Showing posts with label WikiLeaks. Show all posts
Showing posts with label WikiLeaks. Show all posts

Monday, February 27, 2012

WikiLeaks publishes millions of emails stolen from US think tank

Notorious whistleblowing website WikiLeaks has published five million emails from a geopolitical analysis company that Reuters likened to a “shadow CIA.”
The emails, stolen in late December from the U.S.-based company, could reveal private information on Stratfor readers and subscribers, the details of sensitive sources, and even throw light on the intelligence-gathering community, Reuters reported.
According to a WikiLeaks statement accompanying the posting of the documents, they reveal the inner workings of the intelligence publisher, which works with companies such as Lockheed Martin, Northrop

Wednesday, July 27, 2011

British Police Make Arrest in Net Attacks

The British police announced the arrest on Wednesday of a 19-year-old man who they said was the spokesman of the online vigilante group Lulz Security, which has claimed responsibility for a string of attacks on the Web sites of government agencies and private corporations.

In a statement, the police said the man used the online alias Topiary and had been picked up during a raid on a residence in the Shetland Islands, the rugged archipelago off the northeastern coast of Scotland. The police said they were also questioning a 17-year-old but had not arrested him.
On Twitter, Topiary described himself as a “simple prankster turned swank garden hedge.” His missives were often facetious, suggesting the handiwork of someone who relished playful language.
Lulz Security, the offshoot of a larger and more amorphous hacker group called Anonymous, has said it was responsible for attacks on the sites of PBS, the Senate, the Arizona Department of Public Safety and a company associated with the F.B.I.
The most recent post on Topiary’s Twitter feed is dated July 21, two days after law enforcement authorities announced the arrests of more than a dozen people in the United States, Britain and the Netherlands, who were accused of participating in online attacks at the instigation of Anonymous. “You cannot arrest an idea,” Topiary wrote.
In the United States, 14 men and women, mostly in their 20s, were charged in connection with an online attack last December against PayPal, after the online payment company stopped taking donations for WikiLeaks.
On Wednesday, in response to those arrests, Anonymous called on supporters to cancel their PayPal accounts. Shares in PayPal’s parent company, eBay, dropped 3 percent, in line with declines in other tech stocks.
A PayPal spokesman, Anuj Nayar, denied that any significant number of PayPal users had canceled their accounts in response to the call for a boycott. “We haven’t seen any changes to our normal operations, including account opening and closing,” Mr. Nayar said.
The attack on PayPal’s site last December slowed down the company’s system, but to such a small extent that it would have been imperceptible to customers, he said. At no point, Mr. Nayar said, was the Web site shut down.

Thursday, July 21, 2011

Hackers Gain Access to NATO Data

A group of computer hackers on Thursday claimed to have breached NATO security and accessed a trove of restricted material. The group, called Anonymous, said that it would be “irresponsible” to publish most of the material it took from NATO, but that it was sitting on about one gigabyte of data. “Hi NATO,” the group


teased on Twitter. “Yes, we haz more of your delicious data.” A NATO official, who could not be named under standing rules, said the organization was aware that a hacker group had released what it claimed to be classified NATO documents on the Internet and was investigating. “We strongly condemn any leak of classified documents, which can potentially endanger the security of NATO allies, armed forces and citizens,” the official said. Anonymous is a loosely organized group of hackers sympathetic to WikiLeaks. It has claimed responsibility for attacks against corporate and government Web sites worldwide.

Tuesday, July 19, 2011

FBI arrests 14 alleged members of hacker group Anonymous

In what it said was the largest sweep of Internet "hactivists" in the U.S., the FBI arrested 14 alleged members of hacker group Anonymous, which last fall took responsibility for knocking out the websites of several large companies.

