We Are In A New Era Of Espionage

Michael Morell, (pictured) the former acting director of the CIA, was asked about the intelligence community’s findings that Russia interfered in the US presidential election. His answer was unequivocal: The country isn’t grasping the magnitude of the story, he told The Cipher Brief. “To me, and this is to me not an overstatement, this is the political equivalent of 9/11.”

Morell’s comments went even further than what members of Congress, mostly Democrats, have been saying for months: that the Russian-directed cyberattacks are an unprecedented attack on American democracy.

In the heat of moment, it’s easy to lose sight of the context around the Russian hacking operation. In spite of the distinctive 21st-century flavor of the digital intrusions, the data breaches that affected Democrats are just a modern example of routine country-on-country spying.

What sets them apart, though, is the high profile of their mark, an American presidential election, and the hackers’ willingness to leak stolen information to influence voters’ opinions. Altogether, it’s perhaps one of the greatest examples of a successful espionage operation in history.

It’s useful to think of the operation as two distinct parts, says Vince Houghton, the International Spy Museum’s historian and curator. The first part, intrusions into the computer systems of the Democratic National Committee and the personal email of Hillary Clinton’s senior campaign manager, John Podesta, was intelligence-gathering, plain and simple.

It’s the sort of activity that every spy agency in the world engages in on a routine basis. Once, this required rifling through others’ mail; later, as technology progressed, it involved tapping phones, and now, it can be done with a well-crafted phishing email.

The second part can be thought of as an enormous, state-on-state doxing-operation. Instead of sitting on the information stolen from the Democrats and using it to inform its policy positions and predict the US government’s moves and motives, the Kremlin appears to have gone one (giant) step further, releasing that information into the wild.

The US intelligence community has determined that publishing hacked documents through WikiLeaks, DCLeaks.com, and Guccifer 2.0 is “consistent with the methods and motivations of Russian-directed efforts.” NBC News and ABC News reported that Russian President Vladimir Putin was personally involved in directing the operation.

This is where things start to wander into uncharted territory, according to Houghton and Gordon Corera, the BBC’s security correspondent and the author of the espionage-history book, Cyberspies.

The release of the surreptitiously gathered information, either to tip an election in one direction or just to sow disorder, is novel, especially in the context of American elections. During the 2008 and 2012 cycles, political campaigns came under cyberattack, but if anything was stolen, it was never shared with the public.

Despite the unique nature of this intervention, the 2016 cyberattacks square with Russian intelligence techniques reaching as far back as the Cold War.

It’s an evolution of the Soviet Union’s “active measures,” a tactic favored by the KGB that involved covertly spreading politically damaging fictions in order to seed discord in an enemy.

Given the CIA’s history, it’s not a stretch to assume that the agency is regularly taking covert action overseas, including around elections. Shortly after the CIA was established in 1947, its agents poured money, propaganda, and even threats into Italy during its national elections, for example, in order to keep communist-aligned politicians from coming to power.

In 1953, the CIA teamed up with its British counterpart, MI6, to overthrow Iranian Prime minister Mohammed Mossadegh and reinstate the Shah, who had been pushed out of power. And in the years since, it’s intervened repeatedly in other countries’ affairs.

Part of the reason Russia’s alleged meddling this year seems so shocking is because the tables have turned. “We’ve bought and sold elections in the past,” says Houghton. “But now it’s happening to us, and, as an American, that’s different to me.”

Even if Russia did aim to help Trump win the election, it’s not clear how big a role the publication of the stolen documents played in swaying voters. But the intrusions certainly created confusion and chaos, and that may be just as useful to the Kremlin. Internal fractionalisation could distract the US and allow Russia to act even more boldly on the international stage without fearing American repercussions.

“Here, you have an information campaign that’s now pitting the CIA against the FBI, Democrats against Republicans, even Republicans against Republicans. This is perfection. Perfection!” exclaimed Houghton. “It’s just right out of the playbook.”

At this point, there’s no indication, beyond unsubstantiated claims from outgoing Senate Democratic Leader Harry Reid, that the Trump campaign coordinated with Russia, even if it benefited from its actions. The details about Russia’s aims aren’t entirely clear, because the CIA has found itself at odds with the FBI over its assessment that the Kremlin tried to help Trump out.

