Lupa Kata Sandi? Klik di Sini

atau Masuk melalui

Belum Memiliki Akun Daftar di Sini


atau Daftar melalui

Sudah Memiliki Akun Masuk di Sini

Konfirmasi Email

Kami telah mengirimkan link aktivasi melalui email ke rudihamdani@gmail.com.

Klik link aktivasi dan dapatkan akses membaca 2 artikel gratis non Laput di koran dan Majalah Tempo

Jika Anda tidak menerima email,
Kirimkan Lagi Sekarang

Russian Agents, Hackers Charged in Massive Yahoo Breach

Translator

Editor

16 March 2017 12:46 WIB

Logo of Yahoo. REUTERS/Denis Balibouse

TEMPO.CO, Washington - Two Russian intelligence agents and a pair of hired hackers have been charged in a devastating criminal breach at Yahoo that affected at least a half billion user accounts, the Justice Department said Wednesday in bringing the first case of its kind against current Russian government officials.

In a scheme that prosecutors say blended intelligence gathering with old-fashioned financial greed, the four men targeted the email accounts of Russian and U.S. government officials, Russian journalists and employees of financial services and other private businesses, U.S. officials said.

Using in some cases a technique known as "spear-phishing" to dupe Yahoo users into thinking they were receiving legitimate emails, the hackers broke into at least 500 million accounts in search of personal information and financial data such as gift card and credit card numbers, prosecutors said.

"We will not allow individuals, groups, nation states or a combination of them to compromise the privacy of our citizens, the economic interests of our companies or the security of our country," said Acting Assistant Attorney General Mary McCord, the head of the Justice Department's national security division.

The case, announced amid continued U.S. intelligence agency skepticism of their Russian counterparts, comes as U.S. authorities investigate Russian interference through hacking in the 2016 presidential election. Officials said those investigations are separate.

One of the Yahoo-related defendants, a Canadian and Kazakh national named Karim Baratov, has been taken into custody in Canada. Another, Alexsey Belan, is on the list of the FBI's most wanted cyber criminals and has been indicted multiple times in the U.S. It's not clear whether he or the other two defendants, Dmitry Dokuchaev and Igor Sushchin, will ever step foot in an American courtroom since there's no extradition treaty with Russia.

"I hope they will respect our criminal justice system," McCord said.

The indictment identifies Dokuchaev and Sushchin as officers of the Russian Federal Security Service, or FSB. Belan and Baratov were paid hackers directed by the FSB to break into the accounts, prosecutors said.

Dokuchaev has been in custody in Russia since his arrest on treason charges in December, along with his superior and several others. Russian media have reported that Dokuchaev and his superior were accused of passing sensitive information to the CIA. The media reports also have contended that Dokuchaev was arrested by the FSB several years ago and offered a choice: serve a long prison sentence on hacking charges or sign a contract to work for the agency.

The FSB hasn't commented, and the Justice Department did not confirm that.

Yahoo didn't disclose the breach until last September when it began notifying hundreds of millions of users that their email addresses, birth dates, answers to security questions and other personal information may have been stolen. Three months later, Yahoo revealed it had uncovered a separate hack in 2013 affecting about 1 billion accounts, including some that were also hit in 2014.

U.S. officials said it was especially galling that the scheme involved officers from a Russian counterespionage service that theoretically should be working collaboratively with its FBI counterparts.

"Rather than do that type of work, they actually turned against that type of work," McCord said.

Paul Abbate, an FBI executive assistant director, said the bureau had had only "limited cooperation with that element of the Russian government in the past," noting that prior U.S. demands to turn over Belan had been ignored.

Though the U.S. government has previously charged individual Russian hackers with cybercrime — as well as hackers directly linked to the Chinese and Iranian governments — this is the first criminal case to name as defendants sitting members of the FSB for hacking charges, the Justice Department said.

U.S. intelligence authorities have concluded that Russian intelligence agencies were behind hacking efforts of Democratic email accounts in last year's election. Officials say this case is separate from that investigation, though one of the defendants in the Yahoo case, Belan, was among the Russians sanctioned last year by the Obama administration.

The indictment, which includes charges of economic espionage, trade secret theft and unauthorized access to protected computers, arise from a compromise of Yahoo user accounts that began at least as early as 2014.

