Why people are blaming the global cyberattack on the NSA – Politico
How the hacking tools escaped the National Security Agency is unknown. | AP Photo
This week's worldwide cybersecurity crisis is just the latest black eye for the National Security Agency and its practice of stockpiling secret means of snooping into computer systems.
Thats because whoever launched the global series of ransomware assaults is using a flaw in Microsoft Windows that the U.S. spy agency had apparently exploited for years until someone leaked the NSAs hacking tools online and allowed cyber criminals to copy them.
Story Continued Below
Now, critics ranging from Microsoft to Vladimir Putin to fugitive NSA leaker Edward Snowden are denouncing the agencys practice of stockpiling computer vulnerabilities for its own use instead of informing the developers or manufacturers so they can plug the holes. And some privacy advocates and technology experts want Congress to make the agency rein in the practice.
Heres POLITICOs summary of where that debate stands:
How did hackers get ahold of the NSAs tools?
Thats a good question. But the ransomware racing around the globe is based on a cache of apparent NSA hacking software and documents that a group calling itself the Shadow Brokers posted online on April 14. (Shadow Brokers first began making these kinds of dumps last year.) The Trump and former Obama administrations have refused to confirm that the NSA had lost control of its tools, but former intelligence officials say the leaked material is genuine.
How the hacking tools escaped the NSA is unknown. But there are three main possibilities: An NSA employee or contractor went rogue and stole the files; a sophisticated adversary such as the Russian government hacked into the spy agency and took them; or an NSA hacker accidentally left the files exposed on a server being used to stage a U.S. intelligence operation, and someone found them.
Contractors, who can lack the institutional loyalty of regular employees, have long been a source of heartache to the intelligence community, from the 2013 Snowden leaks to the arrest last year of Harold Martin, a Maryland man charged with stealing reams of classified files and hoarding them in his home.
Which NSA tool are the hackers using?
It appears to be a modified version of an NSA hacking tool, a software package dubbed ETERNALBLUE, that was buried in the Shadow Brokers leak.
The tool took advantage of a flaw in a part of Windows called the Server Message Block, or SMB, protocol, which connects computers on a shared network. In essence, the flaw allows malware to spread across networks of unpatched Windows computers, a dangerous prospect in the increasingly connected world.
After the cache leaked, cybersecurity researchers, realizing that the SMB vulnerability could expose organizations to massive hacks, reverse engineered the tool, checking how it worked and evaluating how to defeat it. These researchers posted their work online to crowdsource and accelerate the process.
But their work also helped digital thieves. At some point, the criminals behind the ransomware attack grabbed the reverse-engineered exploit and incorporated it into their malware.
This separated their attack tool from previous popular iterations of ransomware. Whereas normal ransomware locks down an infected computers files and stops there, this variant can jump from machine to machine, infecting entire businesses like the internets earliest computer worms.
What did the NSA do after learning of the theft?
The spy agency probably warned Microsoft about the vulnerability soon afterward. Microsoft released a patch for computer users to repair the flaw in March, a month before the Shadow Brokers leak.
But thats not good enough for civil liberties advocates, who want stricter limits on how long the government can hold onto vulnerabilities it discovers.
These attacks underscore the fact that vulnerabilities will be exploited not just by our security agencies, but by hackers and criminals around the world, said Patrick Toomey, a national security attorney at the American Civil Liberties Union, in a statement. Patching security holes immediately, not stockpiling them, is the best way to make everyones digital life safer.
The agencys defenders disagree. That nobody else discovered these vulnerabilities as far as we know suggests that it is right for the NSA to hold onto them if they have confidence that nobody else has a copy of their tools, Nicholas Weaver, a researcher at the University of California in Berkeley, told POLITICO. It actually is a problem that the NSA cant or wont claim credit for properly notifying Microsoft. The NSA did the right thing, and they arent getting the credit for it they deserve.
Is this a new controversy for the NSA?
No. But the crisis that began on Friday is giving it prominence like never before.
Privacy advocates and tech companies have long criticized the U.S. spy agencies for keeping knowledge of security flaws a secret and building hacking tools to exploit them. And they say its especially bad when the government cant keep its secret exploits out of the hands of cyber criminals.
When [a] U.S. nuclear weapon is stolen, its called an empty quiver, tweeted Snowden, whose 2013 leaks exposed the vast underbelly of the government's spying capacity. This weekend, [the NSAs] tools attacked hospitals.
Microsoft President Brad Smith also denounced the NSAs inability to secure its tools. An equivalent scenario with conventional weapons would be the U.S. military having some of its Tomahawk missiles stolen, he wrote in a weekend blog post.
