facebook linkedin twitter

Cyberattacks Anger Lawmakers As They Prepare a US Response

May 20, 2021 by Tom Ramstack
(Photo via Wikimedia Commons)

WASHINGTON — Lawmakers who listened to Defense Department officials explain recent cyberthreats Friday gave unmistakable hints that some kind of large-scale U.S. response is coming soon.

The hearing of the House Armed Services subcommittee on cyber, innovative technologies and information systems assessed how much of a risk from hackers the United States faces.

“We are in a period of strategic competition,” said Gen. Paul M. Nakasone, commander of the U.S. Army Cyber Command.

Defense analysts name Russia, China, North Korea, Iran and Syria as some of the greatest cyberworld adversaries. Other risks come from what they call “non-state actors,” which normally refers to criminals who use ransomware to get money.

Ransomware is computer code launched by hackers to encrypt an organization’s software, thereby making it unusable. The hackers then demand money in exchange for unlocking the files.

The most devastating incident mentioned during the congressional hearing was the May 7 ransomware attack against Colonial Pipeline that shut down the nation’s biggest fuel pipeline, causing gasoline shortages and higher prices in 11 states. Service resumed on the pipeline this week after the company paid hackers using the name DarkSide nearly $5 million in cryptocurrency.

In another example, the Washington, D.C. police department is negotiating with hackers to avoid having them release confidential police files on the Internet. Thieves who stole the information are demanding a $4 million ransom.

In both cases, the hackers have been traced to gangs of sophisticated computer programmers. Other times, Russian government agents were blamed, such as when they tapped into sensitive files of U.S. agencies in the 2020 SolarWinds attack or sought to use the Internet to influence the 2016 presidential election.

In another case, the U.S. Defense Department accused the Chinese military of hacking attacks intended to steal American technology and potentially disrupt the economy.

In March, Microsoft Corp. warned the world that Chinese hackers using the name Hafnium infected tens of thousands of Microsoft Exchange servers, most commonly used by small to mid-sized businesses.

“Cyber security is national security,” Nakasone told the congressional subcommittee.

Further evidence of the government’s renewed cybersecurity emphasis came from an executive order President Joe Biden issued on May 12. It requires more information-sharing about potential hacking attacks among government agencies and greater outreach to organize public-private joint ventures.

“Incremental improvements will not give us the security we need,” the executive order says. “Instead, the federal government needs to make bold changes and significant investments in order to defend the vital institutions that underpin the American way of life.”

Biden is proposing $2.1 billion for cybersecurity in his 2022 federal budget.

Mieke Eoyang, a deputy defense secretary for cyberpolicy, said at the congressional hearing that identifying computer-based threats is difficult because the attacks are launched anonymously from many places in the world.

“It’s always a challenge to pull that apart and determine who are the non-state actors and who are the state actors,” she said.

She also said the U.S. government is unlikely to succeed alone. Instead, cybersecurity requires assistance from allies and corporations most likely to be targeted.

Members of the subcommittee mentioned “strategy,” “tactics” and “funding” as the key issues to the U.S. response before moving to a closed-door classified discussion.

None of them expressed opposition to a bigger Defense Department cybersecurity initiative.

Rep. James R. Langevin, D-R.I., said that until recently, skeptics of the Defense Department downplayed cyberthreats against the U.S. government and economy.

“I hope the last year has changed those perspectives,” Langevin said.

Rep. Mike Gallagher, R-Wis., said he hoped the federal government would set aside cybersecurity funds that match the dangers to the United States.

“I think it’s safe to say that challenge is only going to grow in the short-term,” Gallagher said.

A+
a-

Cybersecurity

November 22, 2021
by Kate Michael
Klobuchar Weighs in on CAP’s New Report on Tech Regulation

WASHINGTON — Sen. Amy Klobuchar, D-Minn., has been on a crusade for swift and sweeping reform of Big Tech platforms,... Read More

WASHINGTON — Sen. Amy Klobuchar, D-Minn., has been on a crusade for swift and sweeping reform of Big Tech platforms, introducing a number of bills and even publishing a book titled “Antitrust” that looks at the history of policy toward trusts and monopolies and details how... Read More

November 13, 2021
by Victoria Turner
US Cyber Attack Defenses Assessed at Forum

WASHINGTON — The U.S. is at risk of creating a two-silo cybersecurity strategy impeding its ability to adequately address ever-evolving... Read More

WASHINGTON — The U.S. is at risk of creating a two-silo cybersecurity strategy impeding its ability to adequately address ever-evolving cyber threats from bad actors overseas, a former assistant secretary of defense said Friday. Speaking at an American Enterprise Institute event, Paul Stockton, who is now... Read More

November 9, 2021
by Dan McCue
SolarWinds Sued By Shareholders Over Epic 2020 Data Breach

GEORGETOWN, Del. — Shareholders are suing software provider SolarWinds Corp. in the Delaware Court of Chancery claiming the company directors... Read More

GEORGETOWN, Del. — Shareholders are suing software provider SolarWinds Corp. in the Delaware Court of Chancery claiming the company directors should have known of, and yet did nothing to mitigate, the risk of the massive data breach that took place in 2020. The plaintiffs, led by... Read More

October 26, 2021
by Tom Ramstack
Bigger Government Role Expected to Protect Industry From Hackers

WASHINGTON — Large-scale cyberattacks continued this week in the United States and abroad as computer security experts told a congressional... Read More

WASHINGTON — Large-scale cyberattacks continued this week in the United States and abroad as computer security experts told a congressional panel Tuesday that more government intervention is needed. On Monday, Microsoft announced that Russia-backed hackers were trying to steal information technology to disrupt the global supply... Read More

October 22, 2021
by Reece Nations
Commerce Department Tightens Export Controls on Cybersecurity Items

WASHINGTON — The Department of Commerce’s Bureau of Industry and Security announced on Wednesday it would institute new export controls... Read More

WASHINGTON — The Department of Commerce’s Bureau of Industry and Security announced on Wednesday it would institute new export controls over cybersecurity items such as cyber intrusion software that can be used maliciously. The department’s new policy also creates a new license exception for authorized cybersecurity... Read More

October 14, 2021
by Victoria Turner
Cybersecurity Experts Point to More Investment Needed in Detection, Response

WASHINGTON -- If everyone were to employ proper cyber hygiene like multi-factor authentication or not clicking on links in phishing... Read More

WASHINGTON -- If everyone were to employ proper cyber hygiene like multi-factor authentication or not clicking on links in phishing emails, more than 85% of cyberattacks would be prevented, said Sen. Angus King, I-Maine, Thursday.  “The best hack is the one that doesn’t happen,” King said... Read More

News From The Well
scroll top