The 14 people arrested, including two from Southern California, may be the first alleged members of Anonymous to be arrested by the FBI, said a law enforcement official not authorized to speak on the matter. The raids may also mark the first time that federal agents arrested individuals for cyber crimes that may have been committed as a form of political protest.
The arrests came as a result of a distributed denial of service attack — when attackers try to jam a company's website by getting large numbers of computers to contact it at the same time — on PayPal Inc. late last year, federal officials said. Anonymous claimed to have attacked PayPal and other companies including Visa Inc., MasterCard Inc. and Amazon.com Inc. in December as part of "Operation Avenge Assange." The attacks were launched after the companies suspended the accounts of whistleblower organization WikiLeaks, run by Julian Assange, after it began releasing classified information to the public.
The recent arrests are unusual because cyber protesting, a niche segment of cyber crime, is a relatively new phenomenon, said Stan Stahl, president of the Los Angeles chapter of trade group Information Systems Security Assn..
"I don't recall cyber protesting as something that has come up before Anonymous came up with their denial of service attacks against PayPal and Visa," he said.
Law enforcement agencies tend to target hackers based on the amount of financial havoc wreaked or their potential risk to national security, Stahl said. When Anonymous hacked huge corporations such as Visa or government entities such as the Spanish police, they pretty much guaranteed law enforcement scrutiny and action, Stahl said.
Not since 32 people were arrested in Turkey last month had so many alleged members of Anonymous been arrested. The arrests came a day after the group was involved in several attacks on websites belonging to media company News Corp.
Early Tuesday, however, at least one Anonymous member said the arrests would not stop hacker attacks.
"It doesn't matter how many people the FBI arrest," a tweet from the account @ThaiAnonymous said. "#anonymous have (sic) started something unstoppable."
The FBI said agents arrested alleged Anonymous members in Alabama, Arizona, California, Colorado, the District of Columbia, Florida, Massachusetts, Nevada, New Mexico and Ohio.
The FBI released the names and online aliases of all but one of the arrested individuals. The alleged members of Anonymous range in age from 20 to 42, though most are in their 20s.
The arrests were part of a broader ongoing investigation of cyber attacks in recent months.
Separately, the FBI said it arrested 21-year-old Lance Moore of Las Cruces, N.M., who it said may have either worked for or aided the hacker group LulzSec last month. The individual is believed to have stolen information belonging to AT&T Inc. valued at more than $5,000, according to a court document released by the FBI. The stolen information was later published by the hacker group, the FBI said in a release.
The FBI also said Scott Matthew Arciszewski, 21, was arrested and will appear in federal court in Orlando, Fla. Arciszewski is suspected of hacking the Tampa Bay Infragard website, which is affiliated with the FBI.
Five alleged hackers were arrested in Europe but the FBI, which worked with authorities in Britain and the Netherlands, did not say if they were involved with Anonymous.

News Corp. Under Assault Finds Defense in Journal Opinion Pages

While the widening News Corp. (NWSA) phone- hacking scandal sent Rupert Murdoch and son James in front of a U.K. parliamentary committee and unseated senior officials at the company and Metropolitan Police, the media empire found an aggressive defender in the Wall Street Journal’s opinion pages.

