WhatsApp says journalists and civil society members were targets of Israeli spyware

Messaging app said it had ‘high confidence’ some users were targeted and ‘possibly compromised’ by Paragon Solutions spyware

Nearly 100 journalists and other members of civil society using WhatsApp, the popular messaging app owned by Meta, were targeted by spyware owned by Paragon Solutions, an Israeli maker of hacking software, the company alleged today.

The journalists and other civil society members were being alerted of a possible breach of their devices, with WhatsApp telling the Guardian it had “high confidence” that the users in question had been targeted and “possibly compromised”.

Continue reading...

Many Americans’ cellphone data being hacked by China, official says

Cyber-espionage group ‘Salt Typhoon’ targeting ‘at least’ eight US telecom and telecom infrastructure firms

A large number of Americans’ metadata has been stolen in the sweeping cyber-espionage campaign carried out by a Chinese hacking group dubbed “Salt Typhoon”, a senior US official told journalists on Wednesday.

The official declined to provide specific figures but noted that China’s access to America’s telecommunications infrastructure was broad and that the hacking was ongoing.

Continue reading...

NSO – not government clients – operates its spyware, legal documents reveal

Details of emerge in sworn depositions by employees of Israeli company as part of lawsuit brought by WhatsApp

Legal documents released in ongoing US litigation between NSO Group and WhatsApp have revealed for the first time that the Israeli cyberweapons maker – and not its government customers – is the party that “installs and extracts” information from mobile phones targeted by the company’s hacking software.

The new details were contained in sworn depositions from NSO Group employees, portions of which were published for the first time on Thursday.

Continue reading...

Chinese hackers collected audio from a Trump campaign adviser’s calls – report

The Washington Post reports Chinese state-affiliated hackers intercepted audio and texts from unnamed adviser

Chinese state-affiliated hackers intercepted audio from the phone calls of US political figures, including an unnamed campaign adviser of Donald Trump, the Washington Post reported Sunday.

Various media outlets reported on Friday that the Trump campaign was made aware last week that the Republican presidential candidate and his running mate JD Vance were among a number of people inside and outside of government whose phone numbers were targeted through the infiltration of Verizon phone systems.

Continue reading...

Russia’s FSB protected Evil Corp gang that carried out Nato cyber-attacks

NCA says cybercriminal gang used family links to spy agency to shield members targeted by US authorities

A prolific Russian cybercriminal gang carried out attacks against Nato countries at the behest of state intelligence services and used family links with Russia’s domestic spy agency to protect its members after being targeted by US authorities, according to the UK’s National Crime Agency.

The dramatically named Evil Corp group had an unusually close relationship with the Russian state, said the NCA.

Continue reading...

Sweden warns of heightened risk of Russian sabotage

Weapons facilities targeted as security companies report more sabotage attempts, espionage and cyber-attacks

Swedish authorities have warned of a heightened risk of Russian sabotage, in particular of weapons facilities, as the defence industry said it was being increasingly targeted.

Security companies in Sweden reported a rise in sabotage attempts, including using drones over defence company facilities to document and map them, “more aggressive” espionage, cyber-attacks and misinformation.

Continue reading...

FBI told Harris campaign it was target of ‘foreign actor influence operation’ – report

Campaign says it was ‘not aware of any security breaches’ after Trump’s campaign says it was hacked

Kamala Harris’s presidential campaign said it was notified by the FBI last month that it was “targeted by a foreign actor influence operation”, a NBC News reporter said on Tuesday.

“We have robust cybersecurity measures in place, and are not aware of any security breaches of our systems resulting from those efforts,” the campaign said, according to the reporter.

Continue reading...

Donald Trump 2024 campaign says emails were hacked

Spokesperson Steven Cheung accuses ‘foreign sources hostile to the United States’ of leaking internal documents

Donald Trump’s presidential campaign said on Saturday it had been hacked.

Campaign spokesperson Steven Cheung released a statement about the alleged hack, following reports from Politico that it had begun receiving emails from an anonymous account with internal documents from the campaign.

Continue reading...

Sellafield apologises after guilty plea over string of cybersecurity failings

Nuclear site awaits sentencing over breaches that it admitted could have threatened national security

Sellafield has apologised after pleading guilty to criminal charges relating to a string of cybersecurity failings at Britain’s most hazardous nuclear site, which it admitted could have threatened national security.

Among the failings at the vast nuclear waste dump in Cumbria was the discovery that 75% of its computer servers were vulnerable to cyber-attacks, Westminster magistrates court in London heard.

Continue reading...

Hackers leak alleged Taylor Swift ticket data to extort Ticketmaster

Hackers claim they obtained barcode data for hundreds of thousands of tickets to Eras tour and demand millions in ransom

Hackers claimed this week that they had obtained barcode data for hundreds of thousands of tickets to Taylor Swift’s Eras tour, demanding that Ticketmaster pay millions in ransom money or they would leak the information online.

The hacking group posted samples of the data to an online forum– ticket data on Swift’s shows in Indianapolis, Miami, and New Orleans – and alleged that it possessed an additional 30m million barcodes for other high-profile concerts and sporting events.

Continue reading...

NHS confirms stolen data published online is from blood test provider

Health service in England issues update saying there is ‘no evidence’ hackers published entire database

Stolen data published online has been confirmed as having come from the NHS provider Synnovis, NHS England has said.

