Reporters investigating Russian military intelligence have been targeted by highly sophisticated cyberattacks through their encrypted e-mail accounts, with evidence suggesting Moscow was responsible, the e-mail service provider ProtonMail and journalists said on Saturday.
The phishing attack, which sought to dupe users into sharing their ProtonMail passwords, was aimed at journalists from the award-winning Web site Bellingcat, which helped identify the agents who poisoned former Russian spy Sergei Skripal in Britain.
Geneva-based ProtonMail said in a statement that “the evidence [along with independent third-party assessments] seem to suggest an attack of Russian origin.”
ProtonMail chief executive Andy Yen said that the operation “was one of the best-run phishing attacks we have ever seen.”
Bellingcat journalist Christo Grozev, who led the site’s work on the Skripal case, said he had no doubt Russia’s GRU military intelligence unit was responsible and that it marked “a quantum leap” in terms of their technical sophistication.
“It was very convincing,” he said, noting that no Bellingcat reporters gave up their passwords.
ProtonMail, which describes itself as the world’s most secure e-mail provider, has become increasingly popular among journalists and others who handle sensitive information because user communications are protected by end-to-end encryption.
The Harvard-educated Yen, who worked at the European Organization for Nuclear Research for five years before founding ProtonMail, said that the company could not read users’ e-mails even if it wanted to — in clear contrast with Google’s Gmail.
The phishing attacks against Bellingcat reporters occurred last week, with “e-mails sent to the targeted users claiming to be from the ProtonMail team, asking the targets to enter their ... login credentials,” the company said.
Grozev said that despite his technical savvy and awareness that he was a target, he “would have been fooled” if not for prior warning from a contact who had received a similar phishing email earlier this month.
While the assault on Bellingcat journalists was concentrated over the past few days, Grozen claimed that multiple investigators and researchers from other organizations that work on Russia have received phishing e-mails in their ProtonMail accounts since April.
Yen said that “putting a precise start date as to when other Russia journalists began to be targeted is a bit more complex and not something that we can confirm with full confidence right now.”
Yen said that ProtonMail has alerted the Swiss Federal Police and the government’s computer system security office, MELANI, about the events this week.
The company has not yet received any indication that an investigation will be launched, Yen said, noting that he was not optimistic the perpetrators would face justice, in part because Moscow was likely to protect them.
However, ProtonMail is conducting its own investigation.
Grozen said Switzerland had a duty to act, given that its .ch domain was used to carry out the phishing operation.
“It is essentially a crime within the digital territory of Switzerland,” he said, stressing that the entities who registered the malicious .ch web Wites are “traceable for [Swiss] authorities”.
Swiss Federal Police and MELANI did not immediately respond to a request for comment.
Bellingcat, a highly regarded Britain-based investigative Web site, has used open-source technology to break a series of stories, notably concerning Russia, including major revelations in the downing of MH17 flight over eastern Ukraine on July 17, 2014, which has also been linked to the GRU.
Republican US lawmakers on Friday criticized US President Joe Biden’s administration after sanctioned Chinese telecoms equipment giant Huawei unveiled a laptop this week powered by an Intel artificial intelligence (AI) chip. The US placed Huawei on a trade restriction list in 2019 for contravening Iran sanctions, part of a broader effort to hobble Beijing’s technological advances. Placement on the list means the company’s suppliers have to seek a special, difficult-to-obtain license before shipping to it. One such license, issued by then-US president Donald Trump’s administration, has allowed Intel to ship central processors to Huawei for use in laptops since 2020. China hardliners
Conjoined twins Lori and George Schappell, who pursued separate careers, interests and relationships during lives that defied medical expectations, died this month in Pennsylvania, funeral home officials said. They were 62. The twins, listed by Guinness World Records as the oldest living conjoined twins, died on April 7 at the Hospital of the University of Pennsylvania, obituaries posted by Leibensperger Funeral Homes of Hamburg said. The cause of death was not detailed. “When we were born, the doctors didn’t think we’d make 30, but we proved them wrong,” Lori said in an interview when they turned 50, the Philadelphia Inquirer reported. The
RAMPAGE: A Palestinian man was left dead after dozens of Israeli settlers searching for a missing 14-year-old boy stormed a village in the Israeli-occupied West Bank US President Joe Biden on Friday said he expected Iran to attack Israel “sooner, rather than later” and warned Tehran not to proceed. Asked by reporters about his message to Iran, Biden simply said: “Don’t,” underscoring Washington’s commitment to defend Israel. “We are devoted to the defense of Israel. We will support Israel. We will help defend Israel and Iran will not succeed,” he said. Biden said he would not divulge secure information, but said his expectation was that an attack could come “sooner, rather than later.” Israel braced on Friday for an attack by Iran or its proxies as warnings grew of
A prominent Christian leader has allegedly been stabbed at the altar during a Mass yesterday in southwest Sydney. Bishop Mar Mari Emmanuel was saying Mass at Christ The Good Shepherd Church in Wakeley just after 7pm when a man approached him at the altar and allegedly stabbed toward his head multiple times. A live stream of the Mass shows the congregation swarm forward toward Emmanuel before it was cut off. The church leader gained prominence during the COVID-19 pandemic, amassing a large online following, Officers attached to Fairfield City police area command attended a location on Welcome Street, Wakeley following reports a number