UNITED STATES NEWS

Microsoft Exchange hack caused by China, US and allies say

Jul 19, 2021, 6:30 AM | Updated: Jul 20, 2021, 4:29 pm

WASHINGTON (AP) — The Biden administration and Western allies formally blamed China on Monday for a massive hack of Microsoft Exchange email server software and asserted that criminal hackers associated with the Chinese government have carried out ransomware and other illicit cyber operations.

The announcements, though not accompanied by sanctions against the Chinese government, were intended as a forceful condemnation of activities a senior Biden administration official described as part of a “pattern of irresponsible behavior in cyberspace.” They highlighted the ongoing threat from Chinese hackers even as the administration remains consumed with trying to curb ransomware attacks from Russia-based syndicates that have targeted critical infrastructure.

The broad range of cyberthreats from Beijing disclosed on Monday included a ransomware attack from government-affiliated hackers that targeted victims — including in the U.S. — with demands for millions of dollars. U.S officials also alleged that criminal contract hackers associated with China’s Ministry of State Security have engaged in cyber extortion schemes and theft for their own profit.

Meanwhile, the Justice Department on Monday announced charges against four Chinese nationals who prosecutors said were working with the MSS in a hacking campaign that targeted dozens of computer systems, including companies, universities and government entities. The defendants are accused of targeting trade secrets and confidential business information, including scientific technologies and infectious-disease research.

Unlike in April, when public finger-pointing of Russian hacking was paired with a raft of sanctions against Moscow, the Biden administration did not announce any actions against Beijing. Nonetheless, a senior administration official who briefed reporters said that the U.S. has confronted senior Chinese officials and that the White House regards the multination shaming as sending an important message, even if no single action can change behavior.

President Joe Biden told reporters “the investigation’s not finished,” and White House press secretary Jen Psaki did not rule out future consequences for China, saying, “This is not the conclusion of our efforts as it relates to cyber activities with China or Russia.”

Even without fresh sanctions, Monday’s actions are likely to exacerbate tensions with China at a delicate time. Just last week, the U.S. issued separate stark warnings against transactions with entities that operate in China’s western Xinjiang region, where China is accused of repressing Uyghur Muslims and other minorities.

The administration also advised American firms of the deteriorating investment and commercial environment in Hong Kong, where China has been cracking down on democratic freedoms it had pledged to respect in the former British colony.

The European Union and Britain were among the allies who called out China. The EU said malicious cyber activities with “significant effects” that targeted government institutions, political organizations and key industries in the bloc’s 27 member states could be linked to Chinese hacking groups. The U.K.’s National Cyber Security Centre said the groups targeted maritime industries and naval defense contractors in the U.S. and Europe and the Finnish parliament.

In a statement, EU foreign policy chief Josep Borrell said the hacking was “conducted from the territory of China for the purpose of intellectual property theft and espionage.”

The Microsoft Exchange cyberattack “by Chinese state-backed groups was a reckless but familiar pattern of behaviour,” U.K. Foreign Secretary Dominic Raab said.

NATO, in its first public condemnation of China for hacking activities, called on Beijing to uphold its international commitments and obligations “and to act responsibly in the international system, including in cyberspace.” The alliance said it was determined to “actively deter, defend against and counter the full spectrum of cyber threats.”

That hackers affiliated with the Ministry of State Security were engaged in ransomware was surprising and concerning to the U.S. government, the senior administration official said. But the attack, in which an unidentified American company received a high-dollar ransom demand, also gave U.S. officials new insight into what the official said was “the kind of aggressive behavior that we’re seeing coming out of China.”

A spokesperson for the Chinese Embassy in Washington, Liu Pengyu, said in a statement that the “U.S. has repeatedly made groundless attacks and malicious smear against China on cybersecurity. Now this is just another old trick, with nothing new in it.” The statement called China “a severe victim of the US cyber theft, eavesdropping and surveillance.”

The majority of the most damaging and high-profile recent ransomware attacks have involved Russian criminal gangs. Though the U.S. has sometimes seen connections between Russian intelligence agencies and individual hackers, the use of criminal contract hackers by the Chinese government “to conduct unsanctioned cyber operations globally is distinct,” the official said.

Dmitri Alperovitch, the former chief technology officer of the cybersecurity firm Crowdstrike, said the announcement makes clear that MSS contractors who for years have worked for the government and conducted operations on its behalf have over time decided — either with the approval or the “blind eye of their bosses” — to “start moonlighting and engaging in other activities that could put money in their pockets.”

The Microsoft Exchange hack that months ago compromised tens of thousands of computers around the world was swiftly attributed to Chinese cyber spies by Microsoft.

An administration official said the government’s attribution to hackers affiliated with the Ministry of State Security took until now in part because of the discovery of the ransomware and for-profit hacking operations and because the administration wanted to pair the announcement with guidance for businesses about tactics that the Chinese have been using.

