Get 40% Off
🚨 Volatile Markets? Find Hidden Gems for Serious OutperformanceFind Stocks Now

Exclusive: FBI probing cyber attack on congressional campaign in California - sources

Published 08/17/2018, 06:22 PM
Updated 08/17/2018, 06:30 PM
© Reuters. The FBI building is seen in Washington

By Joel Schectman and Christopher Bing

WASHINGTON (Reuters) - The U.S. Federal Bureau of Investigation is investigating a cyber attack on the congressional campaign of a Democratic candidate in California, according to three people close to the campaign.

The hackers successfully infiltrated the election campaign computer of David Min, a Democratic candidate for the House of Representatives who was later defeated in the June primary for California's 45th Congressional district.

The incident, which has not been previously reported, follows an article in Rolling Stone earlier this week that the FBI has also been investigating a cyber attack against Hans Keirstead, a California Democrat. He was defeated in a primary in the 48th Congressional district, neighboring Min's.

Paige Hutchinson, Min's former campaign manager, declined to comment. An FBI spokeswoman said the bureau cannot confirm or deny an investigation.

While both Min and Keirstead later lost to other primary challengers from their own party, the two closely-watched races are considered critical, competitive battlegrounds as the Democrats seek to win back Congress from Republicans in November.

It is unclear who was behind the attack against Min's campaign, why it was carried out, and what the hackers did with any information they obtained. But details of the hack, described to Reuters by people with direct knowledge of the case, highlight the concerns of national security experts who fear that campaigns are woefully unprotected as the November mid-term elections approach.

It also illustrates how small political campaigns do not have the resources to protect themselves from cyber attacks. Few can hire computer security personnel.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

"Political campaigns only exist for such a short amount of time," said Blake Darche, a cyber security researcher and former National Security Agency analyst. "It takes years to build an effective security program at most corporations. Most political campaigns are only a single phishing email away from being breached."

While national political parties offer training and software tools to help candidates, they typically do not provide them with financial support to hire computer security experts, even after a campaign believes it has been hit. Corporations often pay security experts more than $100,000 to investigate an attack, security experts say.

UNUSUAL ACTIVITY

In late March, Min's staff received a troubling notice from the facility manager where the campaign rented space in Irvine, California, said the people close to the campaign. The facility's internet provider had identified unusual patterns of activity that could indicate a cyber attack on campaign computers.

The four-person campaign team had no in-house expertise to deal with the attack. Instead they enlisted the help of software developers with no ties to the campaign other than that they sat nearby in the same shared workspace that Min rented.

The software developers discovered that hackers had placed software into the computers of Min's campaign manager and finance director that recorded and transmitted keystrokes. The hackers had also infected the computers with software that made it undiscoverable by the off-the-shelf anti-virus software used by the campaign staff.

The campaign immediately notified the Democratic Congressional Campaign Committee, the organization that assists the party's candidates. The DCCC notified the FBI and gave the campaign advice on improving its security. It also provided it with secure messaging software for future use. Federal agents interviewed Min's staff and carried off the infected computers.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

Min's tiny staff considered hiring a security firm to investigate the attack, but decided the $50,000 minimum price was unaffordable. The DCCC did not cover the costs of such a hire.

"The DCCC's mission is to elect Democrats to Congress, and we spend the vast majority of our limited resources to do that," a DCCC aide, who declined to named, said. "Despite that, the DCCC has gone far outside the scope of its mission to protect the committee and help campaigns protect themselves when it comes to cybersecurity."

Ultimately, the campaign's defense was limited to replacing the infected machines and a future commitment to using encrypted messaging apps. "Even $4,000 to replace those laptops isn't easy to get," said a person close to the campaign.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.