Intuitive fred888

To the best of my ability I write about my experience of the Universe Past, Present and Future

Top 10 Posts This Month

  • Rosamund Pike: Star of New Amazon Prime Series "Wheel of Time"
  • Belize Barrier Reef coral reef system
  • SNAP rulings ease shutdown pressure as Thune rebuffs Trump call to end filibuster
  • Pacific Ocean from Encyclopedia Britannica
  • Flame (the Giant Pacific Octopus) whose species began here on earth before they were taken to another planet by humans in our near future
  • Learning to live with Furosemide in relation to Edema
  • I put "Blue Sphere" into the search engine for my site and this is what came up.
  • Siege of Yorktown 1781
  • Nine dead, dozens injured in crowd surge at Hindu temple in southern India
  • Transgender members of the Air Force sue government over losing retirement pay

Wednesday, September 28, 2016

1/2 billion Yahoo Email Accounts hacked by Russian Government in Espionage information gathering

NBC News
  • Home
  • Top Videos
  • Decision 2016
  • Ongoing:
  • Ukraine Plane Crash
  • Iraq Turmoil
  • Search

Primary Navigation

  • U.S.
  • World
  • Local
  • Politics
  • Health
  • Tech
  • Science
  • Pop Culture
  • Business
  • Investigations
  • Sports
  • Nightly News
  • Today
  • Meet the Press
  • Dateline

Secondary Navigation

Sections

  • U.S.
  • World
  • Local
  • Politics
  • Investigations
  • Health
  • Tech
  • Science
  • Pop Culture
  • Lifestyle
  • Business
  • Weather
  • Sports
  • Latino
  • Asian America
  • NBCBLK
  • NBC OUT

Top Ongoing

  • Ukraine Plane Crash
  • Iraq Turmoil

TV

  • Nightly News
  • Meet The Press
  • Dateline
  • Today

Featured

  • NBC News VR
  • College Game Plan
  • Data Points
  • Making a Difference
  • Long Story Short
  • 101
  • Show Me
  • Flashback
  • 30 Seconds to Know
  • Debunker

Multimedia

  • Video
  • Photo

More From NBC

  • Sports
  • CNBC
  • MSNBC.com
  • NBC.com
  • Breakingnews.com
  • NBC Learn
  • Re/Code
  • Peacock Productions
  • Next Steps for Vets
  • Parent Toolkit
advertisement
News
U.S. news
  • World
  • Investigations
  • Crime & Courts
  • Asian America
  • Latino
  • NBCBLK
News
Sep 28 2016, 11:58 am ET

Were the Russians Behind the Massive Yahoo Email Hack?

