Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Wednesday, March 28, 2018

Russia blamed for attacks on U.S. power grid starting in 2016

The Trump administration has blamed the Russian government for a series of cyber attacks targeting American and European nuclear power plants and other critical utilities dating back at least two years – raising fears that the Kremlin could disrupt the West’s critical infrastructure in the event of a conflict.


The hackers also targeted the overall energy sector, along with commercial facilities, aviation, manufacturing and the water supply, according to a U.S. security alert published Thursday.



The Department of Homeland Security and FBI said in the alert that a “multi-stage intrusion campaign by Russian government cyber actors” had targeted the networks of small commercial facilities “where they staged malware, conducted spear phishing, and gained remote access into energy sector networks.” The alert did not name facilities or companies targeted. –Reuters



The report says that Russians used various hacking techniques, including spear-phishing emails, watering-hole domains, credential gathering and open-source and network reconnaissance.



Russian hackers made their way to machines with access to critical control systems at power plants that were not identified. The hackers never went so far as to sabotage or shut down the computer systems that guide the operations of the plants.


Still, new computer screenshots released by the Department of Homeland Security on Thursday made clear that Russian state hackers had the foothold they would have needed to manipulate or shut down power plants. –NYT



“We now have evidence they’re sitting on the machines, connected to industrial control infrastructure, that allow them to effectively turn the power off or effect sabotage,” said Eric Chien, a security technology director at Symantec, who added “From what we can see, they were there. They have the ability to shut the power off. All that’s missing is some political motivation.”


The New York Times notes that “American officials and security firms, including Symantec and CrowdStrike, believe that Russian attacks on the Ukrainian power grid in 2015 and 2016 that left more than 200,000 citizens there in the dark are an ominous sign of what the Russian cyberstrikes may portend in the United States and Europe in the event of escalating hostilities.”


Meanwhile, Thursday’s announcement from DHS marks the first official claim that the Kremlin attacked the power grid.



It was the first time the administration officially named Russia as the perpetrator of the assaults. And it marked the third time in recent months that the White House, departing from its usual reluctance to publicly reveal intelligence, blamed foreign government forces for attacks on infrastructure in the United States. –NYT



Vikram Thakur of Symantec Security Response said that gaining access to networks tied to various segments of U.S. infrastructure is extremely difficult, adding that cyberattacks like the ones described in the DHS announcement have the potential to cause significant damage.


“The only thing that holds an attacker back is political motivation,” Thakur told CNN, adding “Usually the bar for flipping the switch is extremely high.”


The announcement coincided with the U.S. Treasury Department’s Thursday decision to slap sanctions on 19 Russians and five groups – including the Kremlin’s intelligence services for meddling in the 2016 U.S. presidential election, along with various other cyber crimes.


Russia has previously denied the charges.


In December, 2016 the Washington Post erroneously reported that Russian hackers had penetrated the electric grid in Vermont using malicious code associated with the hacking operation dubbed “Grizzly Steppe” by the Obama administration. WaPo corrected the story 48 hours later with the publication of a new article.


Last July, however, the Department of Homeland Security reported that the Wolf Creek Nuclear Operating corp in Kansas had been targeted by hackers in one of several breaches of U.S. nuclear plants. Hackers were thought to be mapping out computer networks for future attacks, according to the Times.


That said, there has been a fair amount of pushback against the administration’s claims of Russian hacking by both the Wolf Creek plant and the Nuclear Energy Institute.



Spokeswoman Jenny Hageman declined to say at the time if the plant had been hacked but said that there had been no operational impact to the plant because operational computer systems were separate from the corporate network.Hageman on Thursday said the company does not comment on security matters.


John Keeley, a spokesman for the industry group the Nuclear Energy Institute, said: “There has been no successful cyber attack against any U.S. nuclear facility, including Wolf Creek.” –Reuters



Meanwhile, watch out – China is beefing up their cyberweapons


Via Zero Hedge 




Featured Image: Emmanuel Huybrechts/Flickr

The post Russia blamed for attacks on U.S. power grid starting in 2016 appeared first on Intellihub.

Tuesday, February 6, 2018

Wednesday, November 15, 2017

Americans ‘Should Assume’ Their Tax Returns Can Be Hacked From The IRS, Expert Says

Americans ‘Should Assume’ Their Tax Returns Can Be Hacked From The IRS, Expert Says

Image source: Flickr / Creative Commons


Nov. 15, 2017


No one’s financial information is safe from hackers at the Internal Revenue Service — not even President Trump’s.


That’s according to fraud investigator John Powers, who suspects Trump’s tax returns have been stolen from the IRS. Powers also believes that expert hackers could take anybody’s data from the agency if they wanted it.


Discover How To Become Invisible In Today’s Surveillance State!


“Considering Trump’s risk profile, the determination of his detractors, and the current state of cybersecurity, it’s almost inconceivable his tax returns haven’t been hacked—successfully—by someone with more experience and expertise,” Powers wrote in Wired on Sunday.


“After all, American taxpayers should assume their personally identifying information is already in the hands of criminals and then act accordingly, as former IRS commissioner John Koskinen recently told reporters.”


Koskinen said: “Our estimate is a significant percent of those taxpayers already had their information in the hands of criminals.”


Powers is a certified fraud investigator who has coordinated investigations with the FBI, U.S. Attorney’s Office, the Department of Homeland Security, and the Securities and Exchange Commission (SEC). He has had 20 years of experience and now heads up Hudson Intelligence in New York.


Powers noted that:


  • The IRS awarded a contract to Equifax for fraud protection services. Equifax is the credit bureau that lost data from about 145 million people to hackers earlier this year.

  • Fraudsters were able to steal data from about 100,000 taxpayers and $30 million by hacking an IRS tool for students seeking financial aid.

  • A Louisiana private investigator named Jordan Hamlett may have come close to stealing Trump’s tax returns – and he wasn’t even an expert hacker.

Powers surmises that hackers have seen Trump’s tax returns but haven’t released it because there is nothing there.


“Maybe the tax returns just aren’t that juicy,” he wrote.


What is your reaction? Share it in the section below:

Thursday, September 21, 2017

A “Contagious” Bluetooth Flaw Makes ALL Your Connected Devices Hackable

A “Contagious” Bluetooth Flaw Makes ALL Your Connected Devices Hackable | A-New-Bluetooth-Flaw-Makes-ALL-Your-Connected-Devices-Hackable | Science & Technology Special Interests


In case you don’t have enough to worry about with hackers getting into our power grids, cyber attacks taking down entire countries, and epic natural disasters, a newly discovered Bluetooth flaw makes nearly all devices that are connected subject to hackers.