Among at least five opinion pieces published so far this week supporting the newspaper’s owner were two signed by editorial board members. A third, a 1,000-word lead editorial, said media organizations commonly “pay sources for information” and “skew their coverage” to influence public affairs. The piece, titled “News and Its Critics,” added that it was “up to British authorities to enforce their laws.”
“This is the first great test of the Wall Street Journal under Murdoch’s ownership,” said Sarah Ellison, whose book “War at the Wall Street Journal” chronicled News Corp.’s 2007 acquisition of Dow Jones & Co. for $5.2 billion from the family that had controlled it for 105 years.
“I think this establishes the Journal as a mouthpiece for News Corp., unfortunately,” Ellison said.
The editorial described the “righteous hindsight” and “thick” Schadenfreude of groups such as British Broadcasting Corp., the Guardian newspaper and investigative website ProPublica. “We also trust that readers can see through the commercial and ideological motives of our competitor-critics,” it said.
Calame’s Take
Byron Calame, who joined the Wall Street Journal in September 1965 and was deputy managing editor when he retired from the newspaper in 2004, said it “remains to be seen” if the editorial’s voice resonates with the newspaper’s readers. While it was “well-crafted,” he said, “the defensive tone alone was a disappointment.”
As of 5 p.m. on July 18, the editorial was the second-most- read article on the Wall Street Journal’s website, behind a piece titled “Get Ready for a 70% Marginal Tax Rate.” It was still No. 2 at 5 p.m. yesterday.
News Corp. closed the News of the World tabloid this month after allegations that its journalists tapped the voicemails of murder victims and paid police officers for stories. Bloomberg LP, the parent of Bloomberg News, competes with News Corp. units in providing financial news and information.
The Wall Street Journal’s opinion pages were called “the primest real estate in all journalism” in a column by editorial board member Robert Pollock. He wrote that Murdoch, the company’s 80-year-old chairman and chief executive officer, has imposed “no editorial direction.”
Murdoch told the committee yesterday that while he checks in with editors of his papers on occasion, he doesn't meddle.
`In the Same Building'
``If there's any editor I've spent the most time with, it's the editor of the Wall Street Journal, because I'm in the same building,'' Murdoch said.
Another editorial board member, Bret Stephens, wrote that the reaction to the hacking scandal was harsher than the fallout from whistle-blowing organization WikiLeaks, whose disclosure of classified information he said did more harm.
In a video that followed, Stephens, the editorial page’s deputy editor, described the News Corp. scandal as a “convenient morality play for people who either for competitive reasons or ideological reasons haven’t liked Rupert Murdoch and his company for a very long time.”
Another opinion piece criticized a New York Times columnist who apologized for supporting News Corp.’s purchase of the Wall Street Journal. A fifth described “an outpouring of left-wing ressentiment.”
Les Hinton
The “News and Its Critics” editorial also said that the newspaper’s previous owner, the Bancroft family, had an “appetite for dividends” and that the calls for criminal probes into News Corp. come from a “political mob.” It commended the ethical judgment of Les Hinton, who oversaw News Corp.’s U.K. newspapers during the time of the alleged hacking and resigned as the chief executive officer of the company’s Dow Jones unit on July 15.
The newspaper, the largest by circulation in the U.S., has not been accused of phone hacking.
“The editorial isn’t defending the Wall Street Journal; it obviously easily could defend the Journal,” Dean Starkman, editor of the Columbia Journalism Review’s business press section, said in an interview. “It’s ‘News and Its Critics’ -- News Corp. It’s a defense of News Corp.”
Paul Gigot, the editorial page editor, declined to comment, according to Ashley Huston, a spokeswoman. Former Wall Street Journal op-ed editor Tunku Varadarajan, now the editor of Newsweek International, worked with Gigot for seven years. In an e-mail, he said he saw Gigot’s “high-class mind” and “impressive professional integrity” in the editorial.
David Weidner, a columnist for MarketWatch and the Wall Street Journal, said most of his colleagues would prefer that the newsroom’s work speak for the organization’s integrity.
“The people who are paid to make speeches can make them,” he said in an e-mail. “But you would be hard pressed to find anyone in news who wants opinion pieces read before their own reporting and analysis.”

Saturday, June 25, 2011

LulzSec Posts Stolen Data from Arizona Lawman Site

Stolen data from the Arizona Department of Public Safety has been posted by the hacker group LulzSec. The hackers promised to release "more classified documents and embarrassing personal details" about military and law-enforcement attempts to "terrorize communities." LulzSec also said its attack on Sony Pictures was wider than reported.
Hackers have released a torrent of confidential data seized during an intrusion at the web site of the Arizona