Putin later picked up that theme, telling reporters in Beijing that U.S. intelligence agencies were clearly the initial source of the virus.
Once they're let out of the lamp, genies of this kind, especially those created by intelligence services, can later do damage to their authors and creators," the Russian leader said.
But former national security officials say the government needs to build hacking tools to keep the U.S. safe. And White House homeland security adviser Tom Bossert downplayed the possible origin of the code Monday.
Regardless of the provenance of the exploit here used, he told ABC, who is culpable are the criminals that distributed it and the criminals that weaponized it, added additional details to it, and turned this into something that is holding ransom data but also putting at risk lives and hospitals.
A daily briefing on politics and cybersecurity weekday mornings, in your inbox.
By signing up you agree to receive email newsletters or alerts from POLITICO. You can unsubscribe at any time.
Whats Congress doing?
The government uses a system called the Vulnerability Equities Process to determine whether and when agencies must tell companies about code flaws they discover. Following recent spy agency leaks, former government officials, cyber experts and tech companies have proposed changes to the VEP that would limit the intelligence communitys ability to hoard vulnerabilities.
Some are calling for Congress to act.
Those include Rep. Ted Lieu, a California Democrat with a computer science degree, who has led the charge to reform the VEP.
Lieu, a leading congressional voice on cybersecurity, called the process not transparent in a statement Friday, saying few people understand how the government makes these critical decisions. The ransomware campaign, he added, shows what can happen when the NSA or CIA write malware instead of disclosing the vulnerability to the software manufacturer.
But Lieus bill is unlikely to become law. Not only does the intelligence community have numerous defenders in Congress, but politicians simply arent paying much attention to the issue. Lawmakers haven't rushed to join Lieu in calling for VEP changes. There have only been a few hearings on ransomware in recent years, and no pending legislation mentions either ransomware or the VEP.
Martin Matishak contributed to this report.
Missing out on the latest scoops? Sign up for POLITICO Playbook and get the latest news, every morning in your inbox.
Original post:
Why people are blaming the global cyberattack on the NSA - Politico
- McConnell calls out Trump for hiring amateur isolationists at Pentagon, firing NSA director - The Hill - April 8th, 2025 [April 8th, 2025]
- Trumps firing of NSA chief is rolling out the red carpet for cyber attacks - Politico - April 8th, 2025 [April 8th, 2025]
- A conspiracy theorist convinced Trump to fire the NSA director - Vox - April 8th, 2025 [April 8th, 2025]
- William Hartman Named Acting NSA Director Following Dismissal of Top Officials - ExecutiveGov - April 8th, 2025 [April 8th, 2025]
- NSA and partners Issue Guidance on Fast Flux as a National Security Threat - National Security Agency (NSA) (.gov) - April 8th, 2025 [April 8th, 2025]
- Security News This Week: NSA Chief Ousted Amid Trump Loyalty Firing Spree - WIRED - April 8th, 2025 [April 8th, 2025]
- Head of NSA and US Cyber Command reportedly fired - Cybersecurity Dive - April 8th, 2025 [April 8th, 2025]
- Trump fires Gen. Timothy Haugh from leadership of Cyber Command and NSA - DefenseScoop - April 8th, 2025 [April 8th, 2025]
- Gen. Timothy Haugh, head of NSA and Cyber Command, is fired - CBS News - April 8th, 2025 [April 8th, 2025]
- Trump's mixed tariff messaging and NSA director and deputy fired: Morning Rundown - NBC News - April 8th, 2025 [April 8th, 2025]
- NSA Director and Deputy Reportedly Dismissed: What We Know - Newsweek - April 8th, 2025 [April 8th, 2025]
- Haugh fired from leadership of NSA, Cyber Command - The Record from Recorded Future News - April 8th, 2025 [April 8th, 2025]
- Trump administration fires head of NSA and U.S. Cyber Command, along with other top officials - CBS News - April 8th, 2025 [April 8th, 2025]
- US Cyber Command, NSA Chief Gen. Timothy Haugh ousted by Trump admin - Breaking Defense - April 8th, 2025 [April 8th, 2025]