Given the scope of the attack, Alperovitch said it was “puzzling” that the U.S. did not impose sanctions.

“They certainly deserve it, and at this point, it’s becoming a glaring standout that we have not,” he said.

He added, in a reference to a large Russian cyberespionage operation discovered late last year, “There’s no question that the Exchange hacks have been more reckless, more dangerous and more disruptive than anything the Russians have done in SolarWinds.

___

Associated Press writers Kelvin Chan in London and Matthew Lee and Alexandra Jaffe in Washington contributed to this report.

___

Follow Eric Tucker on Twitter at http://www.twitter.com/etuckerAP.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

United States News

FILE - FTX founder Sam Bankman-Fried leaves Manhattan federal court in New York, Feb. 16, 2023. (AP...

Associated Press

Prosecutors say Sam Bankman-Fried’s arguments to dismiss cryptocurrency charges are meritless

NEW YORK (AP) — Sam Bankman-Fried’s lawyers made meritless arguments in a bid to convince a judge to toss out criminal charges alleging that the FTX founder stole from investors in his multibillion dollar cryptocurrency fund, federal prosecutors said Monday. In papers filed in Manhattan federal court, prosecutors responded to early May filings in which […]

1 day ago

FILE - Florida Gov. Ron DeSantis, center, poses for a photo with audience members during a fundrais...

Associated Press

DeSantis kicks off presidential campaign in Iowa as he steps up criticism of Trump

WASHINGTON (AP) — Ron DeSantis plans to kick off his presidential campaign in Iowa on Tuesday, the start of a busy week that will take him to 12 cities in three states as he tests his pitch as the most formidable Republican challenger to former President Donald Trump. The Florida governor’s two-day trip to the […]

1 day ago

The draft of a bill that President Joe Biden and House Speaker Kevin McCarthy of Calif., negotiated...

Associated Press

Crucial days ahead as debt ceiling deal goes for vote and Biden calls lawmakers for support

WASHINGTON (AP) — President disastrous U.S. default. Biden spent part of the Memorial Day holiday working the phones, calling lawmakers in both parties, as the president does his part to deliver the votes. A number of hard right conservatives are criticizing the deal as falling short of the new work requirements for older Americans in […]

1 day ago

FILE - Activists demonstrate as the Supreme Court hears oral arguments on a pair of cases that coul...

Associated Press

Most in U.S. say don’t ban race in college admissions but that role should be small: AP-NORC poll

WASHINGTON (AP) — As the Supreme Court decides the fate of affirmative action, most U.S. adults say the court should allow colleges to consider race as part of the admissions process, yet few believe students’ race should ultimately play a major role in decisions, according to a new poll. The May poll from The Associated […]

1 day ago

A sign outside a Target store is seen Wednesday, May 24, 2023, in Nashville, Tenn. Target is removi...

Associated Press

LGBTQ+ activists call for new strategies to promote equality after Target backlash

RICHMOND, Va. (AP) — Following Target’s announcement last week that it removed products and relocated Pride displays to the back of certain stores in the South, activists in the LGBTQ+ community are calling for new campaigns to convince corporate leaders not to cave to anti-LGBTQ+ groups. “We need a strategy on how to deal with […]

1 day ago

FILE - Elizabeth Holmes, then the CEO of Theranos, speaks at the Fortune Global Forum on Nov. 2, 20...

Associated Press

The day has arrived for Elizabeth Holmes to report to a Texas prison

Disgraced Theranos CEO Elizabeth Holmes is scheduled to move to her new home —-a federal prison where she has been sentenced to spend the next 11 years for overseeing a blood-testing hoax that became a parable about greed and hubris in Silicon Valley. The federal judge who sentenced Holmes, 39, in November recommended that she […]

1 day ago

Sponsored Articles

...

DAY & NIGHT AIR CONDITIONING, HEATING AND PLUMBING

Here are the biggest tips to keep your AC bill low this summer

PHOENIX — In Arizona during the summer, having a working air conditioning unit is not just a pleasure, but a necessity. No one wants to walk from their sweltering car just to continue to be hot in their home. As the triple digits hit around the Valley and are here to stay, your AC bill […]

...

OCD & Anxiety Treatment Center

How to identify the symptoms of 3 common anxiety disorders

Living with an anxiety disorder can be debilitating and cause significant stress for those who suffer from the condition.

(Photo by Michael Matthey/picture alliance via Getty Images)...

Cox Communications

Valley Boys & Girls Club uses esports to help kids make healthy choices

KTAR’s Community Spotlight focuses on the Boys & Girls Club of the Valley and the work to incorporate esports into children's lives.

Microsoft Exchange hack caused by China, US and allies say