For Russian journalists fighting hacks is part of the job

When news emerged that Kremlin-linked hackers attempted to breach The New York Times Moscow bureau, it probably didn't surprise any journalists working in Russia.

In fact, press freedom advocates say the Russian government constantly monitors independent journalists and aggressively attacks or shuts down controversial news sites.

"The Russian surveillance system is absolutely extensive," says Johann Bihr, who heads up the Eastern Europe and Central Asia desk for press advocacy group Reporters Without Borders. "The [Federal Security Service] has access to the servers of each and every internet server provider at the regional level, so it's quite easy for them to intercept any communication."

Recently, CNN reported that US officials were investigating attacks on Times reporters believed to be carried out by Russian hackers. But the Times subsequently said no systems were breached and it hadn't hired an outside security firm to investigate the incident, contrary to CNN’s report.

The Times' account lead some experts to suggest the apparent attack may have been a failed fraudulent email campaign aimed at the newspaper's office.

While Mr. Bihr said he would not be surprised if Russian spies targeted major US media outlets, he said Russia’s Federal Security Service (known as the FSB) typically takes aim at homegrown journalists.

"Usually [the FSB] is focusing their efforts on outlets that are digging into sensitive stories, such as what RBC were doing,” Bihr said, referring to Russia's largest independent media organization.

After RBC covered corruption allegations linked to President Vladimir Putin’s son-in-law in the Panama Papers leak, Russian authorities searched the offices of RBC's owner and began a criminal investigation examining the company's chief executive.

According to the World Press Freedom Index 2016 by Reporters Without Borders, Russia ranks 148 out of 180 countries. "The climate has become very oppressive for those who question the new patriotic and neoconservative discourse or just try to maintain quality journalism,” the report stated.

While hacking the email accounts of journalists may not be an everyday occurrence, many experts believe the FSB has access to all the communications data stored in Russia, which means gaining access to the emails of most journalists in Russia may be a trivial matter.

The FSB does run into roadblocks when western tech companies don't store data inside Russia. The Russian government is seeking to put pressure on Google and other tech giants such as Facebook and Twitter to store data within its borders, and while Google is believed to have moved some databases to Russian servers, most data remains outside of the government’s purview.

But the Kremlin also has many non-tech tools to clamp down on journalists.

Once a blog has more than 3,000 daily readers, the writes must register with the mass media regulator, Roskomnadzor, and abide by regulations that have been labeled "draconian" by Human Rights Watch.

Distributed denial of service (DDoS) attacks against independent publications that can render websites or blogs inaccessible for hours are also frequently linked to the Kremlin. These attacks typically take place during a major event such as a protest or election, and can serve to silence opposition voices.

Some hacktivist groups are beginning to fight back. The online collective Anonymous International recently hacked into the email accounts of journalists at the pro-government publication Life Media, revealing details of how government-funded operations work.

Many press and privacy organizations are also working to train journalists working in Moscow and elsewhere how to protect themselves from hackers.

“There is increased awareness of the risk of surveillance and increased awareness of the circumvention tools,” said Bihr of Reporters Without Borders. "Several NGOs and associations exist in Russia promoting these tools, but still I would say the general level of awareness is not huge."

CSMonitor

 

 

« Russian Cyber Spies & Hackers Are The New Normal
French Submarine Builder Admits Data-Warfare Breach »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Security Industry Association (SIA)

Security Industry Association (SIA)

The SIA's mission is to be a catalyst for success​ within the global security industry through information, insight and influence.

CANVAS Consortium

CANVAS Consortium

The CANVAS Consortium aims to unify technology developers with legal and ethical scholar and social scientists to approach the challenges of cybersecurity.

Silent Breach

Silent Breach

Silent Breach specializes in network security and digital asset protection. Services include Pentesting, Security Assessments, Incident Detection & Response, Governance Risk & Compliance.

CyberOwl

CyberOwl

CyberOwl builds on cutting-edge research and combines decades of experience in developing, securing and operating large distributed systems.

Slovenska Akreditacija (SA)

Slovenska Akreditacija (SA)

Slovenska Akreditacija (Slovenia Accreditation) is the national standards accreditation body for Slovenia.

GrrCON

GrrCON

GrrCON is an information security and hacking conference that provides the Midwest InfoSec community with a fun atmosphere to come together and engage with like minded people.

NSA Career Development Programs

NSA Career Development Programs

NSA offers entry-level programs to help employees enhance their skills, improve their understanding of a specific discipline and even cross-train into a new career field.

UMBRA

UMBRA

UMBRA is solely concerned with protecting governments against Nation State attacks. We are not a consumer or enterprise company.

Ukrainian Special Systems (USS)

Ukrainian Special Systems (USS)

Ukrainian Special Systems (USS) is a state-owned commercial enterprise providing confidential communication, trust services and services in the field of information protection.

SecureLogix

SecureLogix

SecureLogix deliver a unified voice network security and call verification solution. Protect against call attacks & fraud.

StrikeReady

StrikeReady

StrikeReady have developed CARA, an advanced technology solution that offers personalized and proactive assessment and remediation of future and current risk in real-time.

Cyber Command - Romania

Cyber Command - Romania

Cyber Command represents the military authority responsible for the development, protection and resilience of military IT networks and services that support the Romanian Force Structure.

Appsian Security

Appsian Security

Appsian provides powerful solutions that help organizations take control of their business critical data and financial transactions.

CySecK

CySecK

CySecK is a Centre of Excellence in Cybersecurity formed in 2017 by the Government of Karnataka, as part of the Technology Innovation Strategy.

B2Bcert

B2Bcert

B2BCERT one of the top companies offering ISO 9001, ISO 14001, ISO 45001, ISO 22000, ISO 27001, ISO 20000,CE Marking, HACCP, and other globally accepted standards and Management solutions.

RedArx Cyber Group

RedArx Cyber Group

At RedArx Cyber Group, our vision is to empower businesses with cutting-edge, proactive security solutions that safeguard their digital landscapes.

Cure53

Cure53

Cure53 offers classic black-box penetration tests (zero-knowledge) as well as white-box tests and code audits.

HCLTech

HCLTech

HCLTech is a global technology company delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products.