Feds Crack Down on Pernicious Chinese Hacking Group that Targeted U.S. Gov’t, Dissidents

Hacker mugshots

The U.S. on Monday announced actions aimed at exposing a sweeping Chinese hacking campaign that has targeted U.S. government institutions, critical infrastructure, media and political dissidents for more than a decade.

Wuhan Xiaoruizhi Science and Technology Company, Limited (Wuhan XRZ), served as a front company for China’s Ministry of State Security (MSS), which deals with overseas policing and espionage, allowing Chinese hackers to hide a multitude of malicious cyber operations, the Treasury Department said after sanctioning the organization on Monday in a statement alongside other U.S. agencies and the United Kingdom. In an indictment unsealed separately, the Department of Justice accused Chinese nationals Zhao Guangzong, Ni Gaobin and five others for their role “in furtherance of [China’s] economic espionage and foreign intelligence objectives” over the past 14 years.

Read the full story

Kari Lake, Mark Finchem Appeal Their Case Seeking to Ban Electronic Voting Machine Tabulators to the U.S. Supreme Court, Add New Evidence Including ‘False Statements’ by Defendants

Kari Lake and Mark Finchem

Kari Lake and Mark Finchem filed a Petition for Certiorari with the U.S. Supreme Court on Thursday, appealing the dismissal of their lawsuit against Arizona officials to stop the use of electronic voting machine tabulators. The 210-page petition added new allegations stating that the defendants lied to the court and that new evidence had surfaced exposing the vulnerabilities of the machines to bad actors.

“New evidence from other litigation and public-record requests shows defendants made false statements to the district court regarding the safeguards allegedly followed to ensure the accuracy of the vote, on which the district court relied,” the petition asserted. 

Read the full story

Beijing’s Military Hacked U.S. Nuclear Firm Before Hunter Biden Aided Chinese Bid to Acquire It

U.S. officials were acutely aware that Beijing was trying to obtain America’s premiere nuclear reactor technology, including through illicit hacking, months before Hunter Biden and his business partners sought to arrange a quiet sale of an iconic U.S. reactor company to a Chinese firm, according to court records and national security experts.

Read the full story

DOJ Announces ‘Disruption’ of Hacking Group That Targeted Fulton County, Georgia

Merrick Garland

The Department of Justice (DOJ) on Tuesday announced the “disruption” of a Russia-based hacking and ransomware group that targeted Fulton County last month as the result of a joint operation that involved both the Federal Bureau of Investigation (FBI) and “international law enforcement partners in London” to seize the group’s infrastructure.

In its press release, the DOJ announced “the disruption of the LockBit ransomware group, one of the most active ransomware groups in the world,” which came as the result of “seizing numerous public-facing websites used by LockBit to connect to the organization’s infrastructure and seizing control of servers used by LockBit administrators.”

Read the full story

‘We Can Not Back Down’: GiveSendGo Comes Back Online After Hackers Stole Donor Information

Crowdfunding service GiveSendGo came back online Tuesday after a Sunday hack forced the site to temporarily shut down.

“Sunday evening, February 13th, GiveSendGo was attacked by malicious actors attempting to eliminate the ability of its users to raise funds,” the company said in a statement posted to Twitter, acknowledging the hack publicly for the first time and announcing that the site was back online.

Read the full story

Federal Indictment Alleging Iranian Hack Further Erodes Narrative of Perfect 2020 Election

During the dizzying days after the November 2020 election, the Homeland Security cyber-security chief was fired by a frustrated President Donald Trump, then went on national TV to insist the election was fully secure.

“There was no indication or evidence that there was any sort of hacking or compromise of election systems on, before or after November 3,” ex-Cyber-Security and Infrastructure Agency Chief Chris Krebs declared on “60 Minutes.”

On Thursday, nearly a year later, federal prosecutors in New York unsealed a dramatic indictment that conflicts with that clean bill of health.

