{"id":338272,"date":"2020-02-11T07:31:15","date_gmt":"2020-02-11T05:31:15","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=338272"},"modified":"2020-02-11T07:32:34","modified_gmt":"2020-02-11T05:32:34","slug":"us-charges-chinese-hackers-for-massive-data-breach","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/338272-us-charges-chinese-hackers-for-massive-data-breach.html","title":{"rendered":"US charges Chinese hackers for massive data breach"},"content":{"rendered":"<p>For the last several years, hackers based in China have allegedly been sucking up vast amounts of personal data of U.S. citizens: names, dates of birth, Social Security numbers, even fingerprints.<\/p>\n<p>On Monday, the U.S. Justice Department took another stab at stopping them.<\/p>\n<p>Attorney General William Barr announced that four members of China\u2019s People\u2019s Liberation Army had engaged in a three-months-long campaign to steal information on about 145 million Americans from Equifax Inc. In doing so, Barr detailed an audacious plan that allegedly began with a vulnerability in Apache software and uncovered a mother load of personal data.<\/p>\n<p>But, according to U.S. authorities and cybersecurity experts, the Equifax hack was one of a string of data breaches executed by Chinese hackers in which personal data was stolen. Those experts described an effort to grab so much data on so many people that the Chinese could use it to compile a database of Americans, in part to bolster spying efforts.<\/p>\n<p>Last year, Barr announced charges against a Chinese national who was part of \u201can extremely sophisticated hacking group operating in China\u201d that stole information from four large American businesses, including data on 78.8 million people from the computer network of health insurer, Anthem Inc.<\/p>\n<p>China has also been linked to a\u00a0<strong><a href=\"https:\/\/www.nytimes.com\/2018\/12\/11\/us\/politics\/trump-china-trade.html\" target=\"_blank\" rel=\"noopener noreferrer\">2018 cyber-attack<\/a>\u00a0<\/strong>at Marriott International Inc., yielding data on 500 million guests, and an infamous 2015\u00a0<strong><a href=\"https:\/\/www.bloomberg.com\/politics\/articles\/2017-09-28\/hacked-opm-data-hasn-t-been-shared-or-sold-top-spy-catcher-says\" target=\"_blank\" rel=\"noopener noreferrer\">incident<\/a><\/strong>\u00a0in which data from the federal Office of Personnel Management was stolen on 21 million individuals, including Social Security numbers and 5.6 million fingerprints.<\/p>\n<p>\u201cChinese spying is over the top increasingly dangerous,\u201d said Jim Lewis, a senior vice president and director of the Technology Policy Program at the Center for Strategic and International Studies in Washington, when asked about the charges involving Equifax. \u201cThe PLA has more personal data on Americans than anyone else.\u201d<\/p>\n<p>The Equifax hack represents a major \u201ccounterintelligence operation\u201d by the Chinese government for future use, including advancing artificial intelligence capabilities, said William Evanina, director of the\u00a0<strong><a href=\"https:\/\/www.dni.gov\/index.php\/ncsc-home\" target=\"_blank\" rel=\"noopener noreferrer\">National Counterintelligence and Security Center<\/a><\/strong>.<\/p>\n<p>\u201cThey have more than just your credit score,\u201d Evanina told reporters during a briefing on Monday. \u201cThey have all of your data.\u201d He added that his biggest concern is that the Chinese will use the data to target people who don\u2019t work in national security and therefore might not be aware of an operation.<\/p>\n<p>U.S. officials said there was no evidence the stolen Equifax data was being used. However, Barr said the Equifax hack \u201cfits a disturbing and unacceptable pattern of state-sponsored computer intrusions and thefts by China and its citizens that have targeted personally identifiable information, trade secrets and other confidential information.\u201d<\/p>\n<p>The Chinese Embassy didn\u2019t return a message seeking comment.<\/p>\n<p>John Hultquist, senior director of intelligence analysis at the cybersecurity firm FireEye Inc., said the Equifax incident is \u201cjust one example of a shift by Chinese state hackers toward organizations that aggregate data.\u201d<\/p>\n<p>\u201cGovernment bureaucracies, hospitality and travel organizations have been targeted alongside telecommunications firms and managed service providers in intrusions designed to allow access to huge amounts of data and proprietary information,\u201d he said.<\/p>\n<p>Cybersecurity experts offered different views on the purpose of the stolen data.<\/p>\n<p>The data taken from Equifax may have been used as part of an attempt to compile a database of U.S. personally identifiable information, according to Priscilla Moriuchi, who is director of strategic threat development at the cybersecurity company Recorded Future, Inc.<\/p>\n<p>This database can be used for purposes including developing cover identities for Chinese intelligence officers, validating information from other intelligence services, or \u201cbuilding profiles of individuals that may be susceptible to recruitment by Chinese intelligence, \u201c she said.