Cyberattack Hits Ukraine Then Spreads Internationally

Several companies have been affected by the Petya cyberattack, including, from left, Rosneft, the Russian energy giant; Merck, a pharmaceutical company; and Maersk, a shipping company. Credit Left, Sergei Karpukhin/Reuters; center, Matt Rourke/Associated Press; right, Enrique Castro Sanchez/Agence France-Presse — Getty Images

Computer systems from Ukraine to the United States were struck on Tuesday in an international cyberattack that was like a recent assault that crippled tens of thousands of machines worldwide.

In Kiev, the capital of Ukraine, A.T.M.s stopped working. About 80 miles away, workers were forced to manually monitor radiation at the old Chernobyl nuclear plant when their computers failed. And tech managers at companies around the world, from Maersk, the Danish shipping conglomerate, to Merck, the drug giant in the United States, were scrambling to respond.

It was unclear who was behind this cyberattack, and the extent of its impact was still hard to gauge Tuesday. It started as an attack on Ukrainian government and business computer systems — an assault that appeared to have been intended to hit the day before a holiday marking the adoption in 1996 of Ukraine’s first Constitution after breaking away from the Soviet Union. It spread from there, causing collateral damage around the world.

This outbreak is the latest and perhaps the most sophisticated in a series of attacks that make use of dozens of hacking tools that were stolen from the National Security Agency and leaked online in April by a group called the Shadow Brokers.

Like the WannaCry attacks in May, the latest global hacking took control of computers and demanded digital ransom from their owners to regain access. The new attack used the same N.S.A. hacking tool, Eternal Blue, that was used in the WannaCry incident, and two other methods to promote its spread, according to researchers at the computer security company Symantec.

The N.S.A. has not acknowledged its tools were used in WannaCry or other attacks. But computer security specialists are demanding that the agency help the rest of the world defend against the weapons it created.

”The N.S.A. needs to take a leadership role in working closely with security and operating system platform vendors such as Apple and Microsoft to address the plague that they’ve unleashed,” said Golan Ben-Oni, the global chief information officer at IDT, a Newark-based conglomerate hit by a separate attack in April that used N.S.A. hacking tools. Mr. Ben-Oni warned federal officials that more serious attacks were probably on the horizon.

The vulnerability in Windows software used by Eternal Blue was patched by Microsoft in March, but as the WannaCry attacks demonstrated, hundreds of thousands of organizations around the world failed to properly install the fix.

“Just because you roll out a patch doesn’t mean it’ll be put in place quickly,” said Carl Herberger, vice president of security at Radware. “The more bureaucratic an organization is, the higher chance it won’t have updated its software.”

Because the ransomware used at least two other ways to spread on Tuesday, even those who used the Microsoft patch could be vulnerable, according to researchers at F-Secure, the Finnish cybersecurity firm.

A Microsoft spokesman said the company’s latest antivirus software should protect against the attack.

The Ukrainian government said several of its ministries, local banks and metro systems had been affected. A number of other European companies, including Rosneft, the Russian energy giant; Saint-Gobain, the French construction materials company; and WPP, the British advertising agency, also said they had been targeted.

Ukrainian officials pointed a finger at Russia on Tuesday, though Russian companies were also affected. Home Credit bank, one of Russia’s top 50 lenders, was paralyzed, with all of its offices closed, according to the RBC news website. The attack also affected Evraz, a steel manufacturing and mining company that employs about 80,000 people, the RBC website reported.

In the United States, DLA Piper, the multinational law firm, also reported being hit. Hospitals in Pennsylvania were being forced to cancel surgeries after the attack hit computers at Heritage Valley Health Systems, a Pennsylvania health care provider, and its hospitals in Beaver and Sewickley, Penn., and satellite locations across the state.

A spokesman for the N.S.A. referred questions about the attack to the Department of Homeland Security. “The Department of Homeland Security is monitoring reports of cyber attacks affecting multiple global entities and is coordinating with our international and domestic cyber partners,” Scott McConnell, spokesman for D.H.S., said in a statement.

