Facebook Suspends Trump Campaign Data Firm Cambridge Analytica

Facebook says it has suspended the account of Cambridge Analytica, the data analysis firm hired by Donald Trump’s 2016 presidential campaign, amid reports it harvested the profile information of millions of US voters without their permission.

According to the New York Times and Britain’s Observer, the company stole information from 50 million Facebook users’ profiles in the tech giant’s biggest-ever data breach, to help them design software to predict and influence voters’ choices at the ballot box.

Also suspended were the accounts of its parent organization, Strategic Communication Laboratories, as well as those of University of Cambridge psychologist Aleksandr Kogan and Christopher Wylie, a Canadian data analytics expert who worked with Kogan.

Cambridge Analytica was bankrolled to the tune of $15 million by US hedge fund billionaire Robert Mercer, a major Republican donor. The Observer said it was headed at the time by Steve Bannon, a top Trump adviser until he was fired last summer.

“In 2015, we learned that … Kogan lied to us and violated our Platform Policies by passing data from an app that was using Facebook Login to SCL/Cambridge Analytica, a firm that does political, government and military work around the globe,” Facebook said in a posting late Friday by its vice president and deputy general counsel Paul Grewal.

Kogan also improperly shared the data with Wylie, it said. 

Kogan’s app, thisisyourdigitallife, offered a personality prediction test, describing itself on Facebook as “a research app used by psychologists.”

Some 270,000 people downloaded the app, allowing Kogan to access information such as the city listed on their profile, or content they had “liked.”

“However, the app also collected the information of the test-takers’ Facebook friends, leading to the accumulation of a data pool tens of millions-strong,” the Observer reported.

Facebook later pushed back against the claim of a data breach, issuing a fresh statement on Saturday that suggested the misused data was limited to those who voluntarily took the test. 

“People knowingly provided their information, no systems were infiltrated, and no passwords or sensitive pieces of information were stolen or hacked,” Grewal said.

Cambridge Analytica meanwhile said it was in touch with Facebook “in order to resolve this matter as quickly as possible​.”

It blamed the misuse of data on Kogan and said it has since deleted all the data it received from a company he founded, Global Science Research (GSR). 

“No data from GSR was used by Cambridge Analytica as part of the services it provided to the Donald Trump 2016 presidential campaign,” it said.

– ‘Targeting their inner demons’ –

But Wylie, who later became a whistleblower, told the Observer: “We exploited Facebook to harvest millions of people’s profiles. And built models to exploit what we knew about them and target their inner demons. That was the basis that the entire company was built on.”

Kogan legitimately obtained the information but “violated platform policies” by passing information to SCL/Cambridge Analytica and Wylie, according to Facebook.

Facebook said it removed the app in 2015 when it learned of the violation, and was told by Kogan and everyone who received the data that it had since been destroyed.

“Several days ago, we received reports that, contrary to the certifications we were given, not all data was deleted,” Grewal wrote.

“We are moving aggressively to determine the accuracy of these claims. If true, this is another unacceptable violation of trust and the commitments they made.

“We are suspending SCL/Cambridge Analytica, Wylie and Kogan from Facebook, pending further information.”

– British investigation –

Cambridge Analytica, the US unit of British behavioral marketing firm SCL, rose to prominence as the firm that the pro-Brexit group Leave.EU hired for data-gathering and audience-targeting.

The company is facing an investigation by Britain’s parliament and regulators over its handling of information. 

On Saturday, Britain’s information commissioner Elizabeth Denham said: “We are investigating the circumstances in which Facebook data may have been illegally acquired and used.

“It’s part of our ongoing investigation into the use of data analytics for political purposes which was launched to consider how political parties and campaigns, data analytics companies and social media platforms in the UK are using and analyzing people’s personal information to micro-target voters.”

The New York Times meanwhile reported that copies of the data harvested for Cambridge Analytica were still online and that its team had viewed some of the raw data.

sponsored links

Continue reading Facebook Suspends Trump Campaign Data Firm Cambridge Analytica

US Accuses Russian Government of Hacking Infrastructure

The Russian government is behind a sustained hacking effort to take over the control systems of critical US infrastructure like nuclear power plants and water distribution, according to US cyber security investigators.

