AP: Microsoft Exchange email hack was caused by China

hanimmal

Well-Known Member
https://apnews.com/article/microsoft-exchange-hack-biden-china-d533f5361cbc3374fdea58d3fb059f35
Screen Shot 2021-07-19 at 9.13.06 AM.png
WASHINGTON (AP) — The Biden administration on Monday blamed China for a hack of Microsoft Exchange email server software that compromised tens of thousands of computers around the world earlier this year.

The administration and allied nations also disclosed a broad range of other cyberthreats from Beijing, including ransomware attacksfrom government-affiliated hackers that have targeted companies with demands for millions of dollars. China’s Ministry of State Security has been using criminal contract hackers, who have engaged in cyber extortion schemes and theft for their own profit, according to a senior administration official. That official briefed reporters about the investigation on the condition of anonymity.

Meanwhile, the Justice Department on Monday announced charges against four Chinese nationals who prosecutors said were working with the Ministry of State Security in a hacking campaign that targeted dozens of computer systems, including companies, universities and government entities.

The announcements highlighted the ongoing cyberthreat posed by Chinese government hackers even as the administration has been consumed with trying to curb ransomware attacks from Russia-based syndicates that have targeted critical infrastructure, including a massive fuel pipeline. Even though the finger-pointing was not accompanied by any sanctions of Beijing, a senior administration official who disclosed the actions to reporters said that the U.S. has confronted senior Chinese officials and that the White House regards the multination public shaming as sending an important message.

READ MORE FROM AP
That hackers affiliated with the Ministry of State Security carried out a ransomware attack was surprising and concerning to the U.S. government, the senior administration official said. But the attack, in which an unidentified American company received a high-dollar ransom demand, also gave U.S. officials new insight into what the official said was “the kind of aggressive behavior that we’re seeing coming out of China.”

The European Union and Britain also pointed the finger at China. The EU said malicious cyber activities with “significant effects” that targeted government institutions, political organizations and key industries in the bloc’s 27 member states could be linked to Chinese hacking groups. The U.K.’s National Cyber Security Centre said the groups targeted maritime industries and naval defense contractors in the U.S. and Europe and the Finnish parliament.

In a statement, EU foreign policy chief Josep Borrell said the hacking was “conducted from the territory of China for the purpose of intellectual property theft and espionage.”

The Microsoft Exchange cyberattack “by Chinese state-backed groups was a reckless but familiar pattern of behaviour,” U.K. Foreign Secretary Dominic Raab said.

The majority of the most damaging and high-profile recent ransomware attacks have involved Russian criminal gangs. Though the U.S. has sometimes seen connections between Russian intelligence agencies and individual hackers, the use of criminal contract hackers by the Chinese government “to conduct unsanctioned cyber operations globally is distinct,” the official said.

The Microsoft Exchange hack was first identified in January and was rapidly attributed to Chinese cyber spies by private sector groups. An administration official said the government’s attribution to hackers affiliated with China’s Ministry of State Security took until now in part because of the discovery of the ransomware and for-profit hacking operations and because the administration wanted to pair the announcement with guidance for businesses about tactics that the Chinese have been using.

An advisory Monday from the FBI, the National Security Agency and the Cybersecurity and Infrastructure Security Agency laid out specific techniques and ways that government agencies and businesses can protect themselves.

The White House also wanted to line up an international coalition of allies to call out China, according to the official, who said it was the first time NATO had condemned Beijing’s hacking operations.

A Chinese Foreign Ministry spokesperson, asked about the Microsoft Exchange hack, has previously said that China “firmly opposes and combats cyber attacks and cyber theft in all forms” and cautioned that attribution of cyberattacks should be based on evidence and not “groundless accusations.”
 

mooray

Well-Known Member
This stuff is so frustrating. I'd really like to see a tier-based cord cutting between China/Russia and the US. Start with a day, then a week, then a month, etc., so basically you get a handful of chances before you're permabanned. Ultimately, the corporatocracy would never allow any real punishment.
 

Jimdamick

Well-Known Member
I would love to see the time line on the approval/development of the/those attacks on the US.
Why do i think it was when shit head embargoed & increased tariffs on China?
We picked the wrong country to fuck with.
They think this is a matter of honor & prove they have the ability through cyber warfare to fuck us up.
Wanna bet?

PS
Putin is laughing his ass of.
Wanna bet?
:)
 
Last edited:

hanimmal

Well-Known Member
This stuff is so frustrating. I'd really like to see a tier-based cord cutting between China/Russia and the US. Start with a day, then a week, then a month, etc., so basically you get a handful of chances before you're permabanned. Ultimately, the corporatocracy would never allow any real punishment.
At this point we would have to cut off a lot of the developing world to us I think.

I would love to see the time line on the approval/development of the/those attacks on the US.
Why do i think it was when shit head embargoed & increased tariffs o China?
We picked the wrong country to fuck with.
They think this is a matter of honor & prove they have the ability through cyber warfare to fuck us up.
Wanna bet?

PS
Putin is laughing his ass of.
Wanna bet?
:)
Whatever Snowden smuggled to Russia, he gave to China first, so I am sure they have all the same tools to attack us.
 

shimbob

Well-Known Member
How come there's never any blame on Microsoft for making software that every scriptkiddy and his mom's dog can hack?
 

hanimmal

Well-Known Member
How come there's never any blame on Microsoft for making software that every scriptkiddy and his mom's dog can hack?
Because they are not actively involved in conducting a crime on citizens of the countries that are under attack?

They should be willing to step up and make sure it is fixed as much as possible, and everyone is warned when they are vulnerable though.
 

Dorian2

Well-Known Member
How come there's never any blame on Microsoft for making software that every scriptkiddy and his mom's dog can hack?
On the face of it, I understand why you may ask this question. The unfortunate reality of the situation is that there are a shitload of small and very large companies that do not fund and properly support the Information Tech sections of their business schema to allow the Tech's and end user's to do their jobs appropriately. You'd be very surprised how little money in big business actually goes towards appropriate security, tech infrastructure, and end user needs/support. But you probably see it everyday in basic front end systems that you either work with or in a business you may visit. It's a big issue.

 
Top