Computer specialists said the ransomware was very similar to a virus that first emerged last year called Petya. Petya means “Little Peter,” in Russian, leading some to speculate the name referred to Sergei Prokofiev’s 1936 symphony “Peter and the Wolf,” about a boy who captures a wolf.

Reports that the computer virus was a variant of Petya suggest the attackers will be hard to trace. Petya was for sale on the so-called dark web, where its creators made the ransomware available as “ransomware as a service” — a play on Silicon Valley terminology for delivering software over the internet, according to the security firm Avast Threat Labs.

That means anyone could launch the ransomware with the click of a button, encrypt someone’s systems and demand a ransom to unlock it. If the victim pays, the authors of the Petya ransomware, who call themselves Janus Cybercrime Solutions, get a cut of the payment.

That distribution method means that pinning down the people responsible for Tuesday’s attack could be difficult.

The attack is “an improved and more lethal version of WannaCry,” according to Matthieu Suiche, a security researcher who helped contain the spread of the WannaCry ransomware when he created a kill switch that stopped the attacks.

In just the last seven days, Mr. Suiche noted that WannaCry had tried to hit an additional 80,000 organizations, but was prevented from executing attack code because of the kill switch. Petya does not have a kill switch.

A screenshot of what appeared to be the ransomware affecting systems worldwide on Tuesday. The Ukrainian government posted the shot to its official Facebook page.Petya also encrypts and locks entire hard drives, while the earlier ransomware attacks locked only individual files, said Chris Hinkley, a researcher at Armor, the security firm.

The hackers behind Petya demanded $300 worth of the cybercurrency Bitcoin to unlock victims’ machines. By Tuesday afternoon, online records showed that 30 victims had paid the ransom, though it was not clear whether they regained access to their files. Other victims may be out of luck, after Posteo, the German email service provider, shut down the hackers’ email account.

In Ukraine, people turned up at post offices, A.T.M.s and airports to find blank computer screens, or signs about closures. At Kiev’s central post office, a few bewildered customers milled about, holding parcels and letters, looking at a sign that said, “closed for technical reasons.”

The hackers compromised Ukrainian accounting software mandated to be used in various industries in the country, including government agencies and banks, according to researchers at Cisco Talos, the security division of the computer networking company. That allowed them to unleash their ransomware when the software, which is also used in other countries, was updated.

The ransomware spread for five days across Ukraine, and around the world, before activating Tuesday evening.

“If I had to guess, I would think this was done to send a political message,” said Craig Williams, the senior technical researcher at Talos.

One Kiev resident, Tetiana Vasylieva, was forced to borrow money from a relative after failing to withdraw money at four automated teller machines. At one A.T.M. in Kiev belonging to the Ukrainian branch of the Austrian bank Raiffeisen, a message on the screen said the machine was not functioning.

Ukraine’s Infrastructure Ministry, the postal service, the national railway company, and one of the country’s largest communications companies, Ukrtelecom, had been affected, Volodymyr Omelyan, the country’s infrastructure minister, said in a Facebook post.

Officials for the metro system in Kiev said card payments could not be accepted. The national power grid company Kievenergo had to switch off all of its computers, but the situation was under control, according to the Interfax-Ukraine news agency. Metro Group, a German company that runs wholesale food stores, said its operations in Ukraine had been affected.

At the Chernobyl plant, the computers affected by the attack collected data on radiation levels and were not connected to industrial systems at the site, where, though all reactors have been decommissioned, huge volumes of radioactive waste remain. Operators said radiation monitoring was being done manually.

Cybersecurity researchers questioned whether collecting ransom was the true objective of the attack.

“It’s entirely possible that this attack could have been a smoke screen,” said Justin Harvey, the chief security officer for the Fidelis cybersecurity company. “If you are an evil doer and you wanted to cause mayhem, why wouldn’t you try to first mask it as something else?”

Read More >>

Global Cyberattack: What We Know and Don’t Know


A screenshot of what appeared to be the ransomware affecting systems worldwide on Tuesday. The Ukrainian government posted the shot to its official Facebook page.
A quickly spreading ransomware attack is hitting countries across the world including France, Russia, Spain, Ukraine and the United States, just weeks after a ransomware attack known as WannaCry.