by Chris Francescani
Yahoo security breach: 500 million accounts impacted, 'state sponsor' blamed 0:22
The hack of more than a half billion Yahoo email accounts was motivated by espionage, not profit, according to an independent cybersecurity firm report released Wednesday, which contends that an Eastern European state-sponsored actor appears to have ordered the massive hack as part of a coordinated effort to infiltrate the email accounts of U.S. military, diplomatic and political figures.
The findings by the cyber security firm InfoArmor are consistent with Yahoo officials' claim last week that a state-sponsored actor was behind one of the largest corporate breaches in U.S. history.
Yet InfoArmor's version of events, if accurate, provides significant new details about how and why the company was hacked. Minor league hackers who were peddling Yahoo users' personal information for cash in "dark web" marketplaces were also part of a foreign government espionage campaign dating back to 2014. And the findings also suggest that hacks of LinkedIn, Dropbox, MySpace and other firms -- breaches affecting billions of customers worldwide -- might've been part of the same state-sponsored effort.
In an interview with NBC News prior to the release of his firm's findings, InfoArmor's chief intelligence officer Andrew Komarov described the Yahoo breach as part of a larger, ongoing campaign to break in to the email accounts of prominent officials from the U.S. and across the globe.
He said that his analysts have uncovered a previously unidentified collective of elite black hat hackers-for-hire from Eastern Europe -- a group that InfoArmor analysts now contend was also responsible for hacks of the other social media companies.
Hacker offers data for sale, according to InfoArmor. Courtesy of InfoArmor
Komarov said that a state-sponsored actor from Eastern Europe commissioned and later paid the hacker collective $300,000 for the Yahoo data trove. He said he didn't know if the hacks of the other social media companies were also commissioned by a state-sponsored actor, but believed it was likely. He also said he didn't know if the state that directed the hacks was Russia, or if the state-sponsored actor that paid the hackers was a Russian intelligence agency or some other arm of the Russian government, but that Eastern European hackers often have links to the Russian government.
Eastern European operatives tied to Russia's intelligence agencies have been widely suspected by cybersecurity researchers of multiple efforts to hack U.S. government officials' email accounts and the accounts of Democratic party operatives.
Komarov said that InfoArmor's conclusions that the hackers who attacked Linkedin and other companies were also responsible for the Yahoo breach are based on an extensive intelligence analysis, underground contacts and information gleaned from multiple sources surrounding the Yahoo hack. His firm went into dark web chatrooms and made contact with hackers advertising Yahoo addresses for sale who said they were involved in the breach, and accessed and validated what Komarov described as a "large sample" of the stolen Yahoo data.
"If you calculate all the victims for all these hacks, it will be several billion victims."
Yahoo's confirmation last week of the massive breach has placed the tech giant at the center of a storm of controversy and unanswered questions, and could jeopardize the company's imminent $4.8 billion sale of its core business to the telecom giant Verizon.
It remains unclear how long and how much Yahoo officials knew about the breach before publicly acknowledging it. Company officials have said that Yahoo became aware of the breach in August, and began to investigate. Experts have said that it's not uncommon for a company of Yahoo's size to withhold disclosure of a suspected breach until an internal forensic investigation has been complete.
Last week, Yahoo's chief information security officer, Bob Lord, said that an internal probe had determined that usernames, email addresses, telephone numbers, dates of birth, security questions and answers, and in some cases passwords were harvested from more than 500 million compromised Yahoo accounts.
Lord said in a blog post that the company does not believe that banking or payment information was stolen, and has found no evidence to indicate that the hackers remain inside Yahoo's systems.
Yahoo declined to comment.

"Island-Hopping" To Reach U.S. Officials

Komarov said that the apparently state-sponsored actor involved in the heist was using an indirect but increasingly common strategy known as "island-hopping" or "leap-frogging" to reach its ultimate targets. Rather than going after U.S. and other government officials directly, the aggressors used the data from the hired black-hat hackers to breach the Yahoo accounts of friends, family and associates of their ultimate targets.
Once inside compromised Yahoo accounts, hackers can email or respond to their targets directly with seemingly legitimate Yahoo emails that are virtually indistinguishable from real ones.
"The target will receive the exact same email from the Yahoo user and, for him, it will look legitimate," Komarov said.
Foreign hack on state election databases 5:10
He said that while it's extremely difficult to directly infiltrate a Google Gmail account, for instance, all you really need to get into it is a compromised account of a Yahoo email user who corresponds with the Gmail user.
"Then you simply hack the Yahoo account's contacts, and then analyze the [emails] sent from the real object of interest. At some point you replace [a legitimate Yahoo email sent to a target] and fill it with malware," he said. Once the end target clicks on a link or an attachment in the infected Yahoo email, hackers can get inside the target's account.