Read the full story

Hackers Allegedly Breach Nine Companies Involved in Defense, Energy, and Other Vital Sectors

Ryan Olson

A security firm claims that foreign hackers have infiltrated at least nine companies in several crucial sectors of the economy and government, including defense, energy, technology, and others, according to CNN.

Palo Alto Networks (PAN) shared the information on the breaches with CNN, showing that other affected sectors include education and healthcare. They say that the National Security Agency (NSA) is working with cybersecurity researchers to expose this and other ongoing efforts by foreign entities to hack American infrastructure. PAN’s report included information contributed by a division of the NSA which focuses exclusively on threats against American industrial defense bases by foreign hackers.

Examples of the breaches include the inconspicuous theft of passwords, with the goal of using these passwords to remain inside these networks for a prolonged period of time without anyone even being aware that there was a breach. This would allow hackers to freely receive sensitive data sent over basic communications such as email or information contained on internal storage drives.

Read the full story

Hackers Steal Customer Information in McDonald’s Cyberattack

McDonald's at sunset

Hackers obtained customer data from McDonald’s after breaching the company’s systems in the U.S., South Korea and Taiwan, according to The Wall Street Journal.

U.S. employees’ and franchisees’ contact information, seating capacity of U.S. locations and the dimensions of play areas at restaurants in the U.S were all exposed during the breach, McDonald’s said Friday, The Wall Street Journal reported. While McDonald’s said the hack didn’t cause disruptions at any of its locations, it vowed to launch an investigation into the breach and continue to invest in bolstering its cybersecurity protocol.

“McDonald’s will leverage the findings from the investigation as well as input from security resources to identify ways to further enhance our existing security measures,” the global fast food chain told U.S. employees in an internal message, according to the WSJ.

Read the full story

Hacker Accessed D.C. Donor Information from Virginia Hospital Center For Months

An unauthorized party accessed donor and fundraiser information for months from Virginia Hospital Center (VHC), who has served the Washington, D.C. area for 75 years. The company, Blackbaud, also reported many of its other clients’ donor and fundraising data jeopardized by the hackers.

VHC stored donors’ personal information. This included names, addresses, phone numbers, email addresses – even birth dates and the last four digits of credit card numbers. Hackers had access to these records for approximately three months, from February to May. However, the last traces of hacking didn’t cease until early June.

Read the full story

Massive Plot Stole Data from Google Users Who Downloaded Free Add-Ons to Chrome Web Browsers: Report

A massive spyware effort targeted users of Google’s Chrome web browser extensions downloaded tens of millions of times, Reuters reported Thursday.

The people responsible for the spyware attacked users through 32 million downloads of extensions to Google’s web browser, and collected browsing history and other user data, researchers at Awake Security told Reuters. Google removed more than 70 malicious extensions after researchers alerted the company of the attack in May, the company said.

Read the full story

Hacks and Facts: 10 Things to Know About Data Privacy

Reuters   From hackers exposing private information online to the handling of users’ data by internet giants, online privacy has become a matter of growing concern for countries, companies and people alike. On Monday, countries around the world marked Data Privacy Day, also known as Data Protection Day — an initiative to raise awareness of internet safety issues. Here are 10 facts about online privacy: (1) Less than 60 percent of countries have laws to secure the protection of data and privacy. (2) Europe’s data protection regulators have received more than 95,000 complaints about possible data breaches since the adoption of a landmark EU privacy law in May. (3) More than one in two respondents to a 2018 global survey by pollster CIGI-Ipsos said they had grown more concerned about their online privacy compared to the previous year. (4) Almost 40 percent of respondents to another survey by cybersecurity firm Kaspersky Lab said they did not know how to protect themselves from cybercrime. (5) A survey of tech professionals by security key maker Yubico suggested experts might not live up to safety standards. It found almost 70 percent of respondents shared passwords with colleagues. (6) More than half reused an…

Read the full story