What We Know

• Several private companies have confirmed that they were hit by the attack, including the American pharmaceutical giant Merck, the Danish shipping company AP Moller-Maersk, the British advertising firm WPP, the French multinational Saint-Gobain and the Russian steel, mining and oil companies Evraz and Rosneft.

• Photographs and videos of computers affected by the attack show a message of red text on a black screen. The message read: “Oops, your important files have been encrypted. If you see this text then your files are no longer accessible because they have been encrypted. Perhaps you are busy looking to recover your files but don’t waste your time.”

• Kaspersky Lab, a cybersecurity firm based in Moscow, reported that about 2,000 computer systems had been affected by the new ransomware.

• Cybersecurity researchers first called the new ransomware attack Petya, as it bore similarities to a ransomware strain known by that name, which was first reported by Kasperksy in March 2016. But Kaspersky later said that its investigation into the new attack found that it was a type of ransomware that had never been seen before.

• ESET, a Slovakia-based cybersecurity company, said the first known infection occurred early on June 27, through a Ukrainian software company called MeDoc. MeDoc denied that its program was the initial infection point. In a Facebook post, the firm wrote, “At the time of updating the program, the system could not be infected with the virus directly from the update file,” though an earlier message confirmed that its systems had been compromised.

• Symantec, a Silicon Valley cybersecurity firm, confirmed that the ransomware was infecting computers through at least one exploit, or vulnerability to computer systems, known as Eternal Blue.

• Eternal Blue was leaked online last April by a mysterious group of hackers known as the Shadow Brokers, who have previously released hacking tools used by the National Security Agency. That vulnerability was used in May to spread the WannaCry ransomware, which affected hundreds of thousands of computers in more than 150 countries.

• ESET and several other cybersecurity companies have identified at least one other exploit used in the attack known as PsExec, which takes advantage of a single computer that has not been updated with the latest software in a network to spread infections by looking for — and using — administrative credentials. By using PsExec, the ransomware continued spreading across systems that had been updated, or patched, after the WannaCry outbreak last month.

• Several cybersecurity researchers have identified a Bitcoin address to which the attackers are demanding a payment of $300 from their victims. At least some of the victims appear to be paying the ransom, even though the email address used by the attackers has been shut down. That removes the possibility that the attackers could restore a victim’s access to their computer networks, even once ransom is paid.

What We Don’t Know

• Who is behind the ransomware attack. The original Petya ransomware was developed and used by cybercriminals, and variations have been sold through dark web trading sites, which are accessible only by using browsers that mask a user’s identity, making it difficult for cybersecurity researchers to track.

• The motives for the attack. Cybersecurity researchers ask why, if the goal of the attack was to force victims to pay ransom, more care was not taken to protect the email address through which attackers could communicate with their victims, or to provide multiple avenues for payment.

• How much bigger this attack will get. Cybersecurity researchers say that like WannaCry, the ransomware infects computers using vulnerabilities in the central nerve of a computer, called a kernel, making it difficult for antivirus firms to detect. It also has the ability to take advantage of a single unpatched computer on a network to infect computers across a vast network, meaning that even systems that were updated after WannaCry could potentially become vulnerable again.

What Is Ransomware?

• Ransomware is one of the most popular forms of online attack today. It typically begins with attackers sending their victims email that includes a link or a file that appears innocuous but contains dangerous malware.

• Once a victim clicks on the link or opens the attachment, the computer becomes infected. The program encrypts the computer, essentially locking the user out of files, folders and drives on that computer. In some cases, the entire network the computer is connected to can become infected.

• The victim then receives a message demanding payment in exchange for attackers unlocking the system. The payment is usually requested in Bitcoin, a form of digital currency.

Read More >>

Tumblr Goes Radio Silent On Net Neutrality After Verizon Acquisition

Back when Verizon first began expressing interest in pivoting from broadband duopolist to media and advertising, you might recall that it launched a short-lived technology blog named Sugarstring. Sugarstring quickly made headlines for all the wrong reasons however, after it was revealed that Verizon was banning any new hires from writing about hot-button subjects like net neutrality, or the fact that companies like Verizon and AT&T are now bone-grafted to the nation's intelligence and surveillance apparatus.