Synnovis, which manages blood tests for NHS trusts and GP services, primarily in south-east London, was the victim of a cyber-attack – understood to have been carried out by the Russian group Qilin – on 3 June.

Continue reading...

Ticketmaster hit by data hack that may affect 560m customers

Cybercrime group ShinyHunters reportedly demanding £400,000 ransom to prevent data being sold

Ticketmaster has been targeted in a cyber-attack, with hackers allegedly offering to sell customer data on the dark web, its parent company, Live Nation, has confirmed.

The ShinyHunters hacking group is reportedly demanding about £400,000 in a ransom payment to prevent the data being sold.

Continue reading...

Christie’s website hack shows how art world has become target for cybercrime

Auction house hit by cyber-extortionist group RansomHub which claims to have sensitive information of at least 500,000 clients

A ransomware hack was the last thing the precarious fine art market needed – but that’s what it got when Christie’s website went down days before it began its all-important 20th and 21st century May auctions in New York.

Guillaume Cerutti, CEO of the French-owned auctioneer, gently called the attack a “technology security incident”. Christie’s posted its auction catalogs on a separate site, the sale went ahead with sales of $640m, and 10 days later the website came back to life.

Continue reading...

Europol and US seize website domains, luxury goods in $6bn cybercrime bust

‘World’s largest botnet’ – spread through infected emails – taken down through coordinated police action among several countries

US authorities announced on Thursday that they had dismantled the “world’s largest botnet ever”, allegedly responsible for nearly $6bn in Covid insurance fraud.

The Department of Justice arrested a Chinese national, YunHe Wang, 35, and seized luxury watches, more than 20 properties and a Ferrari. The networks allegedly operated by Wang and others, dubbed “911 S5”, spread ransomware via infected emails from 2014 to 2022. Wang allegedly accrued a fortune of $99m by licensing his malware to other criminals. The network allegedly pulled in $5.9bn in fraudulent unemployment claims from Covid relief programs.

Continue reading...

Germany summons Russian envoy over 2023 cyber-attacks

Investigation finds hacker group linked to Russian intelligence responsible for attacks targeting politicians and defence sector

Germany has summoned a top Russian envoy over a series of cyber-attacks targeting members of the governing Social Democrats and its defence and technology sector.

The 2023 attacks, in which several websites were knocked offline in apparent response to Berlin’s decision to send tanks to Ukraine, have been blamed on a hacker group linked to Russian military intelligence.

Continue reading...

FBI chief says Chinese hackers have infiltrated critical US infrastructure

Volt Typhoon hacking campaign is waiting ‘for just the right moment to deal a devastating blow’, says Christopher Wray

Chinese government-linked hackers have burrowed into US critical infrastructure and are waiting “for just the right moment to deal a devastating blow”, the director of the FBI, Christopher Wray, has warned.

An ongoing Chinese hacking campaign known as Volt Typhoon has successfully gained access to numerous American companies in telecommunications, energy, water and other critical sectors, with 23 pipeline operators targeted, Wray said in a speech at Vanderbilt University in Nashville, Tennessee, on Thursday.

Continue reading...

China will use AI to disrupt elections in the US, South Korea and India, Microsoft warns

Beijing did a test run in Taiwan using AI-generated content to influence voters away from a pro-sovereignty candidate

China will attempt to disrupt elections in the US, South Korea and India this year with artificial intelligence-generated content after making a dry run with the presidential poll in Taiwan, Microsoft has warned.

The US tech firm said it expected Chinese state-backed cyber groups to target high-profile elections in 2024, with North Korea also involved, according to a report by the company’s threat intelligence team published on Friday.

Continue reading...

US reprimands Microsoft for security failures that allowed Chinese hack

Federal report says ‘cascade of errors’ by tech giant let Chinese operators break into senior government officials’ email accounts

In a scathing indictment of Microsoft corporate security and transparency, a Biden administration-appointed review board issued a report Tuesday saying “a cascade of errors” by the tech giant let state-backed Chinese cyber operators break into email accounts of senior US officials including commerce secretary, Gina Raimondo.

The Cyber Safety Review Board, created in 2021 by executive order, describes shoddy cybersecurity practices, a lax corporate culture and a lack of sincerity about the company’s knowledge of the targeted breach, which affected multiple US agencies that deal with China.

Continue reading...

Western governments struggle to coordinate response to Chinese hacking

Experts say UK-imposed sanctions will make no difference when hacking is part of ecosystem of dealing with Beijing

With the announcement that the UK government would be imposing sanctions on two individuals and one entity accused of targeting – without success – UK parliamentarians in cyber-attacks in 2021, the phrase “tip of the iceberg” comes to mind. But that would underestimate the iceberg.

James Cleverly, the home secretary, said the sanctions were a sign that “targeting our elected representatives and electoral processes will never go unchallenged”.

Continue reading...

Why didn’t New Zealand impose sanctions on China?

New Zealand did not follow the US and UK in imposing financial restrictions after accusing Beijing of links to cyber-attacks

Politicians, journalists and critics of Beijing were among those targeted by cyber-attacks run by groups backed by China, western intelligence services said this week.

The separate cyber-attacks hit the US, UK and New Zealand – all members of the Five Eyes alliance. The network of five countries, which also includes Canada and Australia, share security related intelligence.

Continue reading...