Department of Public Safety, including hundreds of private intelligence bulletins, training manuals, and personal e-mail correspondence of law-enforcement officials. The underground group LulzSec said it selected its latest target because of Arizona's recent passage of an anti-immigration bill as well as the racial attitudes of state police officials.
Among the confidential documents released by LulzSec Thursday was a report concerning an encounter between Arizona police and two private individuals equipped with pistols and an assault rifle and wearing camouflage outfits. Both individuals held valid U.S. Marine Corps identification cards and claimed they were off-duty and working as private contract employees paid to patrol the border.
"Every week we plan on releasing more classified documents and embarrassing personal details of military and law enforcement," the LulzSec hackers wrote. The aim is "not just to reveal their racist and corrupt nature, but to purposefully sabotage their efforts to terrorize communities [by] fighting an unjust 'war on drugs.' See you again real soon!"
Problems Along the Border
One sensitive FBI document released Thursday noted that the Mexican government refused to sign an "Intercept Agreement" promising not to eavesdrop on U.S. government radio communications along the border. The confidential report suggested Mexico's response meant Mexican authorities intended "to do a lot of listening."
Other Arizona law-enforcement documents demonstrate that smugglers are becoming more tech-savvy. For example, drug lords moving product across the border are now using sophisticated GPS gear to track their shipments as well as target rival groups.
Smugglers also have begun hiding their flash storage devices in innocuous objects ranging from cigarette lighters, jewelry and pens to calculators and children's toys. By contrast, some of the computers in the Arizona Department of Public Safety are still using dial-up connections to access the Internet.
One anonymous individual whose e-mail accounts were compromised by LulzSec's latest intrusion called the hackers terrorists. "If we're terrorists, then you're a jackass for reusing your password everywhere for nine years," LulzSec retorted in a Friday tweet.
On a Spree
LulzSec claimed responsibility for hacking the PBS web site late last month as payback after the television network ran a TV program about the WikiLeaks hack of sensitive U.S. State Department documents. The intrusion included the posting of a fake Tupac article on the PBS home page.
Then in early June, the hacker group broke into the Sony Pictures web site and claimed to have lifted the personal data of a million individuals. Sony Pictures affirmed the hack on June 8, when it admitted it had notified "approximately 37,500 people who may have had some personally identifiable information stolen during the recent attack."
Sony Pictures said the stolen information didn't include "any credit-card information, Social Security numbers, or driver-license numbers." Still, it admitted the hackers obtained data on a significant number of its web-site users, such as "address, e-mail address, telephone number, gender, date of birth, and web-site password and username."
However, LulzSec said its haul from Sony Pictures had a wider scope than the company reported. The group claimed to have compromised sensitive corporate details as well as propriety information. "Among other things, we also compromised all admin details of Sony Pictures -- including passwords -- along with 75,000 'music codes' and 3.5 million 'music coupons,'" the hacker group wrote.
Moreover, the group hacked Sony Pictures using "a very simple SQL injection -- one of the most primitive and common vulnerabilities, as we should all know by now," LulzSec observed.
 "From a single injection, we accessed EVERYTHING. What's worse is that every bit of data we took wasn't encrypted."