From Foreign Espionage to Dark Web Marketplaces

Komarov said that the state-sponsored actor appears to have been working with the black hat hacker collective -- which the InfoArmor team has dubbed "Group E" -- for at least several years.
He said that his analysts have determined that Group E was also responsible for earlier, high-profile hacks of LinkedIn, MySpace, Dropbox, the music-streaming service Last.fm, the microblogging site Tumblr and others -- likely for the same purpose of identifying trusted third parties surrounding their real targets. Tumblr was purchased by Yahoo in 2013.
"If you calculate all the victims for all these hacks by the same group, it will be several billion victims," Komarov said.
InfoArmor has determined that at least some of the hacks of the other tech firms "were requested of Group E…so we assume that the Yahoo breach was one of the tools used for successful attacks against U.S. government officials."
Komarov said that in recent years the state sponsored actor approached Group E and asked them to hack millions of Yahoo email users' accounts. They provided Group E with specific email addresses they were seeking, and when they were turned over and verified, the foreign agent agreed to purchase the entire trove, he said.
The agent had initially sought exclusive access to the stolen Yahoo data set, but balked at Group E's $500,000 price. Instead, Group E brought the price for the Yahoo trove down to $300,000, and retained the right to peddle the hacked emails elsewhere.
Komarov told NBC News that the Yahoo trove was later sold off to two well-known spammers, who exploited it for profit.
After it had been sold off and mined for months, Group E appears to have provided a low-level but well-known hacker named Tessa88 with mostly useless leftovers from the Yahoo trove to further distance the foreign agent from the Yahoo hack, Komarov said.
Tessa88 began advertising Yahoo data for sale on a Russian-speaking dark web marketplace, and appears to have partnered with a hacker who goes by the handle "Peace," or "Peace of Mind," to do the same in an English-speaking online marketplace called The Real Deal, according to InfoArmor.
It was only when Peace began advertising the Yahoo trove for sale that the company apparently became aware that they had been breached.
InfoArmor's report describes the entire enterprise as "carefully orchestrated in order to mask the actual sources of the hacks."

"Hands in the Cookie Jar"

An independent cybersecurity expert, who was briefed by NBC News on the upcoming report -- with the permission of InfoArmor -- said the firm's conclusions are consistent with what the cybersecurity community has privately postulated about the Yahoo hack.
"The story overall has a legitimacy to it," said Ann Barron-DiCamillo, chief technology officer for Strategic Cyber Ventures, who recently retired as director of the U.S. Department of Homeland Security's Computer Emergency Readiness Team (U.S. CERT).
"If you look at when the data was stolen, because the data was stolen in 2014 and never [until recently] showed up for sale on these [dark web] markets, there's usually going to be a nation-state involved," Barron-DiCamillo said on Tuesday.
Image: Yahoo!
Yahoo! home screen pictured on a macbook pro. Lars Hagberg / Zuma Press file
"Nation-state actors like to have a degree of separation, so their hands are not in the cookie jar if they get caught. You're seeing them more and more leveraging others. Plus there's the fact that the [Yahoo] data wasn't quickly monetized." She said that with large scale hacks like those of Yahoo email users, the attackers must move quickly to profit off the theft.
If the motive is pure profit, hackers "are going to want to monetize [the data] so quickly, because it has a short shelf-life in terms of its value."
Barron-DiCamillo said that she wouldn't be surprised to see a nation-state haggle over the price for a data dump it had commissioned.
"It's just like any other business transactions," she said. "It feels different because the outcome is a little unusual, but it's just like any other business transaction."
Posted by intuitivefred888 at 9:58 AM
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: 1/2 billion Yahoo Email Accounts hacked by Russian Government in Espionage information gathering

No comments:

Post a Comment

Newer Post Older Post Home
View mobile version
Subscribe to: Post Comments (Atom)

Subscribe!

