President-elect Joe Biden warned that his administration would impose “substantial costs” on those responsible for a cyberhack that federal officials say went beyond military, nuclear and intelligence sites to impact vast areas of government activity.
Federal officials said Thursday that the penetration represented a “grave risk to the federal government,” reports the New York Times.
As investigators take stock of the damage and try understand what has been stolen, Biden warned, “A good defense isn’t enough; we need to disrupt and deter our adversaries from undertaking significant cyberattacks in the first place.”
President Donald Trump has yet to say anything about the attack. But in an op ed published Thursday in the New York Times, Trump’s former homeland security adviser Thomas Bossert wrote that the cybersaboteurs linked to Russian intelligence are now likely deeply embedded within U.S. networks and it will be hard to remove them without a major commitment by the government.
He appealed to Congress for legislation authorizing the Department of Homeland Security to do “network hunting” across the federal system.
“An intrusion so brazen and of this size and scope cannot be tolerated by any sovereign nation,” Bossert wrote. “Leadership is essential.”
Microsoft said it had identified 40 companies, government agencies and think tanks that the suspected Russian hackers had infiltrated. Nearly half are private technology firms, many of them cybersecurity firms, like FireEye, that are supposed to be securing vast sections of the public and private sector.
The Energy Department and its National Nuclear Security Administration, which maintains the U.S. nuclear stockpile, were compromised as part of the larger attack, but its investigation found the hack did not affect “mission-essential national security functions.”
Intelligence agencies have told Congress that they believe the attack was carried out by the S.V.R., an elite Russian intelligence agency.
A Microsoft “heat map” of infections shows that 80 percent are in the U.S., while Russia shows no infections at all. Investigators believe the goal of the Russian attack was traditional espionage.
Additional Reading: Officials Scramble to Assess Damage