- Face the Facts: Rep. Himes talks about firing of two top NSA officials - NBC Connecticut - April 8th, 2025 [April 8th, 2025]
- NSA Issues Advisory on Fast Flux Cyberthreat - ExecutiveGov - April 8th, 2025 [April 8th, 2025]
- Loomer, far-right activist, urged Trump to remove NSA director and others: Sources - ABC News - April 8th, 2025 [April 8th, 2025]
- The NSA Sounds Security Alarm For Billions Of iPhone And Android Phones - HotHardware - April 8th, 2025 [April 8th, 2025]
- NSA director fired after Trumps meeting with right-wing influencer Laura Loomer - The Verge - April 8th, 2025 [April 8th, 2025]
- Trump fires head of NSA and Cyber Command - Nextgov - April 8th, 2025 [April 8th, 2025]
- What are the national security concerns of Trump firing the NSA, Cyber Command head? - CBS News - April 8th, 2025 [April 8th, 2025]
- Who is Timothy Haugh? The NSA chief fired amid cyber security concerns - Times of India - April 8th, 2025 [April 8th, 2025]
- NSA, CISA, FBI, and International Partners Release Cybersecurity Advisory on Fast Flux, a National Security Threat - Hstoday - April 8th, 2025 [April 8th, 2025]
- Senator King Responds to Reported Firing of NSA Director General Timothy Haugh - WAGM - April 8th, 2025 [April 8th, 2025]
- NSA warned of vulnerabilities in Signal app a month before Houthi strike chat - CBS News - March 26th, 2025 [March 26th, 2025]
- Trump said poised to fire NSA Mike Waltz for including journalist in top secret war chat - The Times of Israel - March 26th, 2025 [March 26th, 2025]
- Not the last Waltz: Trump defends NSA after security breach - The Times of India - March 26th, 2025 [March 26th, 2025]
- NSA warned about vulnerabilities in Signal prior to White House group chat fiasco - SiliconANGLE News - March 26th, 2025 [March 26th, 2025]
- NSA warned the Signal app was vulnerable last month - WTIC - March 26th, 2025 [March 26th, 2025]
- Codebreakers and Covert Agents: The Women Behind the NSA and CIA heads to Illinois State Museum - WAND - March 26th, 2025 [March 26th, 2025]
- NSA warned about using Signal a month before leak of Houthi strike chat - CBS News - March 26th, 2025 [March 26th, 2025]
- 'Putin is giddy': NSA knew Signal was vulnerable to Russian hackers before security breach - AlterNet - March 26th, 2025 [March 26th, 2025]
- RAW: NSA MIKE WALTZ EXPECTED TO VISIT GREENLAND - Local 3 News - March 26th, 2025 [March 26th, 2025]
- US NSA likely to visit India in third week of April - Hindustan Times - March 26th, 2025 [March 26th, 2025]
- Statement from Secretary Rubio and NSA Waltz on Call with Zelenskyy - Department of State - March 22nd, 2025 [March 22nd, 2025]
- Europe must invest more in defence amid global shifts: Greeces NSA Ntokos - Firstpost - March 22nd, 2025 [March 22nd, 2025]
- NSA Bahrain, NAVCENT Hold First-of-its-Kind Exercise Vigilant Resolve - navy.mil - March 22nd, 2025 [March 22nd, 2025]
- Former NSA boss Osei Assibey Antwi picked up by NIB - GhanaWeb - March 22nd, 2025 [March 22nd, 2025]
- WHAT THE TECH? NSA recommending weekly smartphone restarts & how it improves performance - Local 3 News - March 9th, 2025 [March 9th, 2025]
- Ex-NSA cyber chief warns of devastating impact of potential DOGE-inspired firings - Breaking Defense - March 9th, 2025 [March 9th, 2025]
- Former top NSA cyber official: Probationary firings devastating to cyber, national security - CyberScoop - March 9th, 2025 [March 9th, 2025]
- Prime Targets Martha Plimpton On Her NSA Character & Why This Political Thriller Works: Never Trust People In Charge - Deadline - March 9th, 2025 [March 9th, 2025]
- Former NSA Dep. Director, Gifty Oware-Mensah will see NIB over 80k ghost names allegations - GhanaWeb - March 5th, 2025 [March 5th, 2025]
- Zelensky is not ready for peace talks, US NSA says - Mehr News Agency - English Version - March 3rd, 2025 [March 3rd, 2025]
- More Than 100 Intelligence Staffers Will Be Fired Over Sexually Explicit Texts In NSA Chatrooms, Gabbard Says - Forbes - March 1st, 2025 [March 1st, 2025]
- NSA says it is investigating potential misuse of chat platform - The Record from Recorded Future News - March 1st, 2025 [March 1st, 2025]
- 100-plus spies fired after NSA internal chat board used for kinky sex talk - The Register - March 1st, 2025 [March 1st, 2025]
- Tulsi Gabbard says more than 100 intelligence officers will be fired for sexually explicit NSA chat messages - CNN - March 1st, 2025 [March 1st, 2025]