Posts
Atom
Posts
Comments
Atom
Comments

Top 10 Most Popular Posts

  • The ultra-lethal drones of the future | New York Post 2014 article
  • reprint of: Drones very small to large
  • Dow futures jump 600 points after Trump says he doesn’t plan to get rid of Fed chief: Live updates
  • most read articles from KYIV Post
  • Anthropogenic effects:Human impact on the environment:Wikipedia
  • Russia and Brazil Hit Hardest in Sovereign Risk Ratings...
  • Cessna 152
  • 158,008 visits to intuitivefred888
  • How He lives without money
  • Help:Wiki markup language

About Me

intuitivefred888
I live in Coastal Northern California at present but was raised mostly in Los Angeles and San Diego Counties. I have also lived in Seattle, Santa Fe, New Mexico, Maui and the big Island of Hawaii. My archive site is: dragonofcompassion.com
View my complete profile

Search This Blog

Translate Page

Archives

  • ►  2025 (6273)
    • ►  December (122)
    • ►  November (646)
    • ►  October (635)
    • ►  September (539)
    • ►  August (468)
    • ►  July (437)
    • ►  June (464)
    • ►  May (387)
    • ►  April (650)
    • ►  March (757)
    • ►  February (511)
    • ►  January (657)
  • ►  2024 (6943)
    • ►  December (806)
    • ►  November (1020)
    • ►  October (618)
    • ►  September (475)
    • ►  August (634)
    • ►  July (704)
    • ►  June (591)
    • ►  May (571)
    • ►  April (382)
    • ►  March (451)
    • ►  February (324)
    • ►  January (367)
  • ►  2023 (3205)
    • ►  December (199)
    • ►  November (257)
    • ►  October (262)
    • ►  September (251)
    • ►  August (179)
    • ►  July (293)
    • ►  June (187)
    • ►  May (300)
    • ►  April (331)
    • ►  March (286)
    • ►  February (348)
    • ►  January (312)
  • ►  2022 (5784)
    • ►  December (342)
    • ►  November (475)
    • ►  October (324)
    • ►  September (465)
    • ►  August (652)
    • ►  July (432)
    • ►  June (336)
    • ►  May (479)
    • ►  April (532)
    • ►  March (489)
    • ►  February (386)
    • ►  January (872)
  • ►  2021 (6974)
    • ►  December (1125)
    • ►  November (660)
    • ►  October (486)
    • ►  September (492)
    • ►  August (733)
    • ►  July (535)
    • ►  June (476)
    • ►  May (487)
    • ►  April (306)
    • ►  March (474)
    • ►  February (486)
    • ►  January (714)
  • ►  2020 (8426)
    • ►  December (522)
    • ►  November (870)
    • ►  October (729)
    • ►  September (666)
    • ►  August (753)
    • ►  July (914)
    • ►  June (588)
    • ►  May (551)
    • ►  April (598)
    • ►  March (1042)
    • ►  February (718)
    • ►  January (475)
  • ►  2019 (8007)
    • ►  December (621)
    • ►  November (615)
    • ►  October (632)
    • ►  September (643)
    • ►  August (798)
    • ►  July (934)
    • ►  June (649)
    • ►  May (702)
    • ►  April (568)
    • ►  March (578)
    • ►  February (620)
    • ►  January (647)
  • ►  2018 (5468)
    • ►  December (337)
    • ►  November (412)
    • ►  October (443)
    • ►  September (405)
    • ►  August (458)
    • ►  July (869)
    • ►  June (393)
    • ►  May (381)
    • ►  April (447)
    • ►  March (493)
    • ►  February (417)
    • ►  January (413)
  • ►  2017 (4986)
    • ►  December (434)
    • ►  November (502)
    • ►  October (398)
    • ►  September (308)
    • ►  August (306)
    • ►  July (382)
    • ►  June (443)
    • ►  May (516)
    • ►  April (484)
    • ►  March (495)
    • ►  February (278)
    • ►  January (440)
  • ▼  2016 (5863)
    • ►  December (545)
    • ►  November (519)
    • ►  October (293)
    • ▼  September (335)
      • 1949 Stinson
      • Past Lives are often strange to deal with
      • The real problem is not at all what we thought it was
      • Hacking the Vote:Time Magazine