Sugarstring is long-since dead, replaced in large part by Verizon's acquisitions of Yahoo and AOL, which also brought Huffpo, Engadget, and Techcrunch under the Verizon umbrella. And while Verizon itself has been busy using fake reporters to blatantly lie about the company's ongoing role in killing net neutrality, there's no indication (yet) that the company has pressured any of its own news outlets to quiet down on the subject. In fact, we've noted previously that some of the best reporting on net neutrality in recent months has originated at TechCrunch (this piece in particular is worth a read).
But while Verizon hasn't yet tried to get its own news outlets to quiet down on net neutrality, other now-Verizon-owned companies that used to be very active on the subject have gone dead quiet. Case in point: Tumblr, which was an integral ally in the SOPA/PIPA fight and an outspoken protector of net neutrality, is now utterly radio silent as FCC boss Ajit Pai attempts to kill the popular consumer protections. Insiders at the company this week expressed their concern to the Verge that Verizon is pressuring CEO David Karp to keep his mouth shut on the subject:

"Now, multiple sources tell The Verge that employees are concerned that Karp has been discouraged from speaking publicly on the issue, and one engineer conveyed that Karp told a group of engineers and engineering directors as much in a weekly meeting that took place shortly after SXSW. “Karp has talked about the net neutrality stuff internally, but won’t commit to supporting it externally anymore,” the engineer said. “[He] assures [us] that he is gonna keep trying to fight for the ability to fight for it publicly.” Karp did not respond to four emails asking for comment, and neither Yahoo nor Tumblr would speak about the matter on the record."

Granted Karp may just have toned down the company's rhetoric voluntarily to avoid ruffling feathers during the transition. And obviously any time a smaller company gets acquired by a larger conglomerate (especially from the historically droll and stodgy telecom sector) you'll see a major culture shift that often isn't for the better. Still, Verizon's positions on subjects like net neutrality are so hostile, Tumblr employees have grown increasingly uneasy in recent weeks, which could lead to an exodus of talent at the company:

“Some of our previous stances on issues that are really important to Tumblr employees and its community are being silenced,” said the former employee. “We've been really noisy about things like net neutrality in the past. We asked the new Head, Simon Khalaf, about it in an all-hands a few weeks ago and he said it was ‘not his problem’ and ‘above his pay grade.’” A current employee and another former employee corroborated this account."
It's unfortunate to have lost Tumblr's voice in the net neutrality fight, especially given that other industry giants like Google and Netflix have similarly gone mute on the subject, leaving consumers and small businesses increasingly alone in fighting for something vaguely resembling an open and healthy internet. And while you'd like to think Verizon is above trampling the editorial independence of former AOL and Yahoo news outlets, Verizon's Sugarstring experiment should make it pretty clear that ham-fisted attempts at censorship aren't exactly out of character for the telco.

For now, however, Verizon appears content to try and use entirely fake journalists like "Jeremy" to spread misinformation on net neutrality, as evident by this recent, comically misleading video by the company:

Read More >>

Net Neutrality Is Dying. Speak Out Now Before It's Too Late


“Come on! The internet is an incredible place!” said comedian and political commentator John Oliver, “And tonight, we need to talk about an issue that is impacting it.” He was just one of the many advocates of a free and open internet who were using the public forum to spread awareness on the threats that the internet is about to face. On May 18, 2017, the current Federal Communications Commission (FCC) led by Chairman Ajit Pai voted 2-1 on a motion to repeal rules and regulations put in place by his predecessor to ensure a free and open internet for all.

The motion, if sustained during a second vote held after the FCC is fully staffed later this year, would mean the repelation of the so-called net neutrality regulations that were put into place by retired FCC Chairman Tom Wheeler to ensure that internet service providers like Comcast, AT&T and Verizon cannot discriminate against various types of internet traffic in a way that suits their businesses. This would give popular broadband companies and internet service providers greater monopoly in their services, allowing them to regulate and alter the people’s access to the internet in a way that suits their needs.

