment, but its top security official, Bob Lord, has said the company would make that claim only “when we have a high degree of confidence.” In a policy statement last year, Lord also said the company wouldn’t release details about why it believes attacks are state-sponsored because it doesn’t want to risk disclosing its methods of investigat­ing breaches.

This wouldn’t be the first time that government­s were implicated in high-profile hacking attacks.

U.S. officials have hinted that China might be to blame for a 2015 breach at the U.S. Office of Personnel Management, in which background files and even fingerprin­ts of millions of federal employees were stolen. China denied any official involvemen­t. More recently, news reports say U.S. intelligen­ce officials have blamed Russian spies for the hack of Democratic National Committee files, although Russia’s government has also denied this.

Some security experts believe the OPM attack was carried out by the same hackers who also stole data files from large U.S. insurance and health-care companies in 2014 and 2015. It may have been part of an effort to gather sensitive or compromisi­ng informatio­n to blackmail or coerce individual­s working at a variety of federal agencies.

Hackers could also use such personal informatio­n to concoct bogus emails and send them to a person’s Yahoo account, in what might be a sophistica­ted “phishing” scheme aimed at getting the target to click on a link containing “spyware” or other malicious computer code.

 ?? THE ASSOCIATED PRESS FILE PHOTO ?? This 2015file photo shows Yahoo’s headquarte­rs in Sunnyvale, Calif. On Thursday, the company disclosed hackers stole sensitive informatio­n from at least 500million accounts.
THE ASSOCIATED PRESS FILE PHOTO This 2015file photo shows Yahoo’s headquarte­rs in Sunnyvale, Calif. On Thursday, the company disclosed hackers stole sensitive informatio­n from at least 500million accounts.

Newspapers in English

Newspapers from United States