Tech Republic reports:


BlueBorne is an attack vector that could affect billions of devices. If you’re running IoS, Android, Windows, and even Linux, your devices could be at risk.




Using BlueBorne, hackers can attack Bluetooth-connected devices over the air, without the device even being paired to the attacker’s device, the post said. Once successfully penetrated, the attacker gains full control over the victim’s device.


So far, Armis Labs has identified eight zero-day vulnerabilities associated with BlueBorne. However, as noted in the post, the firm believes there could be “many more” vulnerabilities waiting to be discovered. BlueBorne can conduct remote code execution and Man-in-The-Middle attacks, for example…


Because BlueBorne is airborne, and can spread from device to device, it is considered “highly infectious” by the researchers. It’s airborne nature also means that it is often targeting the weakest spot in the defense strategy for most modern networks…


The method through which BlueBorne spreads allows it to infect air-gapped networks as well, which was a major concern for the researchers. Additionally, it takes minimal effort on behalf of the attacker, requires no victim interaction, and can remain undetected in many systems…(source)



This makes all of your connected devices vulnerable to cyber espionage, data theft, and ransomware. If your passwords are saved for your bank or credit accounts, you can be easily hacked due to this vulnerability. Anything on your devices is under the control of the hackers.


The report by Armis Security calls this a “comprehensive and severe threat.”



The BlueBorne attack vector requires no user interaction, is compatible to all software versions, and does not require any preconditions or configurations aside of the Bluetooth being active. Unlike the common misconception, Bluetooth enabled devices are constantly searching for incoming connections from any devices, and not only those they have been paired with. This means a Bluetooth connection can be established without pairing the devices at all. This makes BlueBorne one of the most broad potential attacks found in recent years, and allows an attacker to strike completely undetected. (source)



These devices have the potential to be hacked with the Bluetooth flaw


Armis warns that the following devices could be hacked with BlueBorne. And warning, it’s nearly every device out there.



Android


All Android phones, tablets, and wearables (except those using only Bluetooth Low Energy) of all versions are affected by four vulnerabilities found in the Android operating system, two of which allow remote code execution (CVE-2017-0781 and CVE-2017-0782), one results in information leak (CVE-2017-0785) and the last allows an attacker to perform a Man-in-The-Middle attack (CVE-2017-0783).


Examples of impacted devices:



  • Google Pixel




  • Samsung Galaxy




  • Samsung Galaxy Tab




  • LG Watch Sport




  • Pumpkin Car Audio System




Google has issued a security update patch and notified its partners. It was available to Android partners on August 7th, 2017, and made available as part of the September Security Update and Bulletin on September 4, 2017. We recommend that users check that Bulletin for the latest most accurate information. Android users should verify that they have the September 9, 2017 Security Patch Level,Note to Android users: To check if your device is at risk or is the devices around you are at risk, download the Armis BlueBorne Scanner App on Google Play.




Windows
All Windows computers since Windows Vista are affected by the “Bluetooth Pineapple” vulnerability which allows an attacker to perform a Man-in-The-Middle attack (CVE-2017-8628).



Microsoft issued has security patches to all supported Windows versions on July 11, 2017, with coordinated notification on Tuesday, September 12. We recommend that Windows users should check with the Microsoft release at here for the latest information.





Linux
Linux is the underlying operating system for a wide range of devices. The most commercial, and consumer-oriented platform based on Linux is the Tizen OS.




  • All Linux devices running BlueZ are affected by the information leak vulnerability (CVE-2017-1000250).




  • All Linux devices from version 3.3-rc1 (released in October 2011) are affected by the remote code execution vulnerability (CVE-2017-1000251).



Examples of impacted devices:


Information on Linux updates will be provided as soon as they are live.



iOS
All iPhone, iPad and iPod touch devices with iOS 9.3.5 and lower, and AppleTV devices with version 7.2.2 and lower are affected by the remote code execution vulnerability. This vulnerability was already mitigated by Apple in iOS 10, so no new patch is needed to mitigate it. We recommend you upgrade to the latest iOS or tvOS available.



If you are concerned that your device may not be patched, we recommend disabling Bluetooth, and minimizing its use until you can confirm a patch is issued and installed on your device. (source)



How can you protect yourself?


One of the primary uses of  Bluetooth is for cell phone users so that they can talk hands-free while driving. As well, devices that sync with your computer, like fitness watches, also use Bluetooth technology. You should disable your Bluetooth until this is resolved.








Create your own review








Average rating:  

 0 reviews





Monday, September 18, 2017

The Equifax Hack Is The Most Disastrous Data Breach In History Because Now Hackers Have The Credit Information Of 143 Million Americans

This report was originally published by Michael Snyder at The Economic Collapse


hack


Talk about a nightmare. It is being reported that criminals were able to hack into Equifax and make off with the credit information of 143 million Americans. We are talking about names, Social Security numbers, dates of birth, home addresses and even driver’s license numbers. If this data breach was an earthquake, we would be talking about a magnitude-10.0 on the identity theft scale. We have never seen anything like this before, and to say that this will be “disastrous” for the credit industry would be a massive understatement.


What really disturbed me about this story is that this hack reportedly occurred between “mid-May and July of this year”



Credit monitoring company Equifax has been hit by a high-tech heist that exposed the Social Security numbers and other sensitive information about 143 million Americans. Now the unwitting victims have to worry about the threat of having their identities stolen.


The Atlanta-based company, one of three major U.S. credit bureaus, said Thursday that “criminals” exploited a U.S. website application to access files between mid-May and July of this year.



So why didn’t we learn about this until September?


Somebody out there really needs to answer that question for us.


And even though the “143 million” number is being thrown around constantly, according to USA Today we may never know the true number of victims…



When asked if there’s a way to quantify how many people have been harmed, John Ulzheimer, a credit expert and former employee at Equifax and credit score firm FICO, said: “There’s no way to know, and there may never be a way to know.”



Personally, I don’t see how Equifax can possibly survive after this. Their stock price is already crashing, and now it has come out that they had put a “music major” in charge of data security…



When Congress hauls in Equifax CEO Richard Smith to grill him, it can start by asking why he put someone with degrees in music in charge of the company’s data security.


And then they might also ask him if anyone at the company has been involved in efforts to cover up Susan Mauldin’s lack of educational qualifications since the data breach became public.


It would be fascinating to hear Smith try to explain both of those extraordinary items.



Also, we are now finding out that Equifax has not just had security problems here in the United States.


According to the New York Post, data breaches have been taking place all over the globe…



Hackers had access to the names, dates of birth and e-mail addresses of nearly 400,000 people in the United Kingdom, said Equifax’s British subsidiary in a statement last week.


