US Department of Homeland Security hacked in cyber attack

World

Published: 2020-12-15 13:29

Last Updated: 2024-04-19 14:17


Photo: Council on Foreign Relations
Photo: Council on Foreign Relations

The US Department of Homeland Security was Monday the victim of a major cyber attack, becoming the third federal agency to be hit by such attacks. 

Washington said the attack may have been orchestrated by a foreign government.

The Washington Post quoted unnamed officials as saying that the ministry charged with protecting the country from cyber and other attacks has been added to a growing list of targets, including the Treasury and Commerce departments.

A statement by the Department of Homeland Security Monday did not confirm the report, saying only that it was "aware of cyber breaches throughout the federal government and is working closely with our partners in the private and public sectors on the federal response."

Sunday, the Department of Homeland Security's Internet Security and Infrastructure Agency said it had asked federal agencies to immediately refrain from using SolarWinds Orion's communications technology products following reports of hackers using a new update to gain access to internal communications.

"We urge all of our partners - in the public and private sectors - to assess their exposure to this breach and to ensure the security of their networks," said acting director Brandon Wells.

SolarWinds acknowledged at the end of last week that hackers took advantage of a back door in a software update that was published between March and June.

The piracy came as part of a wider campaign against cybersecurity firm Fire Eye, which said its defenses had been compromised by sophisticated cyber attackers who stole tools used to scan customers' computer systems.

Fire Eye said it suspects a foreign government is behind the piracy, warning that it has affected many very important targets around the world.

"This campaign may have started as of spring 2020 and will continue now," she wrote in a blog post.

It is not clear what content the hackers sought to steal and how successful they were.

Several US media outlets pointed the finger at the Russian "APT29" group, also known as "Cosi Bear."

The Washington Post reported that the group is affiliated with the Russian intelligence services, and had previously hacked servers in the State Department and the White House during Barack Obama's era.

However, the Russian embassy in the United States considered the information "baseless," denying any involvement in any possible attacks.