A technical report released by the Department of Homeland Security on Thursday singled out Moscow as directing the ongoing effort that could give the hackers the ability to sabotage or shut down energy and other utility plants around the country.

It was the first time Washington named the Russian government as behind the attacks which have been taking place for nearly three years.

The allegation added to a series of accusations of political meddling and hacking against Russia that led to Washington announcing fresh sanctions against the country this week. 

“Since at least March 2016, Russian government cyber actors … targeted government entities and multiple US critical infrastructure sectors, including the energy, nuclear, commercial facilities, water, aviation, and critical manufacturing sectors,” the report from the DHS Computer Emergency Readiness Team said.

DHS, together with the Federal Bureau of Investigation, said the Russian hackers targeted two groups — the infrastructure operators themselves, and also peripheral “staging targets” which could be used as stepping stone into the intended targets.

Staging targets included third party firms supplying services and support to the main targets but may have less secure networks. The hackers had a deep toolbox of methods to enter target systems, they said.

The hacking effort paralleled Russia’s alleged operation to interfere with the 2016 US presidential election and continue with online media manipulation throughout 2017.

DHS did not identify specific targets which the Russians broke into. But it said they were able to monitor the behavior of control systems, install their own software, collect the credentials of authorized users, monitor communications, and create administrator accounts to run the systems.

– Sustained attack –

The government has been issuing warnings to operators of US infrastructure — power producers and distributors, water systems, and others — about foreign hacking since 2016. 

In January a White House report said cyberattacks cost the United States between $57 billion and $109 billion in 2016, and warned that the broader economy could be hurt if the situation worsens. It pointed the finger mainly at attackers from Russia, China, Iran, and North Korea.

Last September the private security firm Symantec outlined hacking efforts focused against US and European energy systems by a high-skilled group it dubbed Dragonfly 2.0.

“The Dragonfly group appears to be interested in both learning how energy facilities operate and also gaining access to operational systems themselves, to the extent that the group now potentially has the ability to sabotage or gain control of these systems should it decide to do so.”

Symantec did not name the origin of the group, but the DHS report included Symantec’s Dragonfly analysis in its allegations against Russia.

On Thursday the government announced sanctions against Russia’s top spy agencies and more than a dozen individuals, citing both the election meddling and cyberattacks.

“We will continue to call out malicious behavior, impose costs, and build expectations for responsible actions in cyberspace,” said Rob Joyce, the cybersecurity coordinator on the White House’s National Security Council.

Learn More About Industrial Cybersecurity at SecurityWeek’s ICS Cyber Security Conference

sponsored links

Continue reading US Accuses Russian Government of Hacking Infrastructure

Hackers Tried to Cause Saudi Petrochemical Plant Blast: NYT

Cyber-attackers tried to trigger a deadly explosion at a petrochemical plant in Saudi Arabia in August and failed only because of a code glitch, The New York Times reported.

Investigators declined to identify the suspected attackers, but people interviewed by the newspaper unanimously said that it most likely aimed to cause a blast that would have guaranteed casualties. A bug in the attackers’ code accidentally shut down the system instead, according to the report.

The cyber-attack — which could signal plans for other attacks around the world — was likely the work of hackers supported by a government, according to multiple insiders interviewed by the newspaper.

All sources declined to name the company operating the plant as well as the countries suspected to have backed the hackers, The New York Times said.

Security experts however told the newspaper that Iran, China, Russia, Israel and the United States had the technical capacity to launch an attack of that magnitude.

There was no immediate comment from Saudi Arabia, which has come under frequent cyber-attacks, including “Shamoon”, the aggressive disc-wiping malware that hit the Saudi energy sector in 2012.

Saudi Aramco, the world’s biggest oil company, was among the firms hit by Shamoon, which was believed then to be the country’s worst cyber-attack yet.

US intelligence officials at the time said they suspected a link to the kingdom’s regional rival Iran.

But the August attack was “much more dangerous” than Shamoon, according to The New York Times, and likely aimed to send a political message — investigators said the code had been custom-built with no obvious financial motive.

Tasnee, the Saudi Arabian industrialisation company, had also been attacked by hackers in January 2017, according to Tasnee officials and researchers with the Symantec cybersecurity company interviewed by the newspaper.

