US Government Reels from Sophisticated Hacking Campaign Linked to Russia

The US government continues to struggle with a massive and sophisticated hacking campaign, believed to be the work of Russia, that has compromised top federal agencies and raised national security concerns. The attack, which was first reported over the weekend, has affected the energy department, the treasury and commerce departments, and even targeted the agency responsible for the country's nuclear weapons stockpile. Authorities have expressed alarm over the hack, warning of "a grave risk" to federal, state, and local governments, as well as "critical infrastructure entities".

Key Takeaways:

  • The hacking campaign, believed to be the work of Russia, has compromised top federal agencies, including the energy department, the treasury and commerce departments, and the National Nuclear Security Administration.
  • The attack, which began as early as March, was carried out through malicious code introduced into updates to SolarWind's popular network safety tool called Orion, which is used by numerous government agencies and large corporations.
  • The hackers gained remote access to an organization's networks, including internal emails, and it is unclear what data they sought to steal and how successful they were.
  • At least six US departments have been impacted by the breach, including defense, state, treasury, homeland security, commerce, and energy.
  • The FBI and other agencies have scheduled a classified briefing for members of Congress on Friday to discuss the hack.
  • Two senators have requested a briefing with the Internal Revenue Service to determine whether personal taxpayer information has been stolen in the breach.
  • Homeland security officials have issued an emergency directive telling all federal civilian agencies to review their systems, marking only the fifth such directive to be issued by the agency since it was created in 2015.

Statistics:

  • Up to 18,000 of SolarWind's over 300,000 customers downloaded the compromised software (SolarWind).
  • At least six US departments have been impacted by the breach, including defense, state, treasury, homeland security, commerce, and energy.
  • The hack began as early as March (source).
  • The US Energy Department has evidence that hackers gained access to their networks as part of the massive cyber campaign.

Sources:

  • Kari Paul and agencies
  • Bloomberg
  • Reuters
  • Politico
  • The Cybersecurity and Infrastructure Security Agency (Cisa)
  • SolarWind
  • SailPoint