Wednesday, June 22, 2011

Inside the Anonymous Army of 'Hacktivist' Attackers

Netherlands—In this sleepy Dutch town last December, police burst into the bedroom of 19-year-old Martijn Gonlag as he hurriedly pulled on jeans over his boxer shorts. He was hauled away on suspicion of taking part in cyber attacks by the online group calling itself Anonymous.
Mr. Gonlag admits taking part in several attacks on websites, but he recently had a change of heart as some hackers adopted increasingly aggressive tactics.
"People are starting to grow tired of" the hackers, he said in an interview. "People are also starting to realize that Anonymous is a loose cannon."
Now he appears to be a target himself. A chat room he hosts faces frequent hack attacks, he says.
Mr. Gonlag's role reversal provides a glimpse of the unruly hunt-or-be-hunted world underpinning a string of online attacks against major companies and government bodies—incidents that have sparked a digital manhunt by law-enforcement agencies in several countries.
What once was just righteous rabble-rousing by Anonymous in the name of Internet freedom has mutated into more menacing attacks, including by a splinter group of Anonymous called LulzSec, which is alleged to have moved beyond paralyzing websites to breaking in to steal data.
The tumult over online agitators like Anonymous comes at a time when the world's computers are under unprecedented attack. Governments suspect each other of mounting cyber espionage and attacks on power grids and other infrastructure. Criminal gangs using sophisticated viruses cull credit-card and other sensitive data to steal from bank accounts.
Now "hacktivists" who populate groups like Anonymous and LulzSec, mostly young males from their teens to early 30s, have also ignited increasing concern among computer experts over the security of corporate and government systems.
Authorities in the U.K., Netherlands, Spain and Turkey have made more than 40 arrests of alleged Anonymous participants. In the U.S., the Federal Bureau of Investigation has conducted sweeping searches as part of a continuing probe into various attacks. On Wednesday, U.K. police charged a 19-year-old believed to have ties with both Anonymous and LulzSec, a group whose name is a blend of "lulz," or laughs, and "security."
Anonymous and LulzSec pose a problem for law enforcement partly because their membership and operations are difficult to pin down. They are amorphous entities with scant leadership structure or formal process for making decisions.
Anonymous is "an idea" rather than a group, said Gregg Housh, a 34-year-old Web designer from Boston. "There is no one group, no one website. That is what makes it so powerful in my eyes." Mr. Housh said he helps Anonymous with logistics but doesn't take part in attempts to shut down websites or do anything illegal.
Waves of infighting spring up periodically within Anonymous, Mr. Housh added. "This is very natural. It's what happens."
A watershed in its tactics came in February when it hacked a California-based Internet-security firm called HB Gary Federal LLC, which sells investigative services to companies and government agencies, and released tens of thousands of internal emails.
The incident sent a chill through the security industry. "Computer-security specialists are afraid to challenge Anonymous," said Mikko Hypponen, of computer-security firm F-Secure Corp. "No one is that confident in their own systems."
Some participants involved in that hack formed the LulzSec splinter group, according to security specialists and participants. LulzSec has claimed credit for a string of computer break-ins, intensifying the response from law-enforcement groups.
Anonymous grew out of an online message forum formed in 2003 called 4chan, a destination for hackers and game players fond of mischievous pranks. Its followers became more politically focused, embracing an ideology of Internet freedom. In 2008, it made headlines with a campaign against the Church of Scientology, protesting what Anonymous claimed was the religious group's effort to control information about itself online.
The campaign included "denial-of-service" attacks—bombarding websites with data to try to knock them offline. Later attacks targeted the movie and music industries, because of their efforts to stop piracy.
In December, the group hit on a cause that propelled it into the spotlight: WikiLeaks. Anonymous began attacking organizations and people who tangled with WikiLeaks and founder Julian Assange, who had been arrested in London over sexual-misconduct allegations in Sweden, which he denies.
Anonymous attacks shut or slowed websites of businesses that had cut ties with WikiLeaks, including MasterCard Inc., Visa Inc. and PayPal, a unit of eBay Inc. All said their systems weren't compromised. PayPal said the attacks temporarily slowed payments via its website but not significantly.
The campaign, Operation Payback, brought Anonymous new followers from around the world. Via online chat forums and social-media websites, participants disseminated instructions about how to download attack software and about sites to target. Software called LOIC, or low-orbit ion canon, was downloaded tens of thousands of times, security specialists say.
Among recruits was Mr. Gonlag, under the nickname Awinee, an online handle the Dutch youth had used during a lifetime of intensive video-game playing. Spurred by talk of the WikiLeaks campaign in chat rooms, he piled in, at one point writing: "Fire, fire fire."
Mr. Gonlag has admitted he participated in attacks including one against the website of a Dutch prosecutor who announced the arrest of a 16-year-old in connection with the WikiLeaks campaign.
Returning home in the early hours of Dec. 10, Mr. Gonlag said in an interview, he typed the address of the prosecutor's website into the attack software and let his computer fire data for about half an hour. That afternoon, Dutch police arrested him and seized his desktop computer and phone.
Mr. Gonlag, who awaits trial, is charged with crimes related to destroying a computer network and inciting others to cause an attack, which carry a possible six years in prison.
