Russian officials charged in years-old energy sector hacks

Mar 24, 2022, 1:59 AM | Updated: Mar 25, 2022, 7:01 am
FILE - Deputy Attorney General Lisa Monaco speaks to The Associated Press during an interview at th...

FILE - Deputy Attorney General Lisa Monaco speaks to The Associated Press during an interview at the Department of Justice in Washington, Nov. 2, 2021. The Justice Department says four Russian government officials have been charged in hacks that targeted the global energy industry and thousands of computers around the world between 2012 and 2018. “Russian state-sponsored hackers pose a serious and persistent threat to critical infrastructure both in the United States and around the world,” Monaco said in a statement. (AP Photo/Manuel Balce Ceneta, File)

(AP Photo/Manuel Balce Ceneta, File)

WASHINGTON (AP) — Four Russian officials, including hackers with a government intelligence agency, have been charged with the malicious hacking of critical infrastructure around the globe including the U.S. energy and aviation sectors between 2012 and 2018, the U.S. Justice Department and British Foreign Office announced.

Among the thousands of computers targeted in some 135 countries were machines at a Kansas nuclear power plant — whose business network was compromised — and at a Saudi petro-chemical plant in 2017 where the hackers overrode safety controls, officials said Thursday.

Though the intrusions date back years, the indictments were unsealed as the FBI has raised fresh alarms about efforts by Russian hackers to scan the networks of U.S. energy firms for vulnerabilities that could be exploited during Russia’s war against Ukraine.

The Foreign Office suggested in an announcement on its website that the timing — exposing “the global scope” of hacking by the KGB’s successor spy agency — was directly related to Russian President Vladimir Putin’s “unprovoked and illegal war in Ukraine.”

Additionally, multiple U.S. federal agencies on Thursday published a joint advisory on the hacking campaign, alerting energy executives to take steps to protect their systems from Russian operatives.

“The DOJ is firing warning shots at people who run Russia’s cyberattack capability,” tweeted threat intelligence analyst John Hultquist at the cybersecurity firm Mandiant.

“Russian state-sponsored hackers pose a serious and persistent threat to critical infrastructure both in the United States and around the world,” Deputy Attorney General Lisa Monaco said in a statement. “Although the criminal charges unsealed today reflect past activity, they make crystal clear the urgent ongoing need for American businesses to harden their defenses and remain vigilant.”

None of the four defendants is in custody, though a Justice Department official who briefed reporters said officials deemed it better to make the investigation public rather than wait for the “distant possibility” of arrests. The State Department on Thursday announced rewards of up to $10 million for information leading to the “identification or location” of any of the four defendants.

The indicted Russians include an employee at a Russian military research institute accused of working with co-conspirators in 2017 to hack the systems of a foreign refinery and to install malicious software, twice resulting in emergency shutdowns of operations. The British Foreign Office identified the target as Saudi and said the military research institute was being sanctioned. The so-called “Triton” case — affecting the Petro Rabigh complex on the Red Sea — has been well-documented by cybersecurity researchers as one of the most dangerous on record. The malware was designed with a goal of inflicting physical damage by disabling a safety shutdown function that would normally stop a refinery from “catastrophic failure,” a Justice Department official said.

The employee, Evgeny Viktorovich Gladkikh, also tried to break into the computers of an unidentified U.S. company that operates multiple oil refineries, according to an indictment that was filed in June 2021 and was unsealed Thursday.

The three other defendants are alleged hackers with Russia’s Federal Security Service, or FSB — which conducts domestic intelligence and counterintelligence — and members of a hacking unit known to cybersecurity researchers as Dragonfly.

The hackers are accused of installing malware into legitimate software updates on more than 17,000 devices in the U.S. and other countries. Their supply chain attacks between 2012 and 2014 targeted oil and gas firms, nuclear power plants and utility and power transmission companies, prosecutors said.

The goal, according to the indictment, was to “establish and maintain surreptitious unauthorized access to networks, computers, and devices of companies and other entities in the energy sector.” That access would enable the Russian government to alter and damage systems if it wanted to, the indictment said.

A second phase of the attack, officials said, involved spear-phishing attacks targeting more than 500 U.S. and international companies, as well as U.S. government agencies including the Nuclear Regulatory Commission.

The hackers also successfully compromised the business network — though not the control systems — of the Wolf Creek Nuclear Operating Corporation in Burlington, Kansas, which operates a nuclear power plant.

The British Foreign Office said the FSB hackers had also targeted U.K. energy companies and stolen data from the U.S. aviation sector and other key U.S. targets.

____

AP reporter Frank Bajak contributed from Lima, Peru. Follow Eric Tucker on Twitter at http://www.twitter.com/etuckerAP.

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

fishery...
Associated Press

Much of drought-plagued West Coast faces salmon fishing ban

The surreal and desperate scramble boosted the survival rate of the hatchery-raised fish, but still it was not enough to reverse the declining stocks in the face of added challenges.
1 day ago
UCLA's Jaime Jaquez Jr. (24) shoots while defended by Gonzaga's Rasir Bolton (45) in the first half...
Associated Press

Gonzaga beats UCLA 79-76 in Sweet 16 on Strawther’s shot

Julian Strawther hit a 3-pointer with 6 seconds left to answer a 3-pointer by UCLA's Amari Bailey, lifting Gonzaga to a wild 79-76 NCAA Tournament win over UCLA Thursday night in the Sweet 16.
1 day ago
transportation...
Associated Press

Officials: Safety device, human error derailed Wash. train

A safety device failed, knocking a train off the tracks last week, spilling diesel after leaving an oil refinery in Anacortes.
1 day ago
File - Credit cards as seen July 1, 2021, in Orlando, Fla. A low credit score can hurt your ability...
Associated Press

What the Fed rate increase means for your credit card bill

The Federal Reserve raised its key rate by another quarter point Wednesday, bringing it to the highest level in 15 years as part of an ongoing effort to ease inflation by making borrowing more expensive.
2 days ago
police lights distracted drivers shooting...
Associated Press

Authorities: Missing mom, daughter in Washington found dead

A missing Washington state woman and her daughter were found dead Wednesday, according to police.
2 days ago
Google...
Associated Press

Google’s artificially intelligent ‘Bard’ set for next stage

Google announced Tuesday it's allowing more people to interact with “ Bard,” the artificially intelligent chatbot the company is building to counter Microsoft's early lead in a pivotal battleground of technology.
3 days ago

Sponsored Articles

Emergency Preparedness...

Prepare for the next disaster at the Emergency Preparedness Conference

Being prepared before the next emergency arrives is key to preserving businesses and organizations of many kinds.
SHIBA volunteer...

Volunteer to help people understand their Medicare options!

If you’re retired or getting ready to retire and looking for new ways to stay active, becoming a SHIBA volunteer could be for you!
safety from crime...

As crime increases, our safety measures must too

It's easy to be accused of fearmongering regarding crime, but Seattle residents might have good reason to be concerned for their safety.
Comcast Ready for Business Fund...
Ilona Lohrey | President and CEO, GSBA

GSBA is closing the disparity gap with Ready for Business Fund

GSBA, Comcast, and other partners are working to address disparities in access to financial resources with the Ready for Business fund.
SHIBA WA...

Medicare open enrollment is here and SHIBA can help!

The SHIBA program – part of the Office of the Insurance Commissioner – is ready to help with your Medicare open enrollment decisions.
Lake Washington Windows...

Choosing Best Windows for Your Home

Lake Washington Windows and Doors is a local window dealer offering the exclusive Leak Armor installation.
Russian officials charged in years-old energy sector hacks