Showing posts with label think tanks and cybersecurity. Show all posts
Showing posts with label think tanks and cybersecurity. Show all posts

Monday, April 22, 2019

Microsoft Helping to Secure Think Tanks, 2020 Elections

Microsoft has a new security service called Microsoft AccountGuard designed to help targeted customers, including think tanks, protect themselves from cybersecurity threats.

Here is more from Microsoft:
While Microsoft AccountGuard is new, it’s grounded in work we’ve done for years to protect democratic processes. This includes support for the Iowa caucuses in 2016, our role as a technology supplier to conventions for both major U.S. parties, and the work of our Washington, D.C.-based team to serve both political campaigns and U.S. government institutions. Based on these foundational experiences, we constructed Microsoft AccountGuard to account for the threats these organizations face, their unique resource constraints and the mix of technologies they often use.
Microsoft AccountGuard is open to all current candidates for federal, state and local office in the United States and their campaigns; the campaign organizations of all sitting members of Congress; national and state party committees; technology vendors who primarily serve campaigns and committees; and certain nonprofit organizations and nongovernmental organizations. Microsoft AccountGuard is offered free of charge. Organizations must be using Office 365 to register.
Microsoft AccountGuard will provide notification about cyberthreats, including attacks by known nation-state actors, in a unified way across both email systems run by organizations and the personal accounts of these organizations’ leaders and staff who opt in. Eligible organizations can invite staff and other associates to enroll in Microsoft AccountGuard, and notification will only occur with the consent of the account owner.

Microsoft is also expanding AccountGuard in Europe, citing similar threats to democracy:
We all saw hacking and disinformation attacks on the French presidential election in 2017, and European leaders have recently warned that attacks will continue across Europe in 2019. At Microsoft, we’ve seen recent activity targeting democratic institutions in Europe as part of the work our Threat Intelligence Center (MSTIC) and Digital Crimes Unit (DCU) carry out every day to protect all of our customers.
These attacks are not limited to campaigns themselves but often extend to think tanks and non-profit organizations working on topics related to democracy, electoral integrity, and public policy and that are often in contact with government officials. For example, Microsoft has recently detected attacks targeting employees of the German Council on Foreign Relations, The Aspen Institutes in Europe and The German Marshall Fund.

The service launched in August 2018, in preparation for the 2018 US midterm elections.  AccountGuard is now helping secure "the 2020 US general elections and broader political and think tank community," says Microsoft.

Over the past several years, Think Tank Watch has documented cyber attacks and cyber intrusions on scores of think tanks in the US, Europe, and elsewhere.

Friday, December 7, 2018

Serious Spearphishing Campaign Against Think Tanks

Here is more from Politico:

A spearphishing campaign that targeted nonprofit groups and think tanks in Washington, D.C., drew Microsoft’s attention because it had “characteristics of previously observed nation-state attacks,” the tech giant said Monday. Because of the people being targeted and the specifics of the spearphishing messages, “Microsoft took the step of notifying thousands of individual recipients in hundreds of targeted organizations,” the company explained in a blog post that shared the technical specifics of the attack. Cyber firm FireEye first publicized the campaign last month, and MC and Reuters subsequently added details.
“Our sensors revealed that the campaign primarily targeted public sector institutions and non-governmental organizations like think tanks and research centers, but also included educational institutions and private-sector corporations in the oil and gas, chemical, and hospitality industries,” Microsoft’s research and threat intelligence teams said in the blog post. The company acknowledged that other firms had attributed the campaign to APT 29, the Russian intelligence service also known as Cozy Bear, but it said it “does not yet believe that enough evidence exists to attribute this campaign” to that group.

Think tanks are a major target of foreign governments, with many of them facing cyber attacks on a daily basis.

Friday, June 24, 2016

DNC Hackers Also Targeting Think Tanks

It seems that foreign intelligence agencies want to tap into the mind on Hillary Clinton's top advisors.  To do so, they are breaking into computer systems of think tanks that have employees who have close ties to the Clintons.

The latest example: Hackers who targeted the Democratic National Committee (DNC) have also been going after US think tanks.  Here is more from Bloomberg Politics:
The Russian hackers who hit the Democratic National Committee and Hillary Clinton’s campaign burrowed much further into the U.S. political system, sweeping in law firms, lobbyists, consultants, foundations and the policy groups known as think tanks, according to a person familiar with investigations of the attacks.
Almost 4,000 Google accounts were targeted in an elaborate “spear phishing” campaign -- intended to trick users into providing access so that information could be gleaned from personal and organizational accounts -- from October through mid-May, according to the person, who asked not to be identified discussing confidential information.
Among the policy groups targeted was the Center for American Progress (CAP), which has ties to Clinton and the Obama administration. “We are constantly reviewing our security and operations to prevent and thwart unauthorized activity,” Liz Bartolomeo, a spokeswoman for the center, said in an e-mailed statement. “We have reviewed our systems and we believe our security measures have prevented unwanted access to our systems.”

As Think Tank Watch has previously reported, several influential think tankers, including CAP President Neera Tanden, sit on the DNC policy committee that is helping Democrats draft their policy platform for the upcoming elections.

Tuesday, May 17, 2016

Hackers Targeting Think Tanks Amid 2016 Election Season

As the 2016 presidential candidates battle it out loudly for all of the public to see, a much quieter battle is taking place against the candidates and their current and future advisors.

Foreign intelligence services are using a "back door" into campaign thinking by hacking into think tanks at an increased rate, trying to get as much intelligence as possible from think tankers who are advising the candidates and drafting their policy proposals.

Here is more from Bloomberg:
Foreign hackers are going after the wonks.
Cyber criminals are targeting policy groups and nongovernmental organizations to get a leg up on U.S. government strategy, according to an executive at cybersecurity company CrowdStrike Inc. Such "nation-state" hackers, often tied to governments including China or Russia, want advanced intelligence on U.S. policy, said Shawn Henry, chief security officer of the Irvine, California-based company.
"They want to know what the thought leaders in the United States are considering, what they’re debating,” Henry, who oversaw the FBI’s global cyber investigations before retiring in 2012, said in an interview in Arlington, Virginia. "They’re looking for how policy is being designed. They’re looking at how senior leaders or former senior leaders are advising existing senior leaders -- what the emerging issues are, how the U.S. government is going to implement certain strategy."
While Henry wouldn’t provide specifics on targets, Washington has many so-called think tanks and interest groups staffed by former government officials and analysts who stay in close touch with current policy makers.

Think tanks have been playing an increasing role in the Donald Trump campaign, and Hillary Clinton has extremely close ties to a number of think tanks, including Brookings, the Center for American Progress (CAP), Center for a New American Security (CNAS), and Council on Foreign Relations (CFR).

Think Tank Watch has previously reported that nearly every major think tank in the US has been hacked, including the Urban Institute, Aspen Institute, Brookings Institution, American Enterprise Institute (AEI), Center for American Progress (CAP), Council on Foreign Relations (CFR), Center for Strategic and International Studies, and the Heritage Foundation.