In Canada, sensitive data belonging to 10,000 consumers may have been hacked in the breach, said a statement from the Canadian Automobile Association.


In Argentina, one of the company’s portals was so easily accessible that it allowed quick exposure to the personal information of more than 14,000 people.



As noted above, the public didn’t learn about any of this until September.


But once top Equifax officials learned what had happened, some of them started dumping their shares of Equifax very rapidly



Three Equifax executives — not the ones who are departing — sold shares worth a combined $1.8 million just a few days after the company discovered the breach, according to documents filed with securities regulators.


Equifax shares have lost a third of their value since it announced the breach.



Needless to say, the SEC is going to be looking into this very closely.


As we move forward, there is a tremendous amount of concern as to how much this data breach will affect the U.S. economy.


Only time will tell, but without a doubt it will have an impact. For example, according to Bloomberg this data breach could potentially have an absolutely disastrous impact on store-branded credit cards…



Equifax Inc.’s massive data breach could make an already tough market outlook even more daunting for the firms behind Gap Inc.’s and Ann Taylor’s store-branded credit cards.


Those retailers’ banking partners, including Synchrony Financial and Alliance Data Systems Corp., could see fewer account originations as more consumers freeze their credit to avoid hack-related fraud. Consumers have to take extra steps — including calling the credit bureau, going online or paying fees — to lift a block and get a new card.


“If people are defaulting to credit freezes, then if you’re a Macy’s retailer trying to sell credit cards, you can’t get that done at the point of sale,” said Vincent Caintic, an analyst at Stephens Inc. “It could become a regular thing, these freezes. It does slow down the origination process and it’s probably going to increase acquisition costs.”



If you believe that your data may have been compromised in this breach, there are some things that you can do right away to help protect against identity theft. You can sign up for 24 hour a day credit monitoring, you can request fraud alerts, you can enable “two factor authentication” and beyond all of that you could go as far as to freeze your credit.


But if everybody in America suddenly started freezing their credit, that would slow down economic activity dramatically. So needless to say authorities are hoping that does not happen.


In this case, Equifax needs to step up and do the right thing. They need to inform all of the victims (even if that means reaching out to 143 million different people), and they should automatically provide free credit monitoring for all of those that were affected.


I seriously doubt that Equifax will take these measures, and I also seriously doubt that Equifax will be able to survive much longer.


When you bungle something as badly as Equifax has done, it is nearly impossible to restore faith in an organization. The credit information of 143 million Americans is now in the hands of criminals, and the potential damage that could be done is absolutely off the charts.

Friday, September 15, 2017

Cyber Experts Prove the American Power Grid Has Been Hacked

Cyber Experts Prove the American Power Grid Has Been Hacked | Cyber-Experts-Prove-the-American-Power-Grid-Has-Been-Hacked | Science & Technology Sleuth Journal Special Interests US News


A report by internet security experts, Symantec, says that a hacking group called Dragonfly 2.0 has gained access to 20 power company networks. The American power grid has been hacked, but for some reason, the culprits restrained themselves from taking down the power like they did in Ukraine recently.


The targets were in the United States, Turkey, and Switzerland. According to Symantec, the hackers did gain access to the interface they would need to control the power equipment, with which they could cause a widespread blackout. Eric Chien, a Symantec security analyst, told Wired:



“There’s a difference between being a step away from conducting sabotage and actually being in a position to conduct sabotage … being able to flip the switch on power generation. We’re now talking about on-the-ground technical evidence this could happen in the US, and there’s nothing left standing in the way except the motivation of some actor out in the world.” (source)



While we were all focused on the natural disasters like wildfires and hurricanes looming over us, this report went all but unnoticed by the mainstream and alternative media alike.



A power grid attack could shut down commerce and destroy our already precarious financial system. It could take down our medical system. If the damage was long-lasting, chaos would erupt and it wouldn’t take long for the death toll to skyrocket, so dependent are we on power at the flip of a switch.


How did the hackers get in?


Remember how John Podesta ended up being the victim of a phishing scheme that allowed the Clinton campaign to be hacked? This was pretty much the same thing. The Symantec report explains that this has been going on for a couple of years now, but that activity has sharply increased this year:



Symantec has strong indications of attacker activity in organizations in the U.S., Turkey, and Switzerland, with traces of activity in organizations outside of these countries. The U.S. and Turkey were also among the countries targeted by Dragonfly in its earlier campaign, though the focus on organizations in Turkey does appear to have increased dramatically in this more recent campaign.


As it did in its prior campaign between 2011 and 2014, Dragonfly 2.0 uses a variety of infection vectors in an effort to gain access to a victim’s network, including malicious emails, watering hole attacks, and Trojanized software.


The earliest activity identified by Symantec in this renewed campaign was a malicious email campaign that sent emails disguised as an invitation to a New Year’s Eve party to targets in the energy sector in December 2015.


The group conducted further targeted malicious email campaigns during 2016 and into 2017. The emails contained very specific content related to the energy sector, as well as some related to general business concerns. Once opened, the attached malicious document would attempt to leak victims’ network credentials to a server outside of the targeted organization.


In July, Cisco blogged about email-based attacks targeting the energy sector using a toolkit called Phishery. Some of the emails sent in 2017 that were observed by Symantec were also using the Phishery toolkit (Trojan.Phisherly), to steal victims’ credentials via a template injection attack. This toolkit became generally available on GitHub in late 2016,


As well as sending malicious emails, the attackers also used watering hole attacks to harvest network credentials, by compromising websites that were likely to be visited by those involved in the energy sector.


The stolen credentials were then used in follow-up attacks against the target organizations. In one instance, after a victim visited one of the compromised servers, Backdoor.Goodor was installed on their machine via PowerShell 11 days later. Backdoor.Goodor provides the attackers with remote access to the victim’s machine…


…Symantec also has evidence to suggest that files masquerading as Flash updates may be used to install malicious backdoors onto target networks—perhaps by using social engineering to convince a victim they needed to download an update for their Flash player. Shortly after visiting specific URLs, a file named “install_flash_player.exe” was seen on victim computers, followed shortly by the Trojan.Karagany.B backdoor.


Typically, the attackers will install one or two backdoors onto victim computers to give them remote access and allow them to install additional tools if necessary. Goodor, Karagany.B, and Dorshel are examples of backdoors used, along with Trojan.Heriplor.  (source)



The moral of this story? Be careful what you do online.


This was a recon mission.


