Houston Chronicle

Kaspersky CEO: U.S. files scraped but then deleted

- By Raphael Satter

PARIS — Sometime in 2014, a group of analysts walked into the office of Eugene Kaspersky, the ebullient founder of Russian cybersecur­ity firm Kaspersky Lab, to deliver some sobering news.

Kaspersky’s anti-virus software had automatica­lly scraped digital surveillan­ce tools off a computer in the U.S., and the analysts were worried: The data’s headers clearly identified the files as classified.

“They immediatel­y came to my office,” Kaspersky recalled, “and they told me that they have a problem.” He said there was no hesitation about what to do with the cache.

“It must be deleted,” Kaspersky says he told them.

The incident, recounted by Kaspersky during a brief telephone interview on Tuesday and supplement­ed by a timeline and other informatio­n provided by company officials, could not immediatel­y be corroborat­ed.

It’s the first public acknowledg­ement of a story that has been building — that Kaspersky’s popular anti-virus program uploaded powerful digital espionage tools belonging to the National Security Agency from a computer in the U.S. and sent them to servers in Moscow.

The account provides new perspectiv­e on the U.S. government’s move to blacklist Kaspersky from federal computer networks, even if it still leaves questions unanswered.

To hear Kaspersky tell it, the incident was an accident borne of carelessne­ss.

Analysts at his company were on the trail of the Equation Group — hackers later exposed as an arm of the NSA — when a computer in the U.S. was flagged for investigat­ion. The machine’s owner, identified in media reports as an NSA worker, had run anti-virus scans on their home computer after it was infected by a pirated copy of Microsoft Office, according to a Kaspersky timeline released Wednesday.

The scan didn’t just treat the infection. It also triggered an alert for Equation Group files the worker had left in a compressed archive which was then sent to Moscow for analysis.

Kaspersky’s story partially matches accounts in the New York Times, the Washington Post and the Wall Street Journal.

Kaspersky declined to say whether he had ever alerted U.S. authoritie­s to the incident.

Even if some questions linger, Kaspersky’s explanatio­n sounds plausible, said Jake Williams, a former NSA analyst and the founder of Rendition InfoSec. He noted that Kaspersky was pitching itself at the time to government clients in the United States and may not have wanted the risk of having classified documents on its network.

“It makes sense that they pulled those up and looked at the classifica­tion marking and then deleted them,” said Williams. “I can see where it’s so toxic you may not want it on your systems.”

Newspapers in English

Newspapers from United States