The attack destroyed the company’s hard drives, wiped all data and replaced it with the now-iconic image of Aylan Kurdi, the Syrian boy in a red T-shirt who washed up dead on the Turkish coast.

Saudi Arabia was also hit by Powershell malware targeting government computers in November.

Learn More about Industrial Cybersecurity at SecurityWeek’s ICS Cyber Security Conference

sponsored links

Continue reading Hackers Tried to Cause Saudi Petrochemical Plant Blast: NYT

U.S. Hits Russia With Sanctions for Election Meddling

Donald Trump’s administration on Thursday levied sanctions against Russia’s top spy agencies and more than a dozen individuals for trying to influence the 2016 US presidential election and two separate cyberattacks.

The announcement follows a lengthy delay that had caused anger on Capitol Hill and raised questions about Trump’s willingness to confront Moscow.

The measures target five entities and 19 individuals — including the FSB, Russia’s top spy service; the military intelligence agency, or GRU; and 13 people recently indicted by Robert Mueller, the US special counsel handling a sprawling Russia probe.

Sanctions were also levied against individuals behind the separate Petya cyberattack and an “ongoing” attempt to hack the US energy grid.

The move comes despite Trump’s repeated denial that Russia tried to tilt the election in his favor, fearing it could call his victory over Hillary Clinton into question.

The president has also decried more damaging allegations that his campaign colluded with the Kremlin — the subject of Mueller’s ongoing investigation that has seen several key aides indicted or make plea deals.

“It took 14 months,” leading Democratic Senator Amy Klobuchar said of the sanctions. “Finally.”

“Now we must protect our elections going forward,” she added.

Treasury Secretary Steven Mnuchin said the decision showed the administration was “confronting and countering malign Russian cyber activity, including their attempted interference in US elections, destructive cyberattacks, and intrusions targeting critical infrastructure.”

“These targeted sanctions are a part of a broader effort to address the ongoing nefarious attacks emanating from Russia,” he added.

– Moscow’s ‘response’ –

Moscow said it was preparing its response. 

“We view this calmly. We have begun to prepare response measures,” deputy foreign minister Sergei Ryabkov told Interfax news agency.

He claimed the US move was designed to coincide with Russia’s presidential election on Sunday.

Many of the main entities and individuals hit — including the spy agencies and ‘troll factory’ boss Yevgeny Prigozhin — already face assets freezes and travel bans, either put in place under Barack Obama’s administration or for actions linked to Russia’s actions in Ukraine.

But the decision heaps pressure on Moscow as it faces separate punitive measures for an alleged attempt to kill a Russian-born British informant with a nerve agent west of London.

Britain, France, Germany and the United States condemned the attack on the Russian ex-spy and his daughter, saying there was “no plausible alternative explanation” to Moscow’s involvement.

Trump said Thursday “it looks like” Russia was behind that attack.

“I’ve spoken with the (British) prime minister and we are in discussions,” he added. “A very sad situation. It certainly looks like the Russians were behind it. Something that should never, ever happen, and we’re taking it very seriously.”

Moscow has denied being involved, claiming the British government was trying to “deflect attention” from difficult negotiations with the European Union over Brexit.

sponsored links

Continue reading U.S. Hits Russia With Sanctions for Election Meddling

‘Panama Papers’ Law Firm Shuts Down Operations

The law firm at the heart of the “Panama Papers” global tax evasion scandal that brought down two world leaders announced Wednesday it would shut down operations, citing negative press and what it called unwarranted action by authorities.

“Reputational deterioration, the media campaign, the financial consequences and irregular actions by some Panamanian authorities have caused irreparable damage, resulting in the total ceasing of public operations at the end of this month,” Mossack Fonseca said in a statement.

But it added a smaller group would continue working to address requests from authorities and other public and private groups.

Last August, co-founder Jurgen Mossack acknowledged the firm had closed most of its offices abroad after its damaged credibility caused business to flounder.

RelatedPanama Papers – Massive Data Leak Exposes Corrupt World Leaders and Tax Havens

April 3, 2016 marked the beginning of the “Panama Papers” scandal — a leak of 11.5 million files from Mossack Fonseca’s digital archive that revealed how wealthy and influential figures across the world had created offshore businesses to safeguard assets.