So, they got in but why didn’t they do anything? According to one expert, they were just in there looking around. John Hultquist, a researcher for FireEye security, said of another such intrusion, “In our experience groups that have solely targeted energy like this have been carrying out reconnaissance for attack,”


According to the report by Symantec:



The Dragonfly group appears to be interested in both learning how energy facilities operate and also gaining access to operational systems themselves, to the extent that the group now potentially has the ability to sabotage or gain control of these systems should it decide to do so. (source)



Back in July of this year, hackers got into an American nuclear power plant in Kansas. On the bright side, they were just into the business side of the Wolf Creek nuclear power plant near Burlington, Kansas, and did not obtain access to the controls. But it’s still pretty unsettling that they’d even get that close. If someone was able to get into the control section, not only could they cause a power outage, but they could potentially disable the nuclear safeguards. Eric Chien suspects that while this hack was originally blamed on the Russians (because, really, what isn’t blamed on the Russians?) that the Dragonfly 2.0 hackers were the ones who were responsible. ““It’s highly unlikely this is just coincidental.”


Symantec seems to believe this will lead to something much, much worse:



Sabotage attacks are typically preceded by an intelligence-gathering phase where attackers collect information about target networks and systems and acquire credentials that will be used in later campaigns…The original Dragonfly campaigns now appear to have been a more exploratory phase where the attackers were simply trying to gain access to the networks of targeted organizations. The Dragonfly 2.0 campaigns show how the attackers may be entering into a new phase, with recent campaigns potentially providing them with access to operational systems, access that could be used for more disruptive purposes in future. (source)



Who is behind Dragonfly?


Symantec isn’t sure who is behind the intrusions and says that many of their actions are aimed at making it difficult to figure out.



Some of the group’s activity appears to be aimed at making it more difficult to determine who precisely is behind it:


  • The attackers used more generally available malware and “living off the land” tools, such as administration tools like PowerShell, PsExec, and Bitsadmin, which may be part of a strategy to make attribution more difficult. The Phishery toolkit became available on Github in 2016, and a tool used by the group—Screenutil—also appears to use some code from CodeProject.

  • The attackers also did not use any zero days. As with the group’s use of publicly available tools, this could be an attempt to deliberately thwart attribution, or it could indicate a lack of resources.

  • Some code strings in the malware were in Russian. However, some were also in French, which indicates that one of these languages may be a false flag.

Conflicting evidence and what appear to be attempts at misattribution make it difficult to definitively state where this attack group is based or who is behind it.  (source)



The report also references the possibility of a false flag.


Our power grid has been hacked.


Our grid has been hacked. Symantec’s report refuses to disclose which power plants were compromised, but there seems to be no doubt the hackers were able to gain access to operational control of them. And while this has been going on for a few years now, they’re getting bolder and nearly have the pieces in place to widespread sabotage our power grid.



What is clear is that Dragonfly is a highly experienced threat actor, capable of compromising numerous organizations, stealing information, and gaining access to key systems. What it plans to do with all this intelligence has yet to become clear, but its capabilities do extend to materially disrupting targeted organizations should it choose to do so. (source)



After last December’s malware attack that took down the grid in Ukraine, the power was back on in most places within 6 hours. But…two months later, the controls were still not fully operational. Nothing was able to be done remotely. Someone had to manually control the breakers for months after the attack.


In the US, it might not go so smoothly.



That’s actually a better outcome than what might occur in the US, experts say, since many power grid control systems here don’t have manual backup functionality, which means that if attackers were to sabotage automated systems here, it could be much harder for workers to restore power. (source)



No manual controls? Yay, progress. But the Ukraine attack could have been worse.



The fact that the hackers could have done much more damage than they did do if only they had decided to physically destroy substation equipment as well, making it much harder to restore power after the blackout. The US government demonstrated an attack in 2007 that showed how hackers could physically destroy a power generatorsimply by remotely sending 21 lines of malicious code. (source)



The Ukrainian grid was hit again with the NotPetya attack earlier this summer, a cyber attack that quickly spread globally. It’s naive to think that


Our power grid has been hacked, and it’s naive to think that a massive cyber attack couldn’t happen to us. Cyber warfare is the war of the future and there is more and more proof that it isn’t a matter of it, but when.







Create your own review








Average rating:  

 0 reviews





Wednesday, September 13, 2017

Hacking The Power Grid: They Can Induce Blackouts On American Soil AT WILL


power-grid4


The American power grid has been hacked.  It also appears that these hackers may take down the entire grid “at will” and induce blackouts when and where they choose.


For an unknown reason, however, the hackers restrained themselves from taking down the power like they did in Ukraine recently.  They simply hacked their way into the system, although speculation is that they just wanted to look around…for now.



You could have seen this one coming a mile away. The narrative is taking shape, folks. The boogie men are being put into place… and when the time is right, “The Powers That Shouldn’t Be”, will send the signal to their henchmen to set off the next crisis, stoking fear in everyone’s hearts. Out of chaos, order! –The Daily Sheeple



A report by internet security experts, Symantec, says that a hacking group called Dragonfly 2.0 has gained access to 20 power company networks.




The targets were in the United States, Turkey, and Switzerland. According to Symantec, the hackers did gain access to the interface they would need to control the power equipment, with which they could cause a widespread blackout.


According to one expert, they were just in there looking around. John Hultquist, a researcher for FireEye security, said of another such intrusion, “In our experience groups that have solely targeted energy like this have been carrying out reconnaissance for attack.” –Organic Prepper



Yet Fortune claims that we should not “freak out” because these hackers got into the power grid.  Fortune went on to say that the American power grid is complex and a take down would be difficult. (Yeah.  So complex hackers can’t get in…oh, wait…) But mainly they simply state without any evidence to back up the subjective statement, that adversaries seeking to take down the grid are at the beginning of their journey of destruction, and not at the end.



These adversaries had access to the networks that operate the industrial equipment used to power our country. That sounds scary. But the belief pushed by governments, Hollywood movie scripts, and media headlines for years—that we are standing on the brink of cyber-induced blackouts and mass chaos—is misinformed. Our adversaries are at the starting point of their journey to cause significant disruption to our power grid, not the finish line. –Fortune



But that isn’t comforting to those who understand what a power grid failure would look like, in the grand scheme of things. Disabeling large portions of the grid would cause chaos.  And many, including Symantec, appear to think this was a much bigger issue than initially thought. While the cyber security company believes that this hack was to just “poke around,” it signals that those seeking to do harm are moving onto their next phase of an attack. With recent campaigns potentially providing them with access to operational systems, access could be used for more disruptive purposes in future.



