Times Online and AP
Win a trip to the Ice Hotel in Lapland
The US State Department has revealed that hackers stole data from its network after an employee in Asia opened a mysterious e-mail that allowed them to break into the government’s computer system.
The security breach happened last summer but details have not been revealed until now. A senior State Department official said that sophisticated international hackers had used an elaborate ploy to exploit a design flaw in Microsoft software. Consumers using the same software remained vulnerable until months afterward.
Donald R. Reid, the senior security coordinator for the Bureau of Diplomatic Security, also confirmed that a limited amount of US Government data was stolen by the hackers before tripwires severed all the State Department’s internet connections throughout eastern Asia. The shut-off left government offices without web access in the weeks preceding missile tests by North Korea.
Mr Reid is expected to tell a congressional cybersecurity hearing today that an employee in the State Department’s Bureau of East Asian and Pacific Affairs opened an e-mail message in late May that gave hackers access to the government’s network.
He is not expected to disclose the identities or nationalities of the hackers believed to have been responsible for the break-ins, or to disclose whether American authorities believe a foreign government was responsible.
Bennie Thompson, the chairman of the Homeland Security Committee, said hackers are no longer considered harmless, bored teenagers: “These are experienced, sophisticated people who are trying to exploit our vulnerabilities and gain access to our information.”
The mysterious State Department e-mail appeared legitimate and included a Microsoft Word document with material from a congressional speech related to Asian diplomacy, Mr Reid said. By opening the document, the employee activated hidden software commands establishing what Mr Reid described as backdoor communications with the hackers.
The technique exploited a previously unknown design flaw in Microsoft’s Office software, Reid said. State Department officials worked with the Homeland Security Department and even the FBI to urge Microsoft to develop a protective software patch, but the company did not offer the patch until August 8, about eight weeks after the break-in.
Microsoft said it works as quickly as it can to provide customers with security updates. “If we release a security update that is not adequately tested, we could potentially put customers at risk, especially as the release of an update can lead to reverse-engineering the fix and lead to broader attacks,” Phil Reitinger, Microsoft’s senior security strategist, said. “Updates must be able to be deployed by customers with confidence.”
At the time, Microsoft described the software flaw as “a newly discovered, privately reported vulnerability,” but did not suggest any connection to the US government break-in. It recommended that consumers should not open or save Microsoft Office files they receive from sources they do not trust or files they receive unexpectedly from trusted sources.
The State Department detected its first break-in immediately, Mr Reid said, and worked to block suspected communications with the hackers. During its investigation, however, it discovered new break-ins at its Washington headquarters and other offices in East Asia.
At first, the hackers did not appear to be trying to steal government data and the authorities quietly monitored the hackers’ activity. Then tripwires severed internet connections in the region after a limited amount of data was detected being stolen, Mr Reid said.
He also complained the State Department’s efforts to deal quietly with the break-in were disrupted by news reports. “We were successful here until a newspaper article telegraphed what we were dealing with,” he said.
Industry sectors news at a glance. Interactive heatmap, video and podcast
The inside track on current trends in the charity, not for profit and social enterprise sectors
Read our exclusive 100 Years of Fleming and Bond interactive timeline, packed with original Times articles and reviews
Everything the Business Traveller needs to know to make a better trip
Shortcuts to help you find sections and articles
05/2005
£13,500
08/2008
£109,950
2005 / 55
£59,500
Great car insurance deals online
£Excellent+ executive benefits
Torres and Partners
London
£49,229 - £62,035 pro rata
Charity Commission
London/Liverpool/Taunton
Alstom Power
Europe
Six Figure
Rolls Royce
Midlands/Europe
From £89,950
Special Offers now available
At the new sophisticated
Encore Las Vegas Resort!
Cruise the Islands of Hawaii - Pride of America
List your property with two leading travel websites
Great travel insurance deals online
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times, or place your advertisement.
Times Online Services: Dating | Jobs | Property Search | Used Cars | Holidays | Births, Marriages, Deaths
News International associated websites: Globrix | Property Finder | Milkround
Copyright 2008 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.
Monroe - You're obviously not the sharpest stick in the box. Just because an agency or department is federally funded, it doesn't mean that everybody has free reign to its access. Some of the data, even if it is unclassified, is not for public consumption and is for official use only. Have someone hit you in the head with a clue by four before you compose your next posting.
Eric Richter, Los Angeles, California
There is no privacy anymore. Why should this surprise anyone?
Kim Righetti, Upland, Calif. USA
Monroe, reflect on the fact that there are state secrets and sensitive documents that were procured/developed with "public funds" that are most certainly NOT for public consumption.
Devil's Advocate, San Francisco, CA
This is all publicly acquired information and should therefore be openly available to anyone. That someone would have to go to all the trouble of stealing publicly paid for information is despicable! The state department officials that perpetrate this 'practice' should be prosecuted to the full extent of the law for misuse of public funds!
Monroe Jeffrey, Los Angeles, CA