The State Department is the most recent federal agency to admit to a breach of its cyber networks after the Associated Press revealed Sunday that the department had shut down its email systems to remediate an intrusion into its unclassified network.
Department Press Office Director Jeff Rathke said Monday the intrusion was linked to the same attack on the White House’s unclassified systems in October, widely attributed to foreign state actors.
“We became aware of this intrusion a few weeks ago and immediately began working with other agencies to remediate,” Rathke said, though he declined to go into detail on any data exfiltrated.
RELATED
White House cyber breach one example of ‘daily’ attacks
Cyberattack exposes personal information of 800K Postal Service employees
‘Spear-phishing’ tactics becoming more sophisticated
Rathke said the breach only affected the State Department’s unclassified networks and interrupted the agency’s “connectivity to the Internet,” which remained down as of Monday afternoon.
Internal emails and classified systems are still operational, he said, however outside emails to State Department employees and officials will be down until further notice.
“We’re working on it as fast as we can,” Rathke said, though he declined to give an estimate on when those systems would be back online.
The department spokesman said the investigation into the source of the attack was ongoing and declined to comment on primary suspects.
“We take cybersecurity very seriously and we are well aware of the threats,” he said.
“The fact that states are trying to compromise our systems is not surprising at all,” Rick Holland, principle cybersecurity analyst at Forrester Research, said Sunday, noting that hacking has become a standard part of global espionage in the modern age, even among allies. “There is definitely a political component to this.”
Without downplaying the gravity of government systems being breached, Holland noted this fourth hacking revelation in as many weeks feels like “almost more of the same.”
“This year in particular, it seems overwhelming,” he said. “It indicates how easy it is to break into these environments.”
Judging from the fact that State Department email was shut down to remediate the breach, Holland posited that the attack was likely in the form of spear-phishing, in which a specially tailored email is sent to someone within an organization to prompt them to click through.
This tactic is often seen in cyber espionage, he said, and can be incredibly effective.
“Even for us cybersecurity guys, if we get a well-crafted email we might click on it,” he admitted. “Security awareness and training has a component … But ultimately it comes down to agencies themselves to have situational awareness — the ability for quick detection and response.”
The lesson to be learned from this most recent revelation: “If you’re a federal agency, you’re on the hit list,” he said.