The question of net neutrality is a rather big one, and significantly more important than being able to decide what streaming service you want to use or what search engine you wish to access, though that alone should be incentive enough to speak up. If the proposal put forward by FCC Chairman Ajit Pai falls into place, it would allow internet service providers to block, throttle and fast-lane various parts of the internet at will, potentially regulating and censoring your entire web-surfing experience and forcing you to stick to the destinations that pay protection money to these cable and broadband companies. It would effectively lead to the monopolization of a free institution that since the 1980s has served as the freest and most democratic source of unbridled information.

It is only rarely that we get to see big corporations the likes of Google and Facebook take up the cause of ordinary citizens on a massive scale, but when we do, it is assured that the matter at hand is an important one. When it came to net neutrality, however, we saw our entire country, rich, poor, democrat, republican, independent and corporate, come together to support an idea that is necessary for the growth and prosperity of our data nation as a whole. That is because net neutrality is an idea that anyone can get behind, one that promotes free and equal access to information for every citizen of the country, and initiative that is not only desirable but also essential for the growth of our country and the entire world from an information perspective.

Thankfully for us, the fight isn’t over yet. A huge number of organizations, small and large, are coming together on July 12 to protest the current administration's blatant disregard of public opinion in their decision to break net neutrality, and it is the hope of these participants that, with the correct amount of attention, they can force the government to take notice regarding an issue that should clearly be independent and bipartisan, much like climate change and affordable healthcare.

If you or anyone you know considers themselves an informed citizen of the country and of the internet, one that is prepared to fight for its freedom and in turn, the freedom of the people, I request you to join now by signing up at this website to participate in the massive protest being held on July 12 to demonstrate our apartisan love for net neutrality and the principles that govern it. Remember, the only thing necessary for the triumph of evil is for good men to do nothing.

Read More >>

Netflix Joins Support of Net Neutrality


July 12 will be a national day of action for net neutrality, and Netflix has finally announced it will be fully participating.

During the Obama years, Netflix was a major player on the front lines of the fight for ensuring net neutrality. As a streaming service, Netflix theoretically relies on net neutrality to ensure internet providers don’t slow down their streaming speed in order to elevate cable programs.

But Netflix hasn’t seemed to be as enthusiastic as of late, even as the FCC under Ajit Pai, a former cable lobbyist appointed by Trump, poses the most grave threat to net neutrality we’ve ever seen.

Netflix CEO Reed Hastings recently said, “We think net neutrality is incredibly important, [but] not narrowly important to us because we’re big enough to get the deals we want.”


This raised concerns that Netflix had grown too big for it’s britches and that the fight for net neutrality had lost one of its most powerful forces.

But a few days ago, Netflix released another statement saying, “Netflix will never outgrow the fight for net neutrality. Everyone deserves an open Internet.” A Netflix spokesperson also added, “”We support strong net neutrality protections, even if we are at less risk because of our popularity. There are other companies for whom this is a bigger issue, and we’re joining this day of action to ensure the next Netflix has a fair shot to go the distance.”

Some have said that Netflix’s response was just a PR ploy and they’re just doing this to save face because of growing public pressure. That may be true, but ultimately it doesn’t matter. It’s great that there’s enough public zeal out there to put pressure on companies, and it’s great that Netflix has reaffirmed its position regardless of their motive.

Maybe Netflix really is big enough now to have sufficient negotiating power to take care of themselves when it comes to streaming speeds and dealing with ISPs. But the internet-based video streaming industry as a whole needs net neutrality and would be one of the hardest hit mediums if Pai and cable providers have their way.

Without net neutrality, cable providers can prioritize cable TV in ways that will attempt to deter people from using various online video streaming platforms. Imagine going to Youtube, Amazon or Netflix and seeing a message saying something along the lines of, “To access this site you must pay $5.99/month access fee to your internet provider. If you would like to be able to stream without buffering for 10 minutes or more, an additional $2 fee will be added for each video.”

It’s impossible to overstate the importance of the what’s going on with net neutrality right now. Regardless of what you think of Netflix, it’s a huge relief to have them, and all their lobbying resources, in the fight.

Read More >>

Secret CIA assessment says Russia was trying to help Trump win White House


The CIA has concluded in a secret assessment that Russia intervened in the 2016 election to help Donald Trump win the presidency, rather than just to undermine confidence in the U.S. electoral system, according to officials briefed on the matter.