Back in July of this year, hackers got into an American nuclear power plant in Kansas. On the bright side, they were just into the business side of the Wolf Creek nuclear power plant near Burlington, Kansas, and did not obtain access to the controls. But it’s still pretty unsettling that they’d even get that close. If someone was able to get into the control section, not only could they cause a power outage, but they could potentially disable the nuclear safeguards. Eric Chien suspects that while this hack was originally blamed on the Russians (because, really, what isn’t blamed on the Russians?) that the Dragonfly 2.0 hackers were the ones who were responsible. “It’s highly unlikely this is just coincidental.” –The Organic Prepper



The Organic Prepper also points out that it’s hard to miss the fact that this could be nothing more than a red flag event.



Symantec’s report refuses to disclose which power plants were compromised, but there seems to be no doubt the hackers were able to gain access to operational control of them. And while this has been going on for a few years now, they’re getting bolder and nearly have the pieces in place to widespread sabotage our power grid.


Some code strings in the malware were in Russian. However, some were also in French, which indicates that one of these languages may be a false flag. Conflicting evidence and what appear to be attempts at misattribution make it difficult to definitively state where this attack group is based or who is behind it. –The Organic Prepper



Advancements in technology have made manual controls obsolete. Meaning that controlling the power grid is a matter of know-how and internet prowess.  Cyber warfare is the war of the future and there is more and more proof that it isn’t a matter of if, but when.



Click here to subscribe: Join over one million monthly readers and receive breaking news, strategies, ideas and commentary.

Gas Masks, Filters, Body Suits, Anti Radiation Pills

Please Spread The Word And Share This Post






Author: Mac Slavo
Views: Read by 250 people
Date: September 13th, 2017
Website: www.SHTFplan.com


Copyright Information: Copyright SHTFplan and Mac Slavo. This content may be freely reproduced in full or in part in digital form with full attribution to the author and a link to www.shtfplan.com. Please contact us for permission to reproduce this content in other media formats.


Saturday, July 15, 2017

Digital Data Is A Mortal Risk

Digital Data Is A Mortal Risk | PeterThiel-BigData_0_jpg_w560h348 | Science & Technology Special Interests


The tech culture would have you believe that the digital data format has produced untold innovations and advancements for personal development, societal advancement and business innovations. Well, the glass is half full for the kool aide drinkers, but for the mere mortals, who seek out a meaningful life as opposed to a regimented existence, the curse of placing the most intimate data on untold hard drives and shuffled among unknown servers, a loss of simple privacy is the least of the problems.


The horror of keeping the door unlocked to the treasure chest of government and business secrets seems not to faze the computer gurus who pushed for decades that going digital was the holy grail of efficiency and productivity. Encryption was the answer to securing central databases of zeros and ones that store the most desirable information of national security.  


When the mainstream USA Today warns, The hacking of OPM: Is it our cyber 9/11? – The cover-up of a vulnerability of unlimited sharing of data from security breaches should be a substantial alarm call.  




“Although the announcement of the hacking into the computers of the OPM and the stealing of personal data on more than four million present and former federal employees was made in late May, the data breach had been discovered a month earlier and had been going on undiscovered for more than a year. 


An obvious question about this latest data breach is why were the hackers seeking this information and the answer at this time is that we do not know. This type of information could be used for purposes of identity theft for profit, for gathering information to be used by the Chinese government to enhance their spying capabilities or even as part of their ongoing worldwide corporate espionage efforts by which they steal corporate and military secrets, such as the theft of secret plans of our most advanced F-35 Stealth Fighter Jet which was accomplished by hacking into computers at the Pentagon and at Lockheed Martin, the builder of the plane. Evidence of the hacking of the F-35 was leaked to the public by NSA whistleblower Edward Snowden. 


In May of 2014, the Justice Department indicted five Chinese military personnel on charge of hacking into six American companies to steal corporate secrets, however this type of activity has gone on for years. According to security company Mandiant, Chinese hackers have stolen corporate secrets from 115 American companies since 2014 and it is not just the Chinese who do this type of corporate espionage. Russia has also been particularly active in corporate cybercrime. It was estimated by cybersecurity company CrowdStrike that the Russian government has hacked hundreds of companies around the world in order to steal trade secrets and corporate information they can exploit.” 



Now it should be self-evident that spying from friends or foes are normal occurrences in a hostile world. Citing the theft of design, confidential technological and engineering details, obviously should be of concern to all citizens. However, the pattern of hacking and easy access to such information just does not seem to rise to the highest national concern.  


The question that is seldom asked is whether placing such sensitive secrets on networks that can be used by anyone, who can duplicate or pilfer the authorization credentials to login, is a core and systemic issue. 


With all the billions spent on the computer spy game, one would reasonably wonder why keep in a digital format the most important information resources that seem to be the highest objective on the target list for foreign theft.  


Espionage makes use of the most sophisticated methods for penetrating the barriers attempting to protect the information. Remember when the U.S. Embassy in the Soviet capital was penetrated with an eavesdropping device, the response was to communicate using an Etch-a-Sketch toy? Magic Slates don’t blow up, go fast or even scare the dickens out of the bad guys, but the erasable memo pads nonetheless came in handy for two congressional delegates trying to outsmart spies during a mission to Moscow. 


While this example used voice recording, the permanent horde of computerized data is a far more significant gold mine of information. The miracle of the computer revolution has turned into the nightmare of espionage extraction. 


Consider how implausible it would be for a human spy to use a Minox camera from the cold war era to photograph top secret documents that were instantly transferred from the Chinese hack. Back in the “good old days” of low tech, organizations and bureaucracies stored their records on magnate tape drives in-house. Those vast sharing networks in cyberspace did not exist and the only cloud known was the one that carried the rain. 


Today, the storm from relying on some exotic algorithm formula that claims to safely encrypt and secure any database is like placing your faith into the iPhone culture of assured communication. Back doors are the true entry gateway of global digital dissimulation.  


Surrendering safekeeping for the promise of easy sharing, misses the entire purpose of why secrets in any business or government are kept in the custody and stewardship of trustworthy persons, managing systems of formidable barriers that resist theft and broadcasting.  


What lessons were learned from Edward Snowden? For all the scorn dumped on this whistleblower, what was the method of his disclosures? The digital format of the files begs for accessing the data, for whatever motive the expert exhibits.


Even harsh critics of Snowden do not make the case that he was a foreign agent plant. However, just imagine the kind of damage that could be accomplished if an undercover spy had access to the type of databases that a civilian contractor at the NSA was able to transmit. 


Centralizing critical information under firewall barriers has little guarantees that networks are secure. Since the digital format is the new standard, just maybe, going against the grain is the prudent method to keep real secrets, confidential.


