Reporters investigating Russian military intelligence have been targeted by highly sophisticated cyberattacks through their encrypted e-mail accounts, with evidence suggesting Moscow was responsible, the e-mail service provider ProtonMail and journalists said on Saturday.
The phishing attack, which sought to dupe users into sharing their ProtonMail passwords, was aimed at journalists from the award-winning Web site Bellingcat, which helped identify the agents who poisoned former Russian spy Sergei Skripal in Britain.
Geneva-based ProtonMail said in a statement that “the evidence [along with independent third-party assessments] seem to suggest an attack of Russian origin.”
ProtonMail chief executive Andy Yen said that the operation “was one of the best-run phishing attacks we have ever seen.”
Bellingcat journalist Christo Grozev, who led the site’s work on the Skripal case, said he had no doubt Russia’s GRU military intelligence unit was responsible and that it marked “a quantum leap” in terms of their technical sophistication.
“It was very convincing,” he said, noting that no Bellingcat reporters gave up their passwords.
ProtonMail, which describes itself as the world’s most secure e-mail provider, has become increasingly popular among journalists and others who handle sensitive information because user communications are protected by end-to-end encryption.
The Harvard-educated Yen, who worked at the European Organization for Nuclear Research for five years before founding ProtonMail, said that the company could not read users’ e-mails even if it wanted to — in clear contrast with Google’s Gmail.
The phishing attacks against Bellingcat reporters occurred last week, with “e-mails sent to the targeted users claiming to be from the ProtonMail team, asking the targets to enter their ... login credentials,” the company said.
Grozev said that despite his technical savvy and awareness that he was a target, he “would have been fooled” if not for prior warning from a contact who had received a similar phishing email earlier this month.
While the assault on Bellingcat journalists was concentrated over the past few days, Grozen claimed that multiple investigators and researchers from other organizations that work on Russia have received phishing e-mails in their ProtonMail accounts since April.
Yen said that “putting a precise start date as to when other Russia journalists began to be targeted is a bit more complex and not something that we can confirm with full confidence right now.”
Yen said that ProtonMail has alerted the Swiss Federal Police and the government’s computer system security office, MELANI, about the events this week.
The company has not yet received any indication that an investigation will be launched, Yen said, noting that he was not optimistic the perpetrators would face justice, in part because Moscow was likely to protect them.
However, ProtonMail is conducting its own investigation.
Grozen said Switzerland had a duty to act, given that its .ch domain was used to carry out the phishing operation.
“It is essentially a crime within the digital territory of Switzerland,” he said, stressing that the entities who registered the malicious .ch web Wites are “traceable for [Swiss] authorities”.
Swiss Federal Police and MELANI did not immediately respond to a request for comment.
Bellingcat, a highly regarded Britain-based investigative Web site, has used open-source technology to break a series of stories, notably concerning Russia, including major revelations in the downing of MH17 flight over eastern Ukraine on July 17, 2014, which has also been linked to the GRU.
DEATH CONSTANTLY LOOMING: Decades of detention took a major toll on Iwao Hakamada’s mental health, his lawyers describing him as ‘living in a world of fantasy’ A Japanese man wrongly convicted of murder who was the world’s longest-serving death row inmate has been awarded US$1.44 million in compensation, an official said yesterday. The payout represents ¥12,500 (US$83) for each day of the more than four decades that Iwao Hakamada spent in detention, most of it on death row when each day could have been his last. It is a record for compensation of this kind, Japanese media said. The former boxer, now 89, was exonerated last year of a 1966 quadruple murder after a tireless campaign by his sister and others. The case sparked scrutiny of the justice system in
The head of Shin Bet, Israel’s domestic intelligence agency, was sacked yesterday, days after Israeli Prime Minister Benjamin Netanyahu said he no longer trusts him, and fallout from a report on the Oct. 7, 2023, Hamas attack. “The Government unanimously approved Prime Minister Benjamin Netanyahu’s proposal to end ISA Director Ronen Bar’s term of office,” a statement said. He is to leave his post when his successor is appointed by April 10 at the latest, the statement said. Netanyahu on Sunday cited an “ongoing lack of trust” as the reason for moving to dismiss Bar, who joined the agency in 1993. Bar, meant to
Indonesia’s parliament yesterday amended a law to allow members of the military to hold more government roles, despite criticisms that it would expand the armed forces’ role in civilian affairs. The revision to the armed forces law, pushed mainly by Indonesian President Prabowo Subianto’s coalition, was aimed at expanding the military’s role beyond defense in a country long influenced by its armed forces. The amendment has sparked fears of a return to the era of former Indonesian president Suharto, who ex-general Prabowo once served and who used military figures to crack down on dissent. “Now it’s the time for us to ask the
‘HUMAN NEGLIGENCE’: The fire is believed to have been caused by someone who was visiting an ancestral grave and accidentally started the blaze, the acting president said Deadly wildfires in South Korea worsened overnight, officials said yesterday, as dry, windy weather hampered efforts to contain one of the nation’s worst-ever fire outbreaks. More than a dozen different blazes broke out over the weekend, with Acting South Korean Interior and Safety Minister Ko Ki-dong reporting thousands of hectares burned and four people killed. “The wildfires have so far affected about 14,694 hectares, with damage continuing to grow,” Ko said. The extent of damage would make the fires collectively the third-largest in South Korea’s history. The largest was an April 2000 blaze that scorched 23,913 hectares across the east coast. More than 3,000