      • The Magnificent Seven (2016)
      • Most word buttons still working
      • How to keep yourself from being injured by childre...
      • What is Enlightenment?
      • 2012: While snorkeling on Lanai:
      • I found all these links at Yahoo.com under the hea...
      • Where Dragon of Compassion actually came from for me
      • 2035
      • Quan Yin Riding the White Dragon of Compassion?
      • dragonofcompassion - As drones evolve
      • The end of free speech on Internet?
      • Tina Fey Suggested Alec Baldwin to Play Donald Tru...
      • GOP Blocks Probes Into Trump-Russia Ties?
      • Aleppo Brings Shame on the whole world (that the w...
      • My experience home schooling on independent study ...
      • Nevada high court blocks funding for school choice...
      • Firefighter subdued gunman, calls teachers 'true h...
      • Rugby, Football, Soccer
      • A Santana or Santa Ana winds in California
      • More people die from air pollution each year than ...
      • Cleric Gulen says he is certain Erdogan behind fai...
      • The Opposite of Freedom and Human rights: Whole fa...
      • New Bombshell Report Shows Trump Had Illegal Busin...
      • Report on Trump company's Cuba dealings could affe...
      • Wikipedia:2016 Hoboken train crash
      • More than 100 injured, 1 dead in NJ Transit Hoboke...
      • Realizations
      • Funny Ideas: Versus too many rules and laws
      • Aleppo: Where Sunni Muslims being bombed prefer to...
      • The Present problem of emails worldwide(not just H...
      • 1/2 billion Yahoo Email Accounts hacked by Russian...
      • Billionaire: Chinese real estate is 'biggest bubbl...
      • It is more important to know about what I write ab...
      • 6.5 million people are dying every year from just ...
      • What I thought of the debates
      • Hill Republicans: At least Trump didn't blow it
      • Elon Musk's proposed spaceship can send 100 people...
      • If you don't believe time travel is happening righ...
      • In order to protect time lines
      • 95 degrees Fahrenheit with 77 degrees at 10 pm las...
      • Fast-moving fire erupts in Santa Cruz Mountains
      • Movies on UFOs are not usually how they really are
      • Iowa city braces for highest floodwaters since 200...
      • Taiwan closes schools, offices ahead of island-wid...
      • Yes, Trump Did Say Global Warming Is A Hoax
      • Donald Trump Fell For Hillary Clinton’s Trap At Mo...
      • Trump Suggests China Should Invade North Korea
      • Donald Trump Fell For Hillary Clinton’s Trap At Mo...
      • Clinton puts Trump on defense at first debate
      • Near as I can figure out
      • Tara Mantra
      • 21 Taras
      • White Tara and the 21 Taras of Tibetan Buddhism
      • As we move closer to modern day female dieties bec...
      • Historical Divine Mother predates all other mascul...
      • 75% of Trump Voters are scared what he will do if ...
      • Heat advisories for most of California
      • How God put me through a Paradigm shift so I could...
      • Advanced Soul Travel
      • I didn't get my understanding of the Universe over...
      • 1,180,831 visits to intuitivefred888
      • The priimary problem in the middle East is not rel...
      • Arnold Palmer dead at 87
      • In the 90s Fahrenheit in Santa Barbara
      • Aleppo is a slow motion Pearl Harbor for 1.1 Billi...
      • The future is always unbelievable to those of us i...
      • What is it like to see the future before it happens?
      • 200 airstrikes pummel Aleppo
      • Orange County to Beverly Hills and then Santa Barbara
      • Bush, Clinton, Obama and Roberts attend opening of...
      • The billionaires strike back
      • As the Present world order Unravels
      • Is the U.S. election killing the economy? Yes.
