Russian hackers allegedly breach US government agencies in cyberattack
Multiple U.S. federal government agencies were hit in a global cyberattack allegedly carried out by the Russian ransomware gang known as Clop. The attack exploited a vulnerability in a file-sharing program popular among corporations and governments called MOVEit, per Homeland Security officials.
The US Cybersecurity and Infrastructure Security Agency is working to support the federal agencies that "experienced intrusions affecting their MOVEit applications," Eric Goldstein, the agency's executive assistant director for cybersecurity, told CNN on Thursday. "We are working urgently to understand impacts and ensure timely remediation."
While all the affected agencies have not been identified, a Department of Energy representative confirmed with CNN that the agency was among the targets. In addition to the U.S. government agencies, "several hundred" U.S. companies and organizations could have been swept up in the hacking spree, a senior CISA official estimated. In the past, Clop, the Russian ransomware gang allegedly behind the cyberattacks, has asked for multimillion-dollar ransoms. Still, the senior official added that the hackers made no demands in this case.
Subscribe to The Week
Escape your echo chamber. Get the facts behind the news, plus analysis from multiple perspectives.
Sign up for The Week's Free Newsletters
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
From our morning news briefing to a weekly Good News Newsletter, get the best of The Week delivered directly to your inbox.
The cyberattacks did not have any "significant impacts" on the federal agencies, CISA Director Jen Easterly said in a statement to the press, noting that the hackers were "largely opportunistic" in exploiting the software flaw to access networks.
Progress Software, the US creator of the MOVEit software, recently discovered another vulnerable point in the software. Over the past few weeks, the hackers have taken advantage of a previously identified flaw in the widely-used software to access the data they transferred. The firm behind the software told CNN they'd discovered a new vulnerability "that could be exploited by a bad actor."
"We have communicated with customers on the steps they need to take to further secure their environments, and we have also taken MOVEit Cloud offline as we urgently work to patch the issue," the company said in a statement.
Sign up for Today's Best Articles in your inbox
A free daily email with the biggest news stories of the day – and the best features from TheWeek.com
Theara Coleman has worked as a staff writer at The Week since September 2022. She frequently writes about technology, education, literature and general news. She was previously a contributing writer and assistant editor at Honeysuckle Magazine, where she covered racial politics and cannabis industry news.
-
What does the G20 summit say about the new global order?
Today's Big Question Donald Trump's election ushers in era of 'transactional' geopolitics that threatens to undermine international consensus
By Elliott Goat, The Week UK Published
-
What will Trump mean for the Middle East?
Talking Point President-elect's 'pro-Israel stance' could mask a more complex and unpredictable approach to the region
By Chas Newkey-Burden, The Week UK Published
-
Bermuda destination guide: exploring an island paradise
The Week Recommends From crystal caves to pink, sandy beaches, this hidden North Atlantic gem has much to offer
By Rebekah Evans, The Week UK Published
-
Racist texts tell Black people in US to prepare for slavery
Speed Read Recipients in at least a dozen states have been told to prepare to 'pick cotton' on slave plantations
By Peter Weber, The Week US Published
-
Australia proposes social media ban before age 16
Speed Read Australia proposes social media ban before age 16
By Peter Weber, The Week US Published
-
FTC bans fake online product reviews
Speed Read The agency will enforce fines of up to $51,744 per violation
By Peter Weber, The Week US Published
-
States sue TikTok over children's mental health
Speed Read The lawsuit was filed by 13 states and Washington, D.C.
By Rafi Schwartz, The Week US Published
-
Questions arise over the use of an AI crime-fighting tool
Under the Radar The tool was used in part to send a man to prison for life
By Justin Klawans, The Week US Published
-
Why Captchas are getting harder to solve
Under The Radar If the process continues to get harder, it could cause problems for people trying to book tickets for popular shows
By Chas Newkey-Burden, The Week UK Published
-
Amazon ending 'Just Walk Out' grocery checkout
Speed Read In its place, the company will let customers scan while they shop with Amazon Dash Cart
By Peter Weber, The Week US Published
-
Justice Department bites Apple with iPhone suit
Speed Read The lawsuit alleges that the tech company monopolized the smartphone industry
By Rafi Schwartz, The Week US Published