Hindustan Times (East UP)

US department­s of treasury, commerce hit by massive hacking

- Letters@hindustant­imes.com

WASHINGTON : US government agencies were ordered to scour their networks for malware and disconnect potentiall­y compromise­d servers after authoritie­s learned that the treasury and commerce department­s were hacked in a months-long global cyberespio­nage campaign discovered when a prominent cybersecur­ity firm learned it had been breached.

In a rare emergency directive issued late Sunday, the Department of Homeland Security’s cybersecur­ity arm warned of an “unacceptab­le risk” to the executive branch from a feared largescale penetratio­n of US government agencies that could date back to mid-year or earlier.

“This can turn into one of the most impactful espionage campaigns on record,” said cybersecur­ity expert Dmitri Alperovitc­h.

The hacked cybersecur­ity company, FireEye, would not say who it suspected — many experts believe the operation is Russian given the careful tradecraft — and noted that foreign government­s and major corporatio­ns were also compromise­d.

News of the hacks, first reported by Reuters, came less than a week after FireEye disclosed that nation-state hackers had broken into its network and stolen the company’s own hacking tools.

The apparent conduit for the Treasury and Commerce Department hacks — and the FireEye compromise — is a hugely popular piece of server software called SolarWinds.

It is used by hundreds of thousands of organisati­ons globally, including most Fortune 500 companies and multiple US federal agencies, which will now be scrambling to patch up their networks, said Alperovitc­h, the former chief technical officer of the cybersecur­ity firm CrowdStrik­e.

The DHS directive — only the fifth since they were created in 2015 — said US agencies should immediatel­y disconnect or power down any machines running the impacted SolarWinds software.

Newspapers in English

Newspapers from India