      • Most people in the U.S. are not anti-Muslim
      • Sailing today
      • The secret costs of Islamophobia
      • CNN tested a Chelsea-style bomb. It was 'vicious'
      • Aleppo Is Being Burned: Onslaught of Airstrikes
      • South Korea has plan to kill Kim?
      • White, working class and worried
      • Oklahoma officer charged with manslaughter surrend...
      • What is Reality?
      • I lived in San Diego County from late 1969 to 1976
      • Tulsa police officer charged with manslaughter
      • The Problem with the whole civil rights problem is...
      • Police won't enforce curfew if protests stay peaceful
      • CNN/Kaiser Family Foundation poll results (PDF)
      • Feeling helpless in West Virginia:CNN
      • Reality check: Trump's really wrong on black commu...
      • Disney halts sales of Moana costume after racism c...
      • US confirms mustard attack
      • Rep.: Protesters 'hate white people'
      • 70% of Americans never had or will have a Passport
      • Climate Change Is Here: Inside the Summer of Hell ...
      • Trump Ohio County Campaign Chair Resigns After Rac...
      • Congresswoman Uses Toys To Show The Insanity Of So...
    • ►  August (419)
    • ►  July (703)
    • ►  June (499)
    • ►  May (475)
    • ►  April (362)
    • ►  March (603)
    • ►  February (609)
    • ►  January (501)
  • ►  2015 (4642)
    • ►  December (454)
    • ►  November (452)
    • ►  October (473)
    • ►  September (305)
    • ►  August (403)
    • ►  July (361)
    • ►  June (452)
    • ►  May (277)
    • ►  April (235)
    • ►  March (419)
    • ►  February (401)
    • ►  January (410)
  • ►  2014 (5288)
    • ►  December (408)
    • ►  November (490)
    • ►  October (442)
    • ►  September (418)
    • ►  August (489)
    • ►  July (454)
    • ►  June (391)
    • ►  May (527)
    • ►  April (433)
    • ►  March (512)
    • ►  February (324)
    • ►  January (400)
  • ►  2013 (4282)
    • ►  December (362)
    • ►  November (338)
    • ►  October (410)
    • ►  September (371)
    • ►  August (364)
    • ►  July (291)
    • ►  June (380)
    • ►  May (386)
    • ►  April (407)
    • ►  March (364)
    • ►  February (277)
    • ►  January (332)
  • ►  2012 (2056)
    • ►  December (251)
    • ►  November (201)
    • ►  October (210)
    • ►  September (214)
    • ►  August (179)
    • ►  July (144)
    • ►  June (149)
    • ►  May (171)
    • ►  April (148)
    • ►  March (128)
    • ►  February (124)
    • ►  January (137)
  • ►  2011 (1207)
    • ►  December (145)
    • ►  November (70)
    • ►  October (70)
    • ►  September (63)
    • ►  August (106)
    • ►  July (98)
    • ►  June (68)
    • ►  May (120)
    • ►  April (114)
    • ►  March (182)
    • ►  February (69)
    • ►  January (102)
  • ►  2010 (1090)
    • ►  December (76)
    • ►  November (92)
    • ►  October (110)
    • ►  September (96)
    • ►  August (133)
    • ►  July (48)
    • ►  June (74)
    • ►  May (115)
    • ►  April (112)
    • ►  March (82)
    • ►  February (79)
    • ►  January (73)
  • ►  2009 (859)
    • ►  December (77)
    • ►  November (63)
    • ►  October (66)
    • ►  September (83)
    • ►  August (44)
    • ►  July (43)
    • ►  June (56)
    • ►  May (89)
    • ►  April (102)
    • ►  March (94)
    • ►  February (86)
    • ►  January (56)
  • ►  2008 (830)
    • ►  December (85)
    • ►  November (85)
    • ►  October (59)
    • ►  September (64)
    • ►  August (46)
    • ►  July (37)
    • ►  June (78)
    • ►  May (87)
    • ►  April (86)
    • ►  March (87)
    • ►  February (64)
    • ►  January (52)
  • ►  2007 (193)
    • ►  December (53)
    • ►  November (55)
    • ►  October (43)
    • ►  September (42)
Picture Window theme. Powered by Blogger.