Reporters investigating Russian military intelligence have been targeted by highly sophisticated cyberattacks through their encrypted e-mail accounts, with evidence suggesting Moscow was responsible, the e-mail service provider ProtonMail and journalists said on Saturday.
The phishing attack, which sought to dupe users into sharing their ProtonMail passwords, was aimed at journalists from the award-winning Web site Bellingcat, which helped identify the agents who poisoned former Russian spy Sergei Skripal in Britain.
Geneva-based ProtonMail said in a statement that “the evidence [along with independent third-party assessments] seem to suggest an attack of Russian origin.”
ProtonMail chief executive Andy Yen said that the operation “was one of the best-run phishing attacks we have ever seen.”
Bellingcat journalist Christo Grozev, who led the site’s work on the Skripal case, said he had no doubt Russia’s GRU military intelligence unit was responsible and that it marked “a quantum leap” in terms of their technical sophistication.
“It was very convincing,” he said, noting that no Bellingcat reporters gave up their passwords.
ProtonMail, which describes itself as the world’s most secure e-mail provider, has become increasingly popular among journalists and others who handle sensitive information because user communications are protected by end-to-end encryption.
The Harvard-educated Yen, who worked at the European Organization for Nuclear Research for five years before founding ProtonMail, said that the company could not read users’ e-mails even if it wanted to — in clear contrast with Google’s Gmail.
The phishing attacks against Bellingcat reporters occurred last week, with “e-mails sent to the targeted users claiming to be from the ProtonMail team, asking the targets to enter their ... login credentials,” the company said.
Grozev said that despite his technical savvy and awareness that he was a target, he “would have been fooled” if not for prior warning from a contact who had received a similar phishing email earlier this month.
While the assault on Bellingcat journalists was concentrated over the past few days, Grozen claimed that multiple investigators and researchers from other organizations that work on Russia have received phishing e-mails in their ProtonMail accounts since April.
Yen said that “putting a precise start date as to when other Russia journalists began to be targeted is a bit more complex and not something that we can confirm with full confidence right now.”
Yen said that ProtonMail has alerted the Swiss Federal Police and the government’s computer system security office, MELANI, about the events this week.
The company has not yet received any indication that an investigation will be launched, Yen said, noting that he was not optimistic the perpetrators would face justice, in part because Moscow was likely to protect them.
However, ProtonMail is conducting its own investigation.
Grozen said Switzerland had a duty to act, given that its .ch domain was used to carry out the phishing operation.
“It is essentially a crime within the digital territory of Switzerland,” he said, stressing that the entities who registered the malicious .ch web Wites are “traceable for [Swiss] authorities”.
Swiss Federal Police and MELANI did not immediately respond to a request for comment.
Bellingcat, a highly regarded Britain-based investigative Web site, has used open-source technology to break a series of stories, notably concerning Russia, including major revelations in the downing of MH17 flight over eastern Ukraine on July 17, 2014, which has also been linked to the GRU.
Young Chinese, many who fear age discrimination in their workplace after turning 35, are increasingly starting “one-person companies” that have artificial intelligence (AI) do most of the work. Smaller start-ups are already in vogue in Silicon Valley and elsewhere, with rapidly advancing AI tools seen as a welcome teammate even as they threaten layoffs at existing firms. More young people in China are subscribing to the model, as cities pledge millions of dollars in funding and rent subsidies for such ventures, in alignment with Beijing’s political goal of “technological self-reliance.” “The one-person company is a product of the AI era,” said Karen Dai
South Korea’s air force yesterday apologized for a 2021 midair collision involving two fighter jets, a day after auditors said the pilots were taking selfies and filming during the flight and held them responsible for the accident. “We sincerely apologize to the public for the concern caused by the accident that occurred in 2021,” an air force spokesman told a news conference, adding that one of the pilots involved had been suspended from flying duties, received severe disciplinary action and has since left the military. The apology followed a report released on Wednesday by the South Korean Board of Audit and Inspection,
About 240 Indians claiming descent from a Biblical tribe landed at Tel Aviv airport on Thursday as part of a government operation to relocate them to Israel. The newcomers passed under a balloon arch in blue and white, the colors of the Israeli flag, as dozens of well-wishers welcomed them with a traditional Jewish song. They were the first “bnei Menashe” (“sons of Manasseh”) to arrive in Israel since the government in November last year announced funding for the immigration of about 6,000 members of the community from the states of Manipur and Mizoram in northeast India. The community claims to descend from
‘TROUBLING’: The firing of Phelan, who was an adviser to a nonprofit that supported the defense of Taiwan, was another example of ‘dysfunction’ under Trump, a US senator said US Secretary of the Navy John Phelan has been fired, a US official and a person familiar with the matter said on Wednesday, in another wartime shakeup at the Pentagon coming just weeks after US Secretary of Defense Pete Hegseth ousted the Army’s top general. The Pentagon announced his departure in a brief statement, saying he was leaving the administration “effective immediately,” but it did not provide a reason or say whether it was his decision to go. The sources, who spoke on condition of anonymity, said Phelan was dismissed in part because he was moving too slowly to implement reforms to