Latest episode, linked to Beijing involves data on 4 million Americans.Â
The latest massive computer hack suggests the Chinese had it right: it may be time for the U.S. to build a great wall to protect its data and that of 320 million Americans. Thatâs why the U.S. secretly expanded the National Security Agencyâs warrantless wiretapping program to root out hackers in 2012. But, as a rash of recent data breaches makes clear, the hackers retain the upper hand.
U.S. officials said Thursday they believe that Chinese hackers penetrated federal computer networks and plundered personal information on more than 4 million current and former U.S. workers. That makes it among the largest theft of U.S. government data in history, with federal officials warning the total could grow as their probe continues. U.S. officials said the hack appears similar to others that have been made into private companiesâ networks, including data on 80 million Americans pilfered from the Anthem insurance company, suggesting a widespread Chinese effort.
The Internet, made up of millions of computers and servers, only works if they can communicate easily with one another. Every password, firewall or other internal barrier built into the system to keep hackers out pushes it closer to grinding to a halt. Thatâs why, just like with your money, more valuable data is more heavily guarded. While the alleged Chinese hackers apparently got basic personal informationânames, addresses, Social Security numbersâthey apparently didnât get into tougher-to-access personnel files that contained sensitive information that is routinely collected during background checks.
The government used its Einstein anti-hacking system to detect the breach. The Department of Homeland Security calls it âan intrusion detection and prevention system that screens federal Internet traffic to identify potential cyber threats.â
The FBI is investigating the intrusion, which involved the federalOffice of Personnel Management, responsible for overseeing the personnel records of U.S. employees. The bureau believes the attack originated in China, but either lacks, or is unwilling to share, the evidence that pinpoints the nation. Attributing the source of such attacks is difficult, and the U.S. doesnât know if this one were carried out by the government, by some entity working for the government, or hackers independent of the government.
While U.S. officials have linked the thefts to China because of the peculiar hacking techniques and computer addresses involved, they havenât been able to come up with a motive. The data havenât shown up on the black market. China denied any role in the hack. âIf you keep using the words âmaybeâ or âperhapsâ without making a thorough study, this is irresponsible and unscientific,â Chinese Foreign Ministry spokesman Hong Lei said.
The U.S. hasnât been reticent about blaming Beijing for cyber attacks in recent years. In addition to this latest series of attacks, Beijing also downloaded terabytes of design data on the Pentagonâs $400 billion F-35 fighter program and other weapons, U.S. officials say. Theyâre also alleged to have stolen additional billions in intellectual property developed by U.S. companies.
âA great deal of what China, North Korea, Iran, and the vast majority of cyber-criminals and self-proclaimed hacktivists do isnât very sophisticated,â Stephanie OâSullivan, the principal deputy to Director of National Intelligence James Clapper, told an April cyber-security conference. They tend to exploit vulnerabilities in computer systems for which fixes exist but havenât been installed. âThe Chinese in particular are cleaning us out because we know weâre supposed to do these simple things and yet we donât do them,â she said. âMost Chinese cyber intrusions are through well-known vulnerabilities that could be fixed with patches already developed.â
Itâs not known if the latest attack exploited such a weakness, but one thing is certain: âGood basic security habits,â says Peter W. Singer of the New America Foundation, âwould stop over 90% of attacks.â































