Miami Herald

U.S. and allies say Microsoft Exchange hack was caused by China

- BY ERIC TUCKER

The Biden administra­tion and Western allies formally blamed China on Monday for a massive hack of Microsoft Exchange email server software and asserted that criminal hackers associated with the Chinese government have carried out ransomware and other illicit cyber operations.

The announceme­nts, though not accompanie­d by sanctions against the Chinese government, were intended as a forceful condemnati­on of activities that a senior Biden administra­tion official described as part of a “pattern of irresponsi­ble behavior in cyberspace.” They highlighte­d the ongoing threat from Chinese hackers even as the administra­tion remains consumed with trying to curb ransomware attacks from Russia-based syndicates that have targeted critical infrastruc­ture.

The cyberthrea­ts from Beijing disclosed on Monagainst day included a ransomware attack from government­affiliated hackers that targeted victims — including in the U.S. — with demands for millions of dollars. U.S officials also alleged that criminal contract hackers associated with China’s Ministry of State Security have engaged in cyber extortion schemes and theft for their own profit.

Meanwhile, the Justice Department on Monday announced charges against four Chinese nationals who prosecutor­s said were working with the MSS in a hacking campaign that targeted dozens of computer systems, including companies, universiti­es and government entities. The defendants are accused of targeting trade secrets and confidenti­al business informatio­n, including scientific technologi­es and infectious­disease research.

Unlike in April, when public finger-pointing of Russian hacking was paired with a raft of sanctions against Moscow, the Biden administra­tion did not announce any actions

Beijing. Nonetheles­s, a senior administra­tion official who briefed reporters said that the U.S. has confronted senior Chinese officials and that the White House regards the multinatio­n shaming as sending an important message, even if no single action can change behavior.

President Joe Biden told reporters “the investigat­ion’s not finished,” and White House press secretary Jen Psaki did not rule out future consequenc­es for China, saying, “This is not the conclusion of our efforts as it relates to cyber activities with China or Russia.”

Even without fresh sanctions, Monday’s actions are likely to exacerbate tensions with China at a delicate time. Just last week, the U.S. issued separate stark warnings against transactio­ns with entities that operate in China’s western Xinjiang region, where China is accused of repressing Uyghur Muslims and other minorities.

The administra­tion also advised American firms of the deteriorat­ing investment and commercial environmen­t in Hong Kong, where China has been cracking down on democratic freedoms it had pledged to respect in the former British colony.

The European Union and Britain were among the allies who called out China. The EU said malicious cyber activities with “significan­t effects” that targeted government institutio­ns, political organizati­ons and key industries in the bloc’s 27 member states could be linked to Chinese hacking groups. The U.K.’s National Cyber Security Centre said the groups targeted maritime industries and naval defense contractor­s in the U.S. and Europe and the Finnish parliament.

In a statement, EU foreign policy chief Josep Borrell said the hacking was “conducted from the territory of China for the purpose of intellectu­al property theft and espionage.”

The Microsoft Exchange cyberattac­k “by Chinese state-backed groups was a reckless but familiar pattern of behaviour,” U.K. Foreign Secretary Dominic Raab said.

NATO, in its first public condemnati­on of China for hacking activities, called on Beijing “to act responsibl­y.”

That hackers affiliated with the Ministry of State Security were engaged in ransomware was surprising and concerning to the U.S. government, the senior administra­tion official said. But the attack, in which an unidentifi­ed American company received a highdollar ransom demand, also gave U.S. officials new insight into what the official said was “the kind of aggressive behavior that we’re seeing coming out of China.”

A spokespers­on for the Chinese Embassy in Washington, Liu Pengyu, said in a statement that the “U.S. has repeatedly made groundless attacks and malicious smear against China on cybersecur­ity. Now this is just another old trick, with nothing new in it.” The statement called China “a severe victim of the US cyber theft, eavesdropp­ing and surveillan­ce.”

 ?? NG HAN GUAN AP ?? A man walks by the Microsoft office in Beijing in 2020. The cyberthrea­ts from Beijing disclosed on Monday included a ransomware attack.
NG HAN GUAN AP A man walks by the Microsoft office in Beijing in 2020. The cyberthrea­ts from Beijing disclosed on Monday included a ransomware attack.

Newspapers in English

Newspapers from United States