Pentagon hacked by Chinese People’s Liberation Army

happygeek 0 Tallied Votes 633 Views Share

According to a report in the Financial Times of all publications, the Chinese military has hacked the Pentagon in what it describes as the most successful cyber attack on the US defense department to date.

Although the Pentagon has acknowledged that a computer system which serves the office of US Defense Secretary Robert Gates was shut down for more than a week, officially it refuses to comment upon whom it believes initiated the attack. However, the FT claims that both current and former Pentagon officials have told it that an internal investigation following the breach, which occurred in June, revealed that the People’s Liberation Army had been pinpointed as the source. The PLA is thought to engage in regular probes of US military networks, just as the Pentagon probes Chinese military networks.

The attack on the Pentagon follows reports of similar infiltration of German government computers which have widely been reported as being of Chinese origin. Indeed, on a recent visit to Beijing the German chancellor, Angela Merkel, brought the matter up with the Chinese premier, Wen Jiabao. This prompted the Chines foreign ministry to release an official statement condemning any such ‘criminal acts’ that undermine computer systems ‘including hacking’ and going on to claim that China itself was the victim of many such attacks.

Whether George W. Bush brings the matter up with the Chinese president, Hu Jintao, later in the week when the two meet up before the Apec summit in Australia remains to be seen.

Dani AI

Generated

A short, practical primer and what to take away from this thread.

As reported, reputable outlets in September 2007 covered an intrusion that forced the Pentagon to take part of a Defense Department e-mail/network system offline; some U.S. officials told reporters the internal probe pointed at China’s military, though the department did not publicly attribute the intrusion at the time. (arstechnica.com)

That doesn’t mean core weapons systems were exposed. The Department of Defense runs separate networks for different classification levels (NIPRNet for unclassified-but-sensitive work, SIPRNet for Secret, JWICS for Top Secret), and attackers typically target the easiest paths — contractors, unclassified systems, and administrative services. Long-running campaigns that probed U.S. defense and contractor networks (often called examples like “Titan Rain”) show this pattern: persistent access to low/med‑value systems is a prize for espionage. (gao.gov)

To address some forum points: is correct that a random Internet server can’t casually “launch” nuclear weapons — nuclear command-and-control is designed to be separate and to require human, multi-person controls — but modernization and networked support systems add attack surfaces, and air gaps are not a perfect guarantee (see Stuxnet as a real-world example of jumping isolated networks). In short: direct remote launch is extremely unlikely, but cyber operations can steal data, disrupt communications, or create dangerous ambiguity. (armscontrol.org)

If the goal is useful next steps (for sysadmins, contractors, or policy readers), focus on defense-in-depth and practice: inventory assets and critical data flows; enforce strict segmentation and least privilege; ban/monitor removable media; apply DISA/NIST hardening and automated compliance tools; deploy EDR/IDS+SIEM and continuous logging; run tabletop and red‑team drills; and implement an incident-response playbook per NIST guidance so containment + forensics happen fast. These are the concrete controls that reduce days‑long outages and data loss. (public.cyber.mil)

Key reading to verify claims and to build a response program: contemporary coverage of the 2007 reporting, DoD network descriptions (NIPR/SIPR/JWICS), historical Chinese‑origin campaigns, NIST incident‑response guidance, and DISA STIGs for concrete hardening.

lasher511 185 Veteran Poster

Heh heh typical americans. Yes we got hacked but look all these other people did as well so its not that bad.

Chaky 191 Posting Virtuoso

Couple of kids in Croatia hacked Pentagon 4-5 years ago. Nobody knows what and how much has been compromised. I wonder why, oh, why is Pentagon relying so much on Internet (I bet they use Windows too)... I know that it is their baby, but... man! , Can't they get the hint? For God's sake, get it in your thick, army brain-washed head (in the sand): YOU WILL GET HACKED OVER AND OVER AGAIN! Nobody wants to see world's most powerful arsenal's trigger in the some 9yo kid/hacker/anarchist/terrorist/any-kind-of-totalitarist trigger happy hands.

pygmalion 2 Junior Poster in Training

a lot of hackers are attempting to hack government servers, for obvious reasons.

Nobody wants to see world's most powerful arsenal's trigger in the some 9yo

i doubt their atomic arsenal can be triggered by a casual server connected to the internet. :X

also, already in 2001, Ehud Tenenbaum, an Israeli teenager hacked into the Pentagon and many other military servers in the U.S and Israel.

Chaky 191 Posting Virtuoso

I explicitly recall the words "we don't know if they gained access to the nuclear missile system" spoken by some Pentagon official when those kids hacked them. If you ask me, dumb thing is that Pentagon is connected AT ALL to internet. Huge liability.

scru 909 Posting Virtuoso Featured Poster

Sometimes I believe that some of those government agencies are run by a dumbed down hard-headed alien civilisation (and Bush is their front man xP).

Seriously though. Being hacked one time isn't enough to decided to severe their systems from internet access? Imho, things like that, you can't just slap a band-aid on and pretend it didn't happen...

especially with China...

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.