The information was obtained by German newspaper Sueddeutsche Zeitung, who shared it with the International Consortium of Investigative Journalists. It was released as a searchable database, with revelations continuing to be unearthed to this day.

Icelandic prime minister Sigmundur David Gunnlaugsson was forced to resign after it was revealed his family had offshore accounts — while former Pakistani prime minister Nawaz Sharif was disqualified for life from office after being implicated in the documents.

Other figures implicated included former British premier David Cameron, football star Lionel Messi, Argentina’s President Mauricio Macri, Spanish filmmaker Pedro Almodovar, to name but a few. 

At least 150 investigations were opened in 79 countries to examine possible tax evasion and money laundering, according to the US-based Center for Public Integrity.

Related: The Panama Papers Wake Up Call

sponsored links

Continue reading ‘Panama Papers’ Law Firm Shuts Down Operations

Researchers Find Critical Security Flaws in AMD Chips

Security researchers said Tuesday they discovered flaws in chips made by Advanced Micro Devices that could allow hackers to take over computers and networks.

Israeli-based security firm CTS Labs published its research showing “multiple critical security vulnerabilities and exploitable manufacturer backdoors” in AMD chips.

CTS itemized 13 flaws, saying they “have the potential to put organizations at significantly increased risk of cyberattacks.”

The report comes weeks after Intel disclosed similar hardware-based flaws dubbed Meltdown and Spectre, sparking widespread computer security concerns and a congressional inquiry.

CTS said the newly discovered flaws could compromise AMD’s new chips that handle applications in the enterprise, industrial and aerospace sectors, as well as consumer products.

In a 20-page white paper, the researchers said the AMD Secure Processor, the gatekeeper responsible for the security of AMD processors, contains “critical vulnerabilities” that “could allow malicious actors to permanently install malicious code inside the Secure Processor itself.”

“These vulnerabilities could expose AMD customers to industrial espionage that is virtually undetectable by most security solutions,” the researchers said.

CTS said AMD’s Ryzen chipset, which AMD outsourced to a Taiwanese chip manufacturer, ASMedia, “is currently being shipped with exploitable manufacturer backdoors inside.”

This could allow attackers “to inject malicious code into the chip” and create “an ideal target” for hackers, the researchers said.

“CTS believes that networks that contain AMD computers are at a considerable risk,” the report said.

“The vulnerabilities we have discovered allow bad actors who infiltrated the network to persist in it, surviving computer reboots and reinstallations of the operating system.

“This allows attackers to engage in persistent, virtually undetectable espionage, buried deep in the system.”

AMD, one of the largest semiconductor firms specializing in processors for PCs and servers, said it was studying the latest report. “At AMD, security is a top priority and we are continually working to ensure the safety of our users as new risks arise,” the California-based company said in a statement.

“We are investigating this report, which we just received, to understand the methodology and merit of the findings.”

Analysts at the security firm enSilo said the AMD flaws could be worse than those affecting Intel chips.

“The impact of these vulnerabilities is more severe than Meltdown/Spectre as it allows an attacker to execute highly privileged code and persist on the victim machine,” enSilo said in a blog post.

Additionally, some of the flaws may be nearly impossible to patch.

“We estimate that without patches from AMD, protection against the vulnerabilities can be limited at best,” enSilo researchers said. “The best protection is to block malware that attempts to leverage these vulnerabilities.”

sponsored links

Continue reading Researchers Find Critical Security Flaws in AMD Chips

Blocking of Broadcom-Qualcomm Tie-up Highlights 5G Security Fears

The unusual move by President Donald Trump blocking a proposed takeover of Qualcomm by Singapore-based chip rival Broadcom highlights growing concerns about the rise of Chinese competitors in the telecom sector and related national security issues.

Trump issued an order Monday barring the proposed $117 billion acquisition, citing credible evidence such a deal “threatens to impair the national security of the United States.”

Trump’s order made no mention of China, but an earlier letter from the US Treasury warned that a takeover might hurt US leadership in 5G, or fifth-generation wireless networks now being deployed, and consequently pose a threat to US security.

