News

Alleged White House E-Mail Cyber Incident now Called Attack from China

Officials in the United Kingdom now suggest that a cyberattack from purported White House e-mail accounts actually originated from China, and the perpetrator used a hoax e-mail address that resembled a White House account. Nevertheless, the U.K. officials are also calling for more cooperation among governments to jointly agree on policies for state-based covert cyber activity.

The initial reports on Feb. 4 from British Foreign Secretary William Hague indicated that e-mail messages alleged to be from the White House were sent to several British officials in late December. The e-mails contained links that, if opened, would download a virus onto the user's computer.

It was first unclear if the attack came from authentic White House e-mail accounts that had been hacked and infected with a virus or from fake e-mail accounts made to resemble White House e-mail messages. In recent days, the latter scenario appears the more likely.

According to several news accounts, Hague referred to “spoof” White House e-mail accounts, suggesting that the messages were not authentic.

Meanwhile, the Guardian reported that the cyberattack is now believed to have originated in China.

Although the foreign secretary did not name the country behind the attacks, intelligence sources familiar with the incidents made it clear the originating country was China, the Guardian said in an article Feb. 4.

"In late December a spoof e-mail purporting to be from the White House was sent to a large number of international recipients who were directed to click on a link that then downloaded a variant of Zeus," Hague said, according to the article. "The U.K. government was targeted in this attack and a large number of e-mails bypassed some of our filters. Our experts were able to clear up the infection, but more sophisticated attacks such as these are becoming more common."

On Feb. 6, in a subsequent article in the Guardian, Hague indicated that more international agreement is needed for state-based covert cyber activity. The article suggested that the United States may be involved in such activity.

About the Author

Alice Lipowicz is a staff writer for 1105 Media's Washington Technology.

Featured

  • Microsoft 365 Business To Get Azure Active Directory Premium P1 Perks

    Subscribers to Microsoft 365 Business (which is being renamed this month to "Microsoft 365 Business Premium") will be getting Azure Active Directory Premium P1 licensing at no additional cost.

  • How To Use .CSV Files with PowerShell, Part 1

    When it comes to bulk administration, few things are handier than .CSV files. In this two-part series, Brien demos his top techniques for working with .CSV files in PowerShell. First up: How to create a .CSV file.

  • SameSite Cookie Changes Rolled Back Until Summer

    The Chromium Project announced on Friday that it's delaying enforcement of SameSite cookie changes, and is temporarily rolling back those changes, because of the COVID-19 turmoil.

  • Basic Authentication Extended to 2H 2021 for Exchange Online Users

    Microsoft is now planning to disable Basic Authentication use with its Exchange Online service sometime in the "second half of 2021," according to a Friday announcement.

comments powered by Disqus

Office 365 Watch

Sign up for our newsletter.

Terms and Privacy Policy consent

I agree to this site's Privacy Policy.