One of the key elements of the CIA’s determination, the claim that the Republican National Committee was hacked, too, but that Russian leaders chose not to leak any of that information, is beginning to look more likely. If it turns out to be true, the Trump administration may find itself in a bind going forward.

More information about the cyberattacks is forthcoming: President Obama ordered a review of election-related hacking, and Congress is launching multiple investigations into the developments as well.

Unless the probes turn up obvious evidence of collusion between Trump’s team and the Russian hackers, it’s unlikely the president-elect will face any repercussions. The reviews will, however, help inform how high-profile cyberattacks will be treated in the future. President Obama reportedly chose not to respond forcefully to Russian hacking, preferring instead to rebuke Putin in private on the sidelines of at a Group of 20 summit in China, The New York Times reported.

So far, it appears that Russia has gotten away with meddling in a US election. That may send a message to other countries that the US won’t lash out after it comes under cyberattack if it’s not politically convenient to do so. But it may also be that the US government just chose not to retaliate in a public way.

The uncertainty surrounding cyberwar norms has a lot to do with how new the phenomenon is. Houghton compared it to the advent of nuclear weapons, when members of Congress struggled to grasp the impact the nuclear age would have on diplomacy and war. Eventually, Houghton said, we’ll look back on 2016 to try and understand the beginnings of the era defined by online warfare.

“This is going to be something that we’ll study for a long time,” he said.

DefenseOne:           Yes, Russia Weaponised Social Media In The US Elections:

 

« Healthcare Data Breaches In 2017 Will Get Worse
Decent Broadband 'denied' To Millions »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 8,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

TSUNAMI

TSUNAMI

The TSUNAMi center focuses on software and system security and how trustworthy software can be built from COTS software components.

Oodrive

Oodrive

Oodrive is the first trusted European collaborative suite allowing users to collaborate, communicate and streamline business with transparent tools that ensure security.

Kount

Kount

Kount's “decision engine” platform is ideal for managing fraud in online/telephone channels that process payments and onboard new customers.

Fornetix

Fornetix

Fornetix is a cybersecurity platform enabling Zero Trust while delivering critical encryption automation, access controls, authorization services, machine identity, and ICAM solutions,

Critifence

Critifence

Critifence provides unique Cyber Security solutions designed for Critical Infrastructure, SCADA and Industrial Control Systems.

MAY Cyber Technology

MAY Cyber Technology

MAY Cyber Technology is a Security Management solutions provider located in Turkey & Germany.

OEDIV SecuSys

OEDIV SecuSys

OEDIV SecuSys (formerly iSM Secu-Sys) develops high-quality IT software solutions, setting standards as a technology leader in the area of identity and access management.

Kuratorium Sicheres Österreich (KSO)

Kuratorium Sicheres Österreich (KSO)

KSO is an independent non-profit association that has set itself the goal of making Austria safer as a national networking and information platform for topics of internal security.

Black Hills Information Security (BHIS)

Black Hills Information Security (BHIS)

Black Hills Information Security provide security testing and vulnerability assessment services.

DataEndure

DataEndure

DataEndure helps companies build digital resilience so that their critical information assets are protected and available to the right people, at the right time.

Boxphish

Boxphish

Boxphish provides a proven solution to reduce Human Error and Cyber Human Risk via automated learning journeys and intelligent phishing simulations.

UST

UST

UST is a global provider of digital technology and transformation, IT services and solutions including managed security services.

Maritime Cyber Threats Research Group - University of Plymouth

Maritime Cyber Threats Research Group - University of Plymouth

The Maritime Cyber Threats research group of the University of Plymouth is focused on investigating marine cyber threats and researching solutions.

Interos

Interos

Interos is the operational resilience company — reinventing how companies manage their supply chains and business relationships — through a breakthrough AI SaaS platform.

Acumera

Acumera

Acumera is a leader in managed network security, visibility and automation services.

Astreya

Astreya

Astreya is the leading IT solutions provider for some of the world's most recognizable and innovative organizations.