Submitting the most important and sensitive to paper and not on computers might well supply a much safer policy than depending on security clearances to protect top secret documents. 


Abandoning the old fashion tax reporting filings for an electronic submission is a formula for opening financial records on all tax payers. Surely, companies should get nervous over certain details that may not be part of public disclosures. And government technocrats should be put on notice that their role in protecting the system may just require their own agencies to be put under the microscope. 


If whistleblowers were the main source of hacks, the risk might be relatively minimal. Conversely, falling under the state sponsored hacking initiative certainly has every aspect of an act of war. Certainly, the prospect for a heated up confirmation is unlikely for no other reason that it is reasonable to conclude that the U.S. is well skilled in its own espionage operations.  


Nonetheless, it should be recognized that transparency is not defined as direct access to every database, both public and private.  


Digital files are well appreciated for library archives, news reports and political debate, but when foreigners attack information platforms that are intended to secure personal disclosures, the outrage should be more intense and the press needs to feature the problem.  


Privacy has become a dirty word for the collectivists who want to dominate individual behavior. Yet, the stuck on stupid crowd continues to voluntarily provide the most intimate details on their lives on every government form or in surveys.


The databases, themselves are the issue. A society that rushes to send “selfies” on the internet, is hardly a culture based upon prudent and protective privacy. 


Accepting the digitalization of all information guarantees that the only security available rests upon non participation in the electronic communication environment. Even dropping out of the computer revolution will not retake your former disclosures.


Files, yes digital format, are so prevalent that only the unborn do not yet have a dossier on file. 


It is one thing for Google, Facebook and Amazon to assemble personal profiles and project future behavior. But it is much worse for governments to target citizens of other countries for accumulating background information of civilians.


Lesson learned. There is no security in cyberspace. 


If the information you want to protect is important, maintain the details in a privately secure paper format. By this definition, banking, employment, medical and educational circumstances are almost impossible to keep private.


As for national security secrets, will you not agree that this is one area where the government should scale back on network access databases that are so vulnerable to foreign infiltration and spying?  


Let the debate be about expanding public disclosure on government policies and programs and keep the personal background data, private. If you believe that Net Neutrality regulations will provide greater security, the opposite will happen.


Soon foreign agents will not have to hack the system. They will just need to plug into the next “Big Brother” data base that the government will assemble.

Friday, July 14, 2017

Faking Russian US Election Meddling

Faking Russian US Election Meddling | trump-1024x576 | Politics Special Interests [image: nbcnews.com]The discredited canard should have been consigned to history’s dustbin long ago. Yet it persist, scoundrel media disinformation continuing to claim what never happened.


No Russian or any other hacking occurred, no foreign interference of any kind in America’s 2016 election, or any others.


The New York Times criticized Trump’s acceptance of Putin’s denial of any Russian US election meddling. So did the neocon/CIA-connected Washington Post in a lengthy propaganda piece.


It claimed (nonexistent) “information…demonstrat(ing) reasonable confidence that Russia was behind the election hacks – even if Trump with access to (classified) information” disagrees.



In June 2016, a fake news WaPo report claimed Russia hacked DNC computers, citing tech security company CrowdStrike, the firm providing no evidence supporting its accusation.


At the time, the FBI didn’t request access to DNC servers to conduct forensic analysis, DNC spokesman Eric Walker, saying:



“The DNC had several meetings with representatives of the FBI’s Cyber Division and its Washington (DC) Field Office, the Department of Justice’s National Security Division, and US Attorney’s Offices, and it responded to a variety of requests for cooperation, but the FBI never requested access to the DNC’s computer servers.”



Instead the agency relied on CrowdStrike, even though it’s standard practice for the FBI to conduct its own cybersecurity investigative work.


Why not this time? Clearly it’s because emails were leaked by one or more disgruntled Democrat party insiders, not hacked by Russia or anyone else.


WaPo claimed other cybersecurity firms concurred with CrowdStrike, wrongfully blaming Russia for what never happened.


No private or US intelligence sources provided any evidence supporting their accusations. Yet baseless ones persists, proliferated by disreputable media like WaPo, reporting its the CIA handlers want published, suppressing what’s most important to know.


WaPo quoted a fabricated joint Director of National Intelligence (DNI) and Department of Homeland Security (DHS) statement made weeks before last November’s election, saying:


“The US Intelligence Community (USIC) is confident that the Russian Government directed the recent compromises of emails from US persons and institutions, including from US political organizations…intended to interfere with the US election process.”


So-called “confiden(ce)” didn’t include a shred of corroborating evidence because none exists. Earlier and current claims are bald-faced lies.


Earlier and in Hamburg, Putin was honest stressing no Russian meddling in America’s electoral process occurred.


In late December, a declassified FBI/National Cybersecurity and Communications Integration Center joint analysis lied, claiming evidence links Russia to US election interference. Again, no evidence was presented, just baseless claims.


In January, a declassified report on alleged Russian hacking said it “does not and cannot include the full supporting information, including specific intelligence and sources and methods” – because no Russian meddling occurred.


So-called “high confidence” expressed many times was and remains mumbo jumbo rubbish. The CIA, FBI and NSA claiming Putin “ordered an influence campaign in 2016 aimed at the US presidential election…to undermine public faith in the US democratic process, denigrate Secretary Clinton, and harm her electability and potential presidency” was malicious disinformation.


WaPo reported all of the above rubbish as factual – knowing it’s a litany of Big Lies.

Sunday, July 2, 2017

Here’s How a DELIBERATE Cyberattack Could Happen To Us

The Petya Ransomware attack hit globally, but one country, in particular, was devastated by it. The Ukrainian infrastructure was brought down by the attack, where the epicenter occurred, and now, experts are suggesting that it may have been deliberate and state-sponsored.


This is not the first time Ukraine has been under siege by cyberattack. In fact, the battle has been nearly constant for quite some time.



 As for whether that state sponsor was Russia, “It’s difficult to imagine anyone else would want to do this,” Boyarchuk says.


Boyarchuk points to the timing of the attack, just before Ukraine’s Constitution Day, which celebrates the country’s post-Soviet independence…


More technical clues support that theory, some Ukrainian security researchers say. Kiev-based Information Systems Security Partners, which has acted as a first responder for several recent waves of cyberattacks on Ukrainian companies and government agencies, says it has found evidence that sophisticated hackers quietly infiltrated the networks of at least some Ukrainian targets two to three months before they triggered the ransomware that paralyzed those organizations. (source)



Security specialist Matthieu Suiche said in a blog post that it wasn’t a “ransomware” attack intended to make money, and is instead a “wiper” sent to eradicate data.



