Russian hackers who pose threat to US election have breached nuclear plants, power grid in the past
The timing of the attacks so close to the election and the potential for disruption set off concern inside private security firms, law enforcement and intelligence agencies


A file image of an election worker arranging returned ballots from a sorting machine at the King County Elections office in Renton, Washington. US officials recently said that Russian hackers have targeted the networks of dozens of state and local governments in the United States in recent days, stealing data from at least two servers. AP[/caption]And it has done so with remarkable success. A disturbing screenshot in a 2018 Department of Homeland Security advisory showed the groups’ hackers with their fingers on the switches of the computers that controlled the industrial systems at a power plant.The group has thus far stopped short of sabotage but appears to be preparing for some future attack. The hackings so unnerved officials that starting in 2018, the US Cyber Command, the arm of the Pentagon that conducts offensive cyberattacks, hit back with retaliatory strikes on the Russian grid.Some called the counterattacks the digital era’s equivalent of mutually assured destruction. But any hope that US officials had that their strikes would deter Russia dissipated when the group started targeting American airports in March.Officials at San Francisco International Airport discovered Russia’s state hackers had breached the online system that airport employees and travelers used to gain access to the airport’s Wi-Fi. The hackers injected code into two Wi-Fi portals that stole visitors’ user names, cracked their passwords, and infected their laptops.The attack began on 17 March and continued for nearly two weeks until it was shut down. By then, officials at two other airports discovered their Wi-Fi portals had also been compromised. Researchers would not name the other victims, citing nondisclosure agreements, but said they were on the West Coast.As pervasive as the attacks could have been, researchers believe Russia’s hackers were interested only in one specific person traveling through the airports that day.“Ostensibly, hundreds of thousands of people could have been compromised,” said Eric Chien, a cybersecurity director at Symantec, who examined the attack. “But only 10 were.”Chien’s team discovered that the hackers were “fingerprinting” the machines of anyone who logged onto the Wi-Fi network in search of one older version of Microsoft’s Internet Explorer browser. If they found a match, the hackers infected those laptops. If the Wi-Fi visitors used any other browser, the hackers left them alone.“From what we could see, they were going after a specific individual,” Chien said.In the government alert on Thursday, officials said that the Russian group was again targeting aviation systems. It did not name the targets but did suggest in some technical language that one could have been the airport in Columbus, Ohio.In a previous homeland security warning about the group, officials said it “targets low security and small networks to gain access and move laterally to networks of major, high-value asset owners within the energy sector".Security researchers warned that the spate of attacks on American state and local systems could mirror the trajectory of those attacks: Russia’s hackers using their foothold in seemingly random victims’ networks to mine for more interesting targets closer to the election on 3 November. They could take steps like pulling offline the databases that verify voters’ signatures on mail-in ballots or given their particular expertise, shutting power to key precincts.“The most disconcerting piece is that it demonstrates Russia’s intent and ability to target systems near and dear to us, but that shouldn’t surprise us,” said Frank Cilluffo, the director of Auburn University’s McCrary Institute for Cyber and Critical Infrastructure Security.By deputising the FSB’s stealthiest infrastructure hackers to target state and local systems, some security experts believe Russia may be hedging its bets.If, for example, Putin believes US president Donald Trump will be re-elected and wants to forge a better relationship with the United States, he may want to limit the degree to which Russia is seen as interfering.Likewise, the experts said, if former Vice President Joe Biden, the Democratic nominee, is elected, Russia may try to use its foothold in the systems to weaken or delegitimise him, or it may hold back so as not to provoke the new administration.“By doing this more quietly, you give yourself more options,” Spaulding said.Campbell Robertson, Edgar Sandoval, Lucy Tompkins and Simon Romero c.2020 The New York Times Company

US set to sign Saudi nuclear deal; Rubio says pact won't fuel proliferation
India-US trade deal 'almost complete', says US after Jaishankar-Rubio talks in Manila
Marco Rubio says he 'would expect India to be concerned' over Trump's pharma tariffs
Trump renews China election interference claims, but files point to Russia's larger role
'See me after class!': UK education secretary Lucy Powell mocked by Tories over grammar gaffe