Intelligence agencies have identified individuals with connections to the Russian government who provided WikiLeaks with thousands of hacked emails from the Democratic National Committee and others, including Hillary Clinton’s campaign chairman, according to U.S. officials. Those officials described the individuals as actors known to the intelligence community and part of a wider Russian operation to boost Trump and hurt Clinton’s chances.

“It is the assessment of the intelligence community that Russia’s goal here was to favor one candidate over the other, to help Trump get elected,” said a senior U.S. official briefed on an intelligence presentation made to U.S. senators. “That’s the consensus view.”

The Obama administration has been debating for months how to respond to the alleged Russian intrusions, with White House officials concerned about escalating tensions with Moscow and being accused of trying to boost Clinton’s campaign.

In September, during a secret briefing for congressional leaders, Senate Majority Leader Mitch McConnell (R-Ky.) voiced doubts about the veracity of the intelligence, according to officials present.

The Trump transition team dismissed the findings in a short statement issued Friday evening. “These are the same people that said Saddam Hussein had weapons of mass destruction. The election ended a long time ago in one of the biggest Electoral College victories in history. It’s now time to move on and ‘Make America Great Again,’ ” the statement read.

Trump has consistently dismissed the intelligence community’s findings about Russian hacking.

“I don’t believe they interfered” in the election, he told Time magazine this week. The hacking, he said, “could be Russia. And it could be China. And it could be some guy in his home in New Jersey.”

The CIA shared its latest assessment with key senators in a closed-door briefing on Capitol Hill last week, in which agency officials cited a growing body of intelligence from multiple sources. Agency briefers told the senators it was now “quite clear” that electing Trump was Russia’s goal, according to the officials, who spoke on the condition of anonymity to discuss intelligence matters.

The CIA presentation to senators about Russia’s intentions fell short of a formal U.S. assessment produced by all 17 intelligence agencies. A senior U.S. official said there were minor disagreements among intelligence officials about the agency’s assessment, in part because some questions remain unanswered.

For example, intelligence agencies do not have specific intelligence showing officials in the Kremlin “directing” the identified individuals to pass the Democratic emails to WikiLeaks, a second senior U.S. official said. Those actors, according to the official, were “one step” removed from the Russian government, rather than government employees. Moscow has in the past used middlemen to participate in sensitive intelligence operations so it has plausible deniability.

Julian Assange, the founder of WikiLeaks, has said in a television interview that the “Russian government is not the source.”

The White House and CIA officials declined to comment.

On Friday, the White House said President Obama had ordered a “full review” of Russian hacking during the election campaign, as pressure from Congress has grown for greater public understanding of exactly what Moscow did to influence the electoral process.

“We may have crossed into a new threshold, and it is incumbent upon us to take stock of that, to review, to conduct some after-action, to understand what has happened and to impart some lessons learned,” Obama’s counterterrorism and homeland security adviser, Lisa Monaco, told reporters at a breakfast hosted by the Christian Science Monitor.

Obama wants the report before he leaves office Jan. 20, Monaco said. The review will be led by James Clapper, the outgoing director of national intelligence, officials said.

During her remarks, Monaco didn’t address the latest CIA assessment, which hasn’t been previously disclosed.

Seven Democratic senators last week asked Obama to declassify details about the intrusions and why officials believe that the Kremlin was behind the operation. Officials said Friday that the senators specifically were asking the White House to release portions of the CIA’s presentation.

This week, top Democratic lawmakers in the House also sent a letter to Obama, asking for briefings on Russian interference in the election.

U.S. intelligence agencies have been cautious for months in characterizing Russia’s motivations, reflecting the United States’ long-standing struggle to collect reliable intelligence on President Vladi­mir Putin and those closest to him.

In previous assessments, the CIA and other intelligence agencies told the White House and congressional leaders that they believed Moscow’s aim was to undermine confidence in the U.S. electoral system. The assessments stopped short of saying the goal was to help elect Trump.

On Oct. 7, the intelligence community officially accused Moscow of seeking to interfere in the election through the hacking of “political organizations.” Though the statement never specified which party, it was clear that officials were referring to cyber-intrusions into the computers of the DNC and other Democratic groups and individuals.