The fact of pretending to be a ransomware while being in fact a nation state attack — especially since WannaCry proved that widely spread ransomware aren’t financially profitable — is in our opinion a very subtle way from the attacker to control the narrative of the attack. (source)



Forensic analyst Oleksii Yasinsky told Wired that the intent was not money, even though this presented as a ransomware attack.




Rather than just encrypting infected hard drives and demanding $300 in Bitcoin for the decryption key, in some cases it simply wiped machines on the same network, deleting a victim computer’s deep-seated master boot record, which tells it how to load its operating system. Yasinsky argues that this behavior indicates the attackers weren’t, in fact, trying to extort payments from those victims but instead wanted to cause maximum disruption. (source)



They wanted to cause maximum disruption. Now, isn’t that just about the scariest thought ever?


What if the US was hit by a similar cyberattack?


Let’s go a little further down this rabbit hole and imagine such an attack happening in the United States. Because, really, is it that far-fetched? In fact, is it possible that this is a dry run for a massive attack on the American infrastructure? Maybe they want to see what happens when they take down the essential systems of a modern country on a smaller scale first, in order to maximize the effects on a larger target.


Scary, but possible.


Everything we do revolves around computers these days.


Businesses keep their records there. Systems are automated there. It goes on and on. And with this particular virus, one expert said, “There IS NO KILL SWITCH.” It’s virtually unstoppable once it gets into a system and it eradicates everything.


You know how I’m always encouraging you to watch survival movies and read survival fiction to enhance your prepared mindset? Let’s use this real life scenario and wargame the situation based on the systems that were damaged in Ukraine and think this through.


Banking would be disrupted.


Many banks in Ukraine were hit by the attack, which means that people suddenly had no access to their money. Their credit and debit cards wouldn’t work and the ATMs were down.


In the United States, most folks use credit or debit as they go throughout their days. Gas pumps are set up to pay at the pump with your bank card. We think nothing of swiping our card at the grocery store or at lunch. We know we have money in there, and it’s less risky than carrying cash, in most folk’s minds.


But what if suddenly you couldn’t use your credit cards and debit cards? What if the ATM machines went dark and you couldn’t get any cash from them?


Imagine this happened when you were traveling on business, miles from home with a half empty gas tank. You wouldn’t be able to get a hotel room, get more fuel, get food – nothing at all unless you had cash on hand – and even if you DID have enough cash, there’d be other problems as you’ll see below.


You should always have enough cash and supplies on hand to manage for quite a while if commerce were to cease.


Gas stations would close.


In Ukraine, getting fuel was difficult.


Of course, it makes sense that getting gasoline would be pretty tricky. Most gas stations are set up as pay-at-the-pump, and if you have cash, you have to go inside, pay, and they reset the pump to allow you the allotted amount of fuel…on a computer.


As well, the gas pumps themselves are digital in just about every place I’ve been in the past few years. Unless you manage to find some anomaly of a gas station where everything is still manual, the fuel you had would be all you’d have until things reverted to normal.


Even if you could buy stuff, there might not be stuff to buy.


It wouldn’t take more than a day or two for the transport trucks to stop running, since the fuel wouldn’t be readily available. Since our stores use “just-in-time” inventory restocking, pickings would be thin within a week.


Here’s a breakdown of what would happen – and how fast it would happen – if the trucks stopped running.


Like I said, be prepped for this.


Business would be disrupted.


In Ukraine, the banks are offline, which means payment systems are also offline.


Most businesses link to banks to be able to take payments by debit or credit. Most people no longer carry around pockets full of cash, and even if they did, some businesses aren’t entirely equipped to take cash payments.


When I worked at a car dealership service department, half a lifetime ago, I recall getting the day off because we were utterly at a standstill when our systems went down. The technicians couldn’t do any kind of electronic repair (and let’s face it, these days, there’s a computer in your car controlling just about every aspect of its function), the advisers couldn’t invoice, no one could check to see if a job was covered under warranty…I’m sure that many other businesses are equally dependent.


Most retail businesses rely on the ability to scan items for the price and to track SKU numbers for inventory purposes. Their cash registers are inextricably linked to computers for both payment options, pricing, and inventory options. Commerce could grind immediately to a halt, which means, what you have on hand would be all you had until things were resolved. You could forget about getting goods or services.


With the banking systems inoperable, other systems would soon go down too.


Think about our day-to-day business. Most of us have things on autopay, like our mortgages, car payments, and other monthly recurring bills.


If the banking systems are completely shut down, then our automatic payments would also cease to work. This means that the businesses relying on those payments would immediately have a shortfall, something that could have long-term ramifications if the issue lasted for more than a few days. Once things came back online, there would be massive confusion and congestion as people tried to straighten out payments that didn’t go through.


Chaos.


Transportation could shut down.


In Ukraine, both the major airport in the capital and the national railway system were shut down.


An attack like this could hit travelers the hardest. Imagine being at an airport to catch a connecting flight, and then discovering all flights had been canceled. If the computer systems were all down, you wouldn’t be able to rent a car to drive the rest of the way, and you wouldn’t be able to get a hotel room without cash, and you wouldn’t be able to buy any food unless you had cash on hand for that.


Commuters who rely on transit like trains to get back and forth to work would be stranded and without ATM access, most would be without any options. This is why you must always have a Plan B to get home when you’re traveling, along with the appropriate gear and footwear to walk if necessary.


The grid would fail.


In Ukraine, the power grid went down across a broad swath of the country.


In an event like this, it isn’t out of the ordinary for the power to go out. Our grid is extremely susceptible to a malware attack and something called “cascading failure.”



…malware can induce what’s often referred to as a cascading failure. This is what caused the massive blackout that occurred in the Northeastern US and Canada back in 2003. An overgrown tree branch in Ohio touched a power line, which caused that section of the grid to overload and shut down. The electricity had to be transferred to other power lines, which in turn also became overloaded. This chain reaction continued until 55 million people were without power. (source)



This can begin to have broad ramifications very quickly:


  • Most homes are reliant on the grid for heat or cooling.

  • No lights.

  • No hot water.

  • Food in the refrigerator or freezer would begin to spoil.

All the basics of a long-term power outage would apply, multiplied by all of the other things going wrong at the same time. Always be ready for a two-week power outage at the bare minimum.


Water could become contaminated.


Without the systems that keep municipal water supplies treated and distributed, it wouldn’t take long for the water from the taps to become contaminated and unsafe to drink – if it still flowed at all. Buying water at the store would be difficult, if not impossible, for all the reasons mentioned above, and even if you could buy it, the supplies would run out very quickly as others realized the tap water was unsafe to consume.