Tapping at his keyboard recently in jeans and a green T-shirt, Mr. Gonlag said that he took part in several pro-WikiLeaks attacks, which he likened to a "digital sit-in," but that he wasn't guilty of the charges because he didn't destroy or steal anything.
He indicated he grew disenchanted as some arms of Anonymous allegedly moved from paralyzing websites to stealing from them, putting the group in "a very, very bad position."
Alluding to the cyber attacks he himself now faces, he said that when his computer server that powers the online chat rooms comes under fire, he takes the server offline and waits until his attackers tire of the effort. Then he connects back online again.
Each online Anonymous forum, such as AnonOps and AnonNet, has multiple chat rooms or "channels," typically focused on a particular operation or theme.
While there may be a hundred or so active followers of a network on a regular basis, numbers swell into the thousands during popular campaigns.
Many channels are public, but participants can also set up invitation-only chat rooms or send each other private messages. Participants often speak online using audio or camera software, and they also can share videos and other files. Many participants are U.S.-based but there is also a significant following in Europe and elsewhere.
Discussion ranges from political theory to technical chatter to juvenile banter. In one chat log, a participant promised to push a company "so far into orbit that they'll transmute into a gravitational dip and exude Hawking radiation."
Anonymous does have a hierarchy of sorts, with a core group of about 15 leaders who run the online chat rooms, participants say. They can issue sanctions, including banning someone from a channel or an entire network.
"There are nodes of power and authority, but it is pretty decentralized, and no one is calling the shots for all the operations," said Gabriella Coleman, an New York University academic who follows Anonymous.
The Anonymous attacks turned more ominous in February, when some members broke into HB Gary Federal's systems.
The Internet-security company's then-chief executive, Aaron Barr, noticed the problem one morning when he was unable to access corporate email via an iPhone.
He instantly suspected Anonymous, as he had been quoted in a newspaper article saying he had uncovered key participants. Soon, his Twitter account was hijacked and used to post racial slurs and his Social Security number. Then Anonymous announced it had hacked his email and would make the contents public.
"I was shocked and consumed by it," Mr. Barr said.
By hacking into the company's public Web page and stealing passwords, attack participants obtained about 70,000 emails, which they posted online. The traffic included details of a proposed effort to gather information on critics of the U.S. Chamber of Commerce in an attempt to prove illegal activity by labor-union members. Mr. Barr said the initiative was only intended to show what information could be retrieved.
The attackers also exposed minutiae of Mr. Barr's marital issues. He said the personal communications were taken out of context.
Mr. Barr stepped down from his job in late February.
Anonymous participants say the attacks expose weaknesses in the systems of computer-security companies and large organizations. "They should be scared," said Corey Barnhill, a 23-year-old New Jersey native who uses the online nickname Xyrix and who said he took part in the attack on HB Gary Federal. "You're college-educated and you can't secure a server? How hard is it? They can't keep a kid out?"
Mr. Barnhill said the HB Gary Federal hack was designed to teach Mr. Barr a lesson for suggesting he could unmask Anonymous. "Whacking him down a peg was pretty funny," he said.
In April, an Anonymous denial-of-service attack against Sony Corp. was followed by a breach of its computer system that resulted in the theft of names and birth dates and other personal information on about 100 million people who play online video games through Sony's online gaming services.
Sony shut down its PlayStation online network for nearly a month and has estimated the attack cost it $171 million, including costs for enhanced security.
Sony has said that it isn't clear that any credit-card data were ever accessed. The company said it has added security to its systems.
Sony told U.S. lawmakers it found a file left on its servers called "Anonymous," the contents of which said "We are Legion," a tagline often used by Anonymous.
Anonymous participants claim responsibility for the denial-of-service attacks, in press releases and via their Twitter account. They said the group didn't orchestrate the data breach but didn't rule out that someone from the group could have been involved. Meanwhile, the LulzSec group formed.
Security experts who follow LulzSec say it has about 10 core participants and is known for its hacking expertise. In recent weeks it has claimed responsibility for breaking into computer systems of several organizations, including the U.S. Senate and an FBI affiliate called InfraGard.
Last week, LulzSec said it had knocked the Central Intelligence Agency's website offline for about an hour. The CIA said no internal or classified networks were affected.
A call to a phone number set up by the group, 614-LULZSEC, wasn't returned. One LulzSec follower called "tflow" responded to a Wall Street Journal reporter in an online chat room, saying: "Unfortunately the gnomes are too busy to pick up your clearly inferior call."
"For the past month and a bit, we've been causing mayhem and chaos throughout the Internet, attacking several targets," LulzSec said in a statement last week. "This is the Internet, where we screw each other over for a jolt of satisfaction."
This week, LulzSec claimed to rat out a couple of individuals it said had "tried to snitch" on it. In a document addressed to the "FBI & other law enforcement clowns," the group appeared to reveal the full names, addresses and other contact information of two U.S. men it claims were involved in some hacks. "These goons begged us for mercy after they apologized to us all night for leaking some of our affiliates' logs," according to the document, accessed via a link on LulzSec's twitter page. "There is no mercy on the Lulz Boat."