- Elon Asked What Government Workers Did. The NSA Overshared - Schiff Sovereign - March 1st, 2025 [March 1st, 2025]
- Tulsi Gabbard Fires 100 Intelligence Officers for Sex Chats on NSA-Hosted Tool - The Daily Beast - March 1st, 2025 [March 1st, 2025]
- Elon Musk reacts to leaked chat alleging NSA, CIA officials discussed raising intersex babies as non-bina - The Times of India - March 1st, 2025 [March 1st, 2025]
- What NSA, DIA agents said about Libs of TikTok, Ben Shapiro in leaked messages - The Times of India - March 1st, 2025 [March 1st, 2025]
- NSA staff accused of lurid sex chats at work they were just discussing LGBTQ+ issues - PinkNews - March 1st, 2025 [March 1st, 2025]
- Sen. Tom Cotton reacts to lewd NSA chats: 'We don't want these people anywhere near classified information' - Fox News - March 1st, 2025 [March 1st, 2025]
- At least 100 NSA staffers to be fired for explicit chats during work hours - WDRB - March 1st, 2025 [March 1st, 2025]
- Gifty Oware-Mensah on the run as NIB investigates NSA scandal - GhanaWeb - February 25th, 2025 [February 25th, 2025]
- Former NSA, Cyber Command chief Paul Nakasone says U.S. falling behind its enemies in cyberspace - CyberScoop - February 25th, 2025 [February 25th, 2025]
- NSA emphasizes strong defensive posture as it responds to report it hacked China - Washington Times - February 25th, 2025 [February 25th, 2025]
- How the NSA Head of Accounts was undermined by his deputy for eight months after appointment - GhanaWeb - February 25th, 2025 [February 25th, 2025]
- What Is Proteus in Zero Day? How the NSA Weapon Changes Everything - Collider - February 25th, 2025 [February 25th, 2025]
- 'Zelenskyy will sign the minerals deal, no matter': US NSA Mike Waltz on Trump's Ukraine plan - The Economic Times - February 25th, 2025 [February 25th, 2025]
- EXCLUSIVE: Clearcover launches Illinois-based reciprocal exchange to jumpstart entry into NSA - Re-Insurance.com - February 12th, 2025 [February 12th, 2025]
- Chief of Naval Operations Visits NSA Crane, Purdue University [Image 18 of 25] - DVIDS - February 12th, 2025 [February 12th, 2025]
- Liminal Health Launches NSA ClearPath: Revolutionizing Reimbursement for Out-of-Network Providers - PR Newswire - February 12th, 2025 [February 12th, 2025]
- Elon Musks D.O.G.E is giving the CIA and NSA nightmares now - MSN - February 12th, 2025 [February 12th, 2025]
- NSA Ajit Doval likely to visit US along with PM Modi - The Economic Times - February 12th, 2025 [February 12th, 2025]
- The NSA says do these 5 things with your phone right now - Fox News - January 30th, 2025 [January 30th, 2025]
- NSA: Iraqi territory will not be used to attack neighboring countries Iraqi News Agency - ina.iq - January 30th, 2025 [January 30th, 2025]
- NDC is not here to witch-hunt - Opare Addo to NSA staff - GhanaWeb - January 30th, 2025 [January 30th, 2025]
- NSA Warns iPhone And Android UsersDisable Location Tracking - Forbes - January 19th, 2025 [January 19th, 2025]
- Trumps incoming NSA: Hamas must have no role in governing Gaza - JNS.org - January 19th, 2025 [January 19th, 2025]
- Trump NSA Disputes Report That Neocons Are Influencing MAGA Staffing - RealClearDefense - January 19th, 2025 [January 19th, 2025]
- US NSA lauds Ajit Doval for pivoting ties to advanced future tech - The Times of India - January 9th, 2025 [January 9th, 2025]
- Auto insurtech Clearcover expands into Texas NSA market with CGA launch - Re-Insurance.com - January 9th, 2025 [January 9th, 2025]
- "Cannot Think Of A Better Way To End My Tenure": US NSA On His India Visit - NDTV - January 9th, 2025 [January 9th, 2025]
- Heightened Security At U.S. Naval Academy And NSA Annapolis: Public Access Suspended Amid Increased Force Protection Measures - Bay Net - January 9th, 2025 [January 9th, 2025]
- From The Seabed To The Stars: 10 Takeaways From U.S. NSA Sullivans Visit - Strategic News Global - January 9th, 2025 [January 9th, 2025]
- NSA Sullivan to visit India to finalise important ongoing initiatives: White House - The Hindu - January 9th, 2025 [January 9th, 2025]
- What NSA Jake Sullivans India Visit Signals For Nuclear And Tech Ties As US Lifts Curbs On Indian Entities - Swarajya - January 9th, 2025 [January 9th, 2025]
- NSA Sullivan arrives today, seeks to strengthen AI, space, tech ties - The Tribune India - January 9th, 2025 [January 9th, 2025]