“It’s a real threat,” said James Lewis, a former US national security official who is now vice president at the Center for Strategic and International Studies in Washington.

“Every administration since 2002 has figured out we are vulnerable to Chinese espionage if they control the infrastructure. Qualcomm and to some degree Cisco are the last two that keep the US in the game when it comes to telecom, and we don’t want to lose them.”

The takeover, which would have been the largest in the tech sector, was under investigation by the normally secretive Committee on Foreign Investment in the United States (CFIUS).

Last week’s Treasury letter said a takeover of Qualcomm could lead to a loss of US influence in 5G standards, opening the door for Chinese firms like Huawei to dominate.

“Huawei is maybe the only company that offers a full range of 5G products,” Lewis said. “It is positioning itself to be the number one provider of 5G equipment.”

Broadcom said it “strongly disagrees” a tie-up could raise national security concerns, and had pledged to invest to ensure US leadership in 5G, the superfast networks crucial to robotics, connected cars and other smart devices.

Lewis said it was possible US intelligence found something to warrant concern over the deal even as Broadcom was taking steps to redomicile in the United States by April 3, which would negate a CFIUS investigation.

“Maybe it’s money, maybe it’s control, maybe it’s something we don’t know that would justify this kind of extreme action,” Lewis said.

– Fear of Huawei –

Paul Rosenzweig, a former Department of Homeland Security official who now has a consulting firm, had also voiced caution.

“Nobody knows for sure, but there is a suspicion going around that Broadcom’s ultimate goal is to help Huawei and that this play is an attempt to squelch American 5G development,” Rosenzweig wrote recently on the Lawfare national security blog.

Rosenzweig added Broadcom could fire Qualcomm management, cut research spending on 5G or stop Qualcomm from participating in the 5G standards-setting process.

“Perhaps more to the point, Qualcomm is an essential contracting partner of the US government, holding a top secret facility security clearance. If purchased by a foreign company that status might be in jeopardy,” Rosenzweig added.

The Trump move underscores growing concerns over Huawei, the third-largest smartphone maker but also a leading telecom infrastructure producer.

Huawei earlier this year lost a bid for broader entry into the US smartphone market, when AT&T and Verizon canceled deals after US lawmakers expressed concern over the company’s Chinese government ties.

– ‘The 5G problem’ –

Lewis said a controversial proposal floated earlier this year that would have nationalized the United States’ 5G network shows how worried the administration is about espionage using telecom networks.

“This administration has woken up to the 5G problem,” Lewis said.

Technalysis Research president Bob O’Donnell said Broadcom has gained a reputation as a cost-cutter while Qualcomm has been focused on innovating.

“Without the kinds of advancements the culture of Qualcomm has created, the telecom industry would not be as advanced as it is today,” O’Donnell wrote in a blog post.

“Were Broadcom to purchase Qualcomm and apply the same principles it has to other acquisitions, the likely effect would be to dramatically slow those advances down, both through the company’s tactics as well as the likely departures of key employees who would be averse to working for Broadcom.”

Patrick Moorhead, an analyst with Moor Insights & Strategy, said an independent Qualcomm will keep innovating in 5G and that “the industry is breathing a collective sigh of relief” with the deal blocked.

“Qualcomm funds a lot of the 5G interoperability testing and troubleshooting between device makers like Samsung, carrier equipment manufacturers like Ericsson and networks like AT&T, and I believe this will continue with an independent Qualcomm,” Moorhead said.

sponsored links

Continue reading Blocking of Broadcom-Qualcomm Tie-up Highlights 5G Security Fears

Concern Over China Influence Shadows Chip Sector Deal

Concern over China’s potential influence, and rising US protectionist sentiment, hangs over an effort by California-based Qualcomm to repel a Singaporean firm’s hostile takeover bid.

Concern over China’s potential influence, and rising US protectionist sentiment, hangs over an effort by California-based Qualcomm to repel a Singaporean firm’s hostile takeover bid.

If finalized, a tie-up between Broadcom and Qualcomm would be worth an estimated $117 billion and potentially the biggest-ever deal in the tech sector.

read more

Continue reading Concern Over China Influence Shadows Chip Sector Deal

Posted in Uncategorized