The Justice Department's assertion that the FSB was directing the hacking likely provides political and legal cover for Yahoo, which saw its multibillion-dollar deal with Verizon teeter after it was forced to warn consumers that their private information might have been exposed.

Companies are more likely to be blamed for security incompetence when their networks are compromised by thieves or wayward teenagers than when they become the targets of sophisticated espionage carried out by foreign governments.

In a statement, Chris Madsen, Yahoo's assistant general counsel and head of global security, thanked law enforcement agencies for their work.

"We're committed to keeping our users and our platforms secure and will continue to engage with law enforcement to combat cybercrime," he said.

Rich Mogull, CEO of the security firm Securosis, said the indictment "shows the ties between the Russian security service and basically the criminal underground," something that had been "discussed in security circles for years."

Cyber criminals gave Russian officials access to specific accounts they were targeting, and in return, Russian officials helped the criminals to evade authorities and let them keep the type of information that hackers that hack for money tend to exploit such as email addresses and logins and credit card information.

"We've come to expect that you don't really figure out who performs these attacks," Mogull said. The fact that the indictment ties together the FSB and criminals is a new development, he said. "It will be very interesting to see what comes up in court, and how they tie those two together."

AP




Presidential Debate Series: Expert Warns of Rising Cyber Security Threats

3 Januari 2024

Presidential Debate Series: Expert Warns of Rising Cyber Security Threats

The upcoming presidential debate will discuss the theme of "Defense, Security, International Relations, and Geopolitics".


BSSN Deploys Cyber Task Force Ahead of Bali AIS Forum

9 Oktober 2023

BSSN Deploys Cyber Task Force Ahead of Bali AIS Forum

The National Cyber and Encryption Agency (BSSN) deployed a cyber security task force to ensure the implementation of the AIS Forum in Bali.


Today's Top 3 News: Jokowi's Cyber Security Strategy, Indonesia's Plan to Take World Bank Loan

4 Agustus 2023

Today's Top 3 News: Jokowi's Cyber Security Strategy, Indonesia's Plan to Take World Bank Loan

Tempo English compiles three popular news on the platform on Friday, August 4, including Kaspersky's comment on Indonesia's cyber security strategy.


Jokowi's Cyber Security Strategy Strengthens Indonesia Digital Landscape

4 Agustus 2023

Jokowi's Cyber Security Strategy Strengthens Indonesia Digital Landscape

Russian cyber security company Kaspersky comments on Jokowi's Regulation No. 47 of 2023 on the National Cyber Security Strategy.


34 Million Indonesian Passport Data Allegedly Leaked; Kominfo Responds

6 Juli 2023

34 Million Indonesian Passport Data Allegedly Leaked; Kominfo Responds

Kominfo Ministry confirmed that it has been informed about the alleged leak of 34,900,867 Indonesian citizens' passport data.


Indonesia's Digital Economy Growth Projected to Hit Rp3,216tn in 2027: Kadin

19 Juni 2023

Indonesia's Digital Economy Growth Projected to Hit Rp3,216tn in 2027: Kadin

Indonesian Chamber of Commerce and Industry (Kadin) predicted that the country's digital economy growth will reach Rp3,216 trillion in 2027.


BSSN, Huawei Tighten Synergy in Cyber Security Development

16 Juni 2023

BSSN, Huawei Tighten Synergy in Cyber Security Development

Indonesian Cyber and Encryption Agency (BSSN) renewed its MoU with Chinese telecom giant Huawei for cooperation in cyber security.


Data Belonging to Tax DG Leaked, Distributed Freely on Hacking Forum

3 Maret 2023

Data Belonging to Tax DG Leaked, Distributed Freely on Hacking Forum

Data allegedly belonging to the Finance Ministry's Directorate General of Tax were distributed freely on a hacking forum site.


Moeldoko Says Losses Caused by Hackers Hit $6tn

26 Oktober 2022

Moeldoko Says Losses Caused by Hackers Hit $6tn

Presidential Chief of Staff Moeldoko highlights financial losses caused by hackers and scammers in the digital world.


Kaspersky Reveals Web Attacks, Password Thefts Targeting Southeast Asian MSME

17 Oktober 2022

Kaspersky Reveals Web Attacks, Password Thefts Targeting Southeast Asian MSME

Russian cybersecurity company Kaspersky revealed malicious activities targeting MSMEs in Southeast Asia during the first half of 2022.