<\/p>\n<p><strong><a href=\"https:\/\/gufaculty360.georgetown.edu\/s\/contact\/00336000014U0TKAA0\/ben-buchanan\" target=\"_blank\" rel=\"noopener noreferrer\">Ben Buchanan<\/a><\/strong>, a cybersecurity expert at Georgetown University, said the data gleaned may have uses such as providing \u201cfinancial context on targets of interest to China.\u201d<\/p>\n<p>\u201cIt probably wasn\u2019t too taxing for the hackers to get even this voluminous amount of data, so why not take it?\u201d he said.<\/p>\n<p>Aside from allegedly stealing personal data, China has also been accused of pilfering intellectual property from U.S. companies, including by hacking. Former National Security Agency Director Keith Alexander, who served under presidents Barack Obama and George W. Bush, has called it the \u201cgreatest transfer of wealth in history.\u201d<\/p>\n<p>In 2018, for instance, the U.S.\u00a0<strong><a href=\"https:\/\/www.justice.gov\/opa\/pr\/chinese-intelligence-officers-and-their-recruited-hackers-and-insiders-conspired-steal\" target=\"_blank\" rel=\"noopener noreferrer\">indicted<\/a><\/strong>\u00a0Chinese intelligence officers for stealing technology underlying a turbofan used by airlines while members of China\u2019s Ministry of State Security were<strong>\u00a0<a href=\"https:\/\/www.justice.gov\/opa\/pr\/two-chinese-hackers-associated-ministry-state-security-charged-global-computer-intrusion\" target=\"_blank\" rel=\"noopener noreferrer\">charged<\/a><\/strong>\u00a0with targeting government agencies and more than 45 technology companies in the U.S.<\/p>\n<p>According to the indictment announced on Monday, the hack at Equifax began in May 2017, maybe earlier, and continued through July of that year. The defendants exploited a vulnerability in Apache software that was used by Equifax\u2019s online dispute portal, where users could research and dispute inaccuracies in their credit reports.<\/p>\n<p>Apache had announced a vulnerability in certain versions of its Struts software, and it wasn\u2019t patched on Equifax\u2019s online dispute portal, according to the indictment.<\/p>\n<p>Equifax \u201cholds a colossal repository of sensitive personally identifiable information, including full names, addresses, Social Security numbers, birth dates, and driver\u2019s license numbers,\u201d according to the indictment, which alleged that the People\u2019s Liberation Army obtained the names, birth dates, and Social Security numbers for 145 Americans, in addition to the driver\u2019s licenses for at least 10 million Americans, and the credit card numbers and other personally identifiable information on 200,000 U.S. consumers.<\/p>\n<p>PLA hackers also obtained personal data belonging to nearly a million citizens of the U.K. and Canada, according to the indictment.<\/p>\n<p>Despite major investments in security measures, Equifax appeared to have been compromised \u201cby poor implementation and the departures of key personnel in recent years,\u201d according to a September 2017 story in Bloomberg Businessweek. A congressional report in 2018\u00a0<strong><a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2018-12-10\/equifax-failed-to-adjust-security-to-rapid-growth-report-says\" target=\"_blank\" rel=\"noopener noreferrer\">found<\/a><\/strong>\u00a0that Equifax failed to modernize its security to match its aggressive growth strategy.<\/p>\n<p>On Monday, Equifax Chief Executive Officer Mark Begor said, \u201cHaving China indicted for this really changes the stakes for all of us.\u201d<\/p>\n<p>\u201cThese cyber-attacks are getting more challenging for every company,\u201d he said. \u201cIt definitely raises the bar for all of us on what we need to do to defend the sensitive data that we have.\u201d<\/p>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/338058-facebook-vows-to-improve-security-after-data-breaches.html\" rel=\"bookmark\">Facebook vows to improve security after data breaches<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>For the last several years, hackers based in China have allegedly been sucking up vast amounts of personal data of U.S. citizens: names, dates of birth, Social Security numbers, even fingerprints.<\/p>\n","protected":false},"author":341034,"featured_media":296352,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[129,63066,46033,461,19937,15499],"class_list":["post-338272","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-china","tag-data-breaches","tag-equifax","tag-hacking","tag-spying","tag-us"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/338272"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341034"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=338272"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/338272\/revisions"}],"predecessor-version":[{"id":338274,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/338272\/revisions\/338274"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/296352"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=338272"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=338272"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=338272"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}