Always be prepared with water storage, a plan to acquire more water, and a way to purify water.


Dangerous infrastructure systems could be at risk.


The Chernobyl nuclear plant lost its ability to monitor radiation with the usual computerized systems.


Because Chernobyl hasn’t already had enough issues. The plant is still not fully decommissioned after the horrible disaster in the 80s, and some people are still working there monitoring for radiation leaks. All systems have had to revert to manual ones due to the cyberattack.


The United States has 99 nuclear reactors in 30 states.  99 Chernobyls waiting to happen?



Here’s How a DELIBERATE Cyberattack Could Happen To Us | power-reactors-operating | Science & Technology Special Interests


Photo Credit: USNRC



 Hospitals could be affected.


In the US, two hospitals in Pennsylvania were forced to cancel surgeries due to the Petya cyberattack.


During a widespread attack in the United States, there is potential for our medical system to be severely affected. Without access to patient records, terrible mistakes could occur. Many patient monitoring systems are computerized. Some life support machinery is tied into the grid. And what happens if the grid-down situation outlasts the fuel for the generators?


In a situation like that, there wouldn’t be much medical help available for incidents that occur during the disaster. You must keep some first aid and longer-term care supplies on hand, as well as informational guides to help you deal with health issues and emergencies as they arise. Know how to back this up with natural remedies in the event the situation outlasts your commercial supplies.


With all of this, unrest would erupt fairly quickly.


If the situation only lasted for a few days, society certainly wouldn’t break down. But if it stretched into weeks and more people began running out of the basics, we’d begin to see unrest on a massive scale. Think about it – what wouldn’t YOU do to take care of your hungry children?  Add to this the now-refugees stranded in airports and other travel centers across the country, with no supplies and no way to get home. It wouldn’t take long for the need to outstrip any governmental efforts to supply aid.


Long before such a thing ever occurs, you should protect yourself by keeping your mouth shut. No one needs to know that you’re stocked to the rafters and ready for a situation like this. Secondly, you need to be prepared to protect your home and family should things go sideways. Here’s an article I wrote about why preppers must be armed and ready for unrest.


Are you prepped for something like this?


Prepping is prepping is prepping.


This, like any other disaster, assumes certain things.


  • The grid could go down.

  • Emergency services and first responders may not be there.

  • What you have on hand is what you have with which to survive,

  • If you’re away from home, the trip back could be difficult.

Have you thought this through?


An attack like this could have very longterm effects because, as I mentioned above, once it gets into a system, it’s unstoppable. It wipes clean all the date, the information stored, the functions. It would take a long time to come back from that.


What are some other things that could be affected by a massive cyberattack on the US? How would you prepare for something like this? Share your thoughts in the comments section below.




Tuesday, June 20, 2017

The Russian US Election Hacking Big Lie Got Bigger

The Russian US Election Hacking Big Lie Got Bigger | Russian-Hacking-US-elections | Propaganda Special Interests US News [image: Global Research]According to  Bloomberg News, “Russian Cyber Hacks on (the) US electoral system (are) far greater than previously known.”


A Big Lie – utter rubbish! The CIA, and likely NSA and FBI, can cyberattack targets anywhere, making it appear to have originated elsewhere – outside America from any other designated country.


Despite months of allegations, insinuations and accusations, not a shred of evidence suggests any Russian hacking of America’s November 2016 election or any other US target.



Claims otherwise are Big Lies. Repeated enough gets most people to believe them.


Bloomberg:



“Russia’s cyberattack on the US electoral system before Donald Trump’s election was far more widespread than has been publicly revealed, including incursions into voter databases and software systems in almost twice as many states as previously reported.”



Investigators in Illinois said “cyber intruders tried to delete or alter voter data,” according to Bloomberg – presenting no evidence of Russian involvement in what may or may not have happened, just more baseless claims with nothing verifying them.


In December, Jill Stein’s Wisconsin, Michigan and Pennsylvania electoral recount scam ended with her discredited.


In ruling against her, Pennsylvania US District Court Judge Paul Diamond said her hacked election claim “border(ed) on the irrational.”



“(T)here is no credible evidence that any ‘hack’ occurred, and compelling evidence (shows) Pennsylvania’s voting system was not in any way compromised.” Strong stuff!



Stein struck out the same way in Wisconsin and Michigan. No evidence suggests foreign hacking in any of America’s 50 states.


Not according to sources Bloomberg cited, claiming “(d)etails of the wave of attacks, in the summer and fall of 2016, were provided by three people with direct knowledge of the US investigation into the matter. In all, the Russian hackers hit systems in a total of 39 states, one of them said.”


Where’s the evidence? None was presented, just accusations with nothing backing them. Bloomberg cited the dubious Intercept report as proof of Russian hacking.


A previous article debunked what it called a leaked top secret NSA document, claiming without justification that “Russian military intelligence executed a cyberattack on at least one US voting software supplier and sent spear-phishing emails to more than 100 local election officials just days before last November’s presidential election.”


It said the document obtained was anonymously provided, “independently authenticated,” though lacking “ ‘raw’ intelligence on which” NSA claims were made.


An unnamed “US intelligence officer” cautioned about drawing conclusions from its material. Here’s a sample:



“Russian General Staff Main Intelligence Directorate actors…executed cyber espionage operations against a named US company in August 2016, evidently to obtain information on elections-related software and hardware solutions.”


“The actors likely used data obtained from that operation to…launch a voter registration-themed spear-phishing campaign targeting US local government organizations.”




Where’s the evidence? Claims without it are groundless. Besides, what motive could Russia have to hack America’s presidential election.


Duopoly government with two right wings rules, dirty business as usual winning all US elections. Russia and other countries have no ability to change things.


Attempting to hack America’s election system would be an exercise in futility – accomplishing nothing.


In Senate Intelligence Committee testimony, Comey repeated the Big Lie about Russian US election hacking, adding:


“They’re coming after America. They will be back.” Most significant from his testimony was admitting he unethically and maybe illegally leaked government memos about Trump to The NYT.


If government property, “a claim for criminal conduct could be made but it would be unlikely under existing precedent,” Law Professor Jonathan Turley explained.



“However, that does not mean that (his) conduct was either lawful or professional,” he added.



“(O)thers have been punished for releasing non-public information to the media…Comey and the FBI were tasked with finding” administration leakers. He’s one of them, discrediting him more than already.


As for claims about Russian US election hacking or anything else in America, ignore them.


Without proof, they’re baseless, part of longstanding Russia bashing – solely for its sovereign independence and opposition to US imperial lawlessness.