Sunday, June 12, 2011

IMF State-Backed Cyber-Attack Follows Hacks of Atomic Lab, G-20

The data theft from International Monetary Fund computers by hackers said to be linked to a foreign government follows incidents against companies and governments that illustrate the growth of cyber-attacks as an espionage tool. The IMF hack resulted in the loss of a “large quantity” of data, including documents and e-mails, according to a person familiar with the incident, a security expert who declined to be identified because he wasn’t authorized to speak on the subject. This year, the Group of 20 and
Oak Ridge National Laboratory have also come under cyber-attack. The person said the intrusion was state-based, without saying which government is thought to be behind it. The Washington-based IMF approved a record $91.7 billion in emergency loans last year and provides a third of bailout packages in Europe. “The value of what’s being lost in these cyber-attacks is increasing at a very fast rate,” Sami Saydjari, the founder of Cyber Defense Agency in Wisconsin Rapids, Wisconsin, said in an interview this year before the latest attacks. “There are two perpetrators that are most concerning. One is organized crime, the other is nation-states, and they are both quite serious.” Google Inc.’s computer networks were broken into this month by hackers who gained access to the private Gmail accounts of senior U.S. officials. Defense contractor Lockheed Martin Corp. was hacked in May. Computers at Hopkinton, Massachusetts-based EMC Corp.’s RSA Security division were infiltrated in March by hackers who stole technology used to protect other U.S. government and corporate networks. Vocational School Google, based in Mountain View, California, traced the incursion on its networks to hackers at a vocational school associated with the Chinese military. Kevin Kempskie, an RSA spokesman, didn’t specify who was linked to the RSA attack. The same attackers used data stolen from RSA to gain access to Bethesda, Maryland-based Lockheed Martin’s computer network, RSA said this month. The pattern of the attacks against RSA and Lockheed Martin confirmed RSA’s suspicion that the hackers were seeking national security information and weren’t out for financial gain, according to RSA. David Hawley, an IMF spokesman, on June 11 declined to discuss details of the attack on the fund. Fund employees were alerted about hackers this month and “strongly requested not to open e-mails and video links without authenticating the source,” according to a copy of a staff memo provided to Bloomberg News. ‘Phishing Activity’ An e-mail from the IMF’s chief information officer, Jonathan Palmer, warned employees of “increased phishing activity.” Phishing is the practice of obtaining information such as computer user names or passwords under false pretenses. Palmer instructed employees on how to detect and respond to cyber-attackers, warning them not to divulge their passwords or open “unexpected documents.” According to one IMF memo, the fund’s network connection to the World Bank was severed “as a precautionary measure.” On June 1, the IMF’s information technology department sent an e-mail to employees with the subject line “Important Notice: Virus Attacks.” It warned of attempts to hack into the system. “Staff are strongly requested NOT TO OPEN e-mails and video links without authenticating the source,” the e-mail said. Anup Ghosh, chief executive officer of Invincea Inc., a Fairfax, Virginia-based cyber-security company, said the warning suggests computer worms were downloaded into the IMF’s networks through so-called spear phishing, which involves sending e-mails that appear to come from colleagues or other officials. He said the technique is associated with directed attacks for espionage. Oak Ridge In an attack on the Oak Ridge National Laboratory this year, a malicious program was downloaded through an e-mail purporting to come from the human resources department. Ten percent of the 570 recipients clicked on a link, infecting of several machines connected to the lab’s network, Ghosh said. The Tennessee-based lab was founded in 1943 to support the Manhattan Project and works with the U.S. Energy Department. In February, France’s budget minister, Francois Baroin, said the finance ministry was targeted in a cyber-attack aimed at stealing files on the G-20 summit in Paris. The attack was traced to Internet addresses in China, while there was no evidence it was directly linked to the Chinese government, the French publication Paris Match said at the time. Several countries are known to use hacking as a tool in espionage, including China, according to Mike Hayden, a former director of the Central Intelligence Agency. ‘Very Aggressive’ “China is a state that is very aggressive at collecting intelligence through these means,” Hayden said in an interview with Bloomberg News in February. “They are not bashful at all.” Google said this month that the latest breach of its network appeared linked to the same sophisticated attackers who broke into its computers and the computers of at least 20 other major U.S. companies in 2009 in what was known as Operation Aurora. Leaked U.S. diplomatic cables published by WikiLeaks said that attack was directed by high-level officials in the Chinese government security apparatus. Wang Baodong, a spokesman for the Chinese embassy in Washington, didn’t respond to a request yesterday for comment. “Our species has never put as much of its knowledge into the electromagnetic spectrum as it has now,” Hayden said. “Everything important exists out there in ones and zeroes.”