Credit: Shutterstock.com
Get the Big One in your inbox daily. Sign up here for the DC Inno Beat.
In the background of Thursday’s electric Republican Debate between the GOP’s leading presidential prospects, the Pentagon continued on what’s been an anxious two-week investigation into a “sophisticated hack” that breached the Pentagon’s Joint Staff unclassified email system, U.S. military officials confirmed to NBC.
The hack reportedly affects roughly 4,000 military and civilian personnel who directly work with the Joint Chiefs of Staff. No classified networks were penetrated, however, U.S. officials told CNN. The DoD are currently working with cybersecurity experts to “scrub and rebuild” the email network.
Shortly after media reports of the attack appeared to proliferate on the net, The Defense Department (DoD) made a brief statement suggesting that the perpetrators were likely state-sponsored Russian hackers.
The DoD originally announced that a breach had occurred, but did not cite Russian actors, on July 25.
The Big One: Time Is Running Out on Major Cybersecurity Bill
“We’ve learned time and time again that email is not only the #1 business tool but it contains the ‘keys to the kingdom’—confidential information, password reset links for all online services, and, when compromised, an amazing channel for social engineering,” Patrick Peterson, CEO of Silicon Valley email system cybersecurity firm Agari, told DC Inno.
In what can only be defined as a year of turbulent and perhaps frenetic cybersecurity breaches aimed at the federal government, the latest Pentagon attack reportedly underscores yet another example of foreign state-sponsored actors attacking an institution.
Patrik Peterson, Agari Founder/CEO
In this case, a security system that captured national security related correspondences was penetrated. While details regarding the Pentagon breach are, at moment, scant, early reports from a cohort of news publications have identified significant aspects/elements of it.
“This attack was fairly sophisticated and has the indications .?.?. of having come from a state actor such as Russia,” a U.S. official told the Washington Post.
Focus on phishing
According to sources cited by The Post and CNN, the breach was originally noticed two weeks ago. The system was immediately shut off upon notification. While some have described the cyberattack as a “sophisticated hack,” others with knowledge of the investigation have said it was likely caused by a phishing ploy.
Phishing email attacks are usually directed at individuals within a secure network, rather than the defense network itself, and can infect a system if the user believes its author is legitimate and proceeds to access the content attached to an email while on the system. It’s by far the most common form of “hacking” and remains one of the most effective, as tricking a human is presumably easier than cracking a complex security system like that of the Pentagon. In addition, tracking the author of such an attack is also extremely challenging and as such, attributing a probable perpetrator is far from an exact science.
Peterson, the Agari CEO, noted that there’s “an increasing prevalence of spear-phishing as a new attack vector to compromise corporate security, intellectual property, and consumer data.”
“In fact, the Verizon Data Breach Investigations Report shows more than two-thirds of Nation State attacks originate with a targeted email. Until we solve this problem, we can expect more headlines of this nature,” Peterson said.