Some key Republican lawmakers have continued to question the quality of evidence supporting Russian involvement.

“I’ll be the first one to come out and point at Russia if there’s clear evidence, but there is no clear evidence — even now,” said Rep. Devin Nunes (R-Calif.), the chairman of the House Intelligence Committee and a member of the Trump transition team. “There’s a lot of innuendo, lots of circumstantial evidence, that’s it.”

[U.S. investigating potential covert Russian plan to disrupt elections]

Though Russia has long conducted cyberspying on U.S. agencies, companies and organizations, this presidential campaign marks the first time Moscow has attempted through cyber-means to interfere in, if not actively influence, the outcome of an election, the officials said.

The reluctance of the Obama White House to respond to the alleged Russian intrusions before Election Day upset Democrats on the Hill as well as members of the Clinton campaign.

Within the administration, top officials from different agencies sparred over whether and how to respond. White House officials were concerned that covert retaliatory measures might risk an escalation in which Russia, with sophisticated cyber-capabilities, might have less to lose than the United States, with its vast and vulnerable digital infrastructure.

The White House’s reluctance to take that risk left Washington weighing more-limited measures, including the “naming and shaming” approach of publicly blaming Moscow.

By mid-September, White House officials had decided it was time to take that step, but they worried that doing so unilaterally and without bipartisan congressional backing just weeks before the election would make Obama vulnerable to charges that he was using intelligence for political purposes.

Instead, officials devised a plan to seek bipartisan support from top lawmakers and set up a secret meeting with the Gang of 12 — a group that includes House and Senate leaders, as well as the chairmen and ranking members of both chambers’ committees on intelligence and homeland security.

Obama dispatched Monaco, FBI Director James B. Comey and Homeland Security Secretary Jeh Johnson to make the pitch for a “show of solidarity and bipartisan unity” against Russian interference in the election, according to a senior administration official.

Specifically, the White House wanted congressional leaders to sign off on a bipartisan statement urging state and local officials to take federal help in protecting their voting-registration and balloting machines from Russian cyber-intrusions.

Though U.S. intelligence agencies were skeptical that hackers would be able to manipulate the election results in a systematic way, the White House feared that Russia would attempt to do so, sowing doubt about the fundamental mechanisms of democracy and potentially forcing a more dangerous confrontation between Washington and Moscow.

[Putin denies that Russia hacked the DNC but says it was for the public good]

In a secure room in the Capitol used for briefings involving classified information, administration officials broadly laid out the evidence U.S. spy agencies had collected, showing Russia’s role in cyber-intrusions in at least two states and in hacking the emails of the Democratic organizations and individuals.

And they made a case for a united, bipartisan front in response to what one official described as “the threat posed by unprecedented meddling by a foreign power in our election process.”

The Democratic leaders in the room unanimously agreed on the need to take the threat seriously. Republicans, however, were divided, with at least two GOP lawmakers reluctant to accede to the White House requests.

According to several officials, McConnell raised doubts about the underlying intelligence and made clear to the administration that he would consider any effort by the White House to challenge the Russians publicly an act of partisan politics.

Some of the Republicans in the briefing also seemed opposed to the idea of going public with such explosive allegations in the final stages of an election, a move that they argued would only rattle public confidence and play into Moscow’s hands.

McConnell’s office did not respond to a request for comment. After the election, Trump chose McConnell’s wife, Elaine Chao, as his nominee for transportation secretary.

Some Clinton supporters saw the White House’s reluctance to act without bipartisan support as further evidence of an excessive caution in facing adversaries.

“The lack of an administration response on the Russian hacking cannot be attributed to Congress,” said Rep. Adam B. Schiff (Calif.), the ranking Democrat on the House Intelligence Committee, who was at the September meeting. “The administration has all the tools it needs to respond. They have the ability to impose sanctions. They have the ability to take clandestine means. The administration has decided not to utilize them in a way that would deter the Russians, and I think that’s a problem.”

Read More >>

Share

Twitter Delicious Facebook Digg Stumbleupon Favorites More