The hackers’ greatest asset is our complacency

A false tweet from Associated Press claimed Obama had been injured by a bomb

Share
Related Topics

Last week, The Independent and i joined the list of organisations to be targeted by the Syrian Electronic Army or SEA. The email address of a former staff member was being used to approach other colleagues. The email contained a link: when they clicked on the link, it asked for a password; if they had complied, then our entire system would have been compromised.

Fortunately, we spotted it before any harm was done. What could have happened? Well, anything from our production operation and websites breaking down, to messages going out in our name in support of the Syrian President, Bashar al-Assad.

We were the latest media company to be on the receiving end of the SEA’s attacks. They include Facebook and Twitter – the accounts of President Obama and Nicolas Sarkozy were hacked – and Al Jazeera, BBC, Reuters and Associated Press. In the case of the BBC, its weather service sent out tweets that were explicitly anti-Israel and pro-Assad.

I confess, until then, I’d been fairly blasé about cyber-attacks. Sure, I’d received my fair share of Nigerian fraud emails and the like down the years. What was different about the SEA effort was the level of sophistication.  The SEA is not to be taken lightly. In April this year, a false tweet from the Associated Press news agency claimed the White House had been bombed and President Obama was injured. It led to a $136.5bn collapse in the S&P 500 before order could be restored.

A leader of the SEA has claimed it is not officially aligned to the Assad regime. But it uses a domain name that must be approved by the Syrian government and a previous address was traceable to the Syrian Computer Society. The head of that society, until he took charge of the entire country, was one Bashar al-Assad. The President has lauded the SEA, calling  it “a real army in a virtual reality”.

Assad’s software soldiers, official or not, are just one manifestation of a phenomenon that has been sweeping the globe. Very few of us are treating cyber-crime seriously enough. Everyone is at risk, and the infiltration can come at any time.

The Bank of England is aware of the problem – how can it not be – and has launched one large-scale exercise already to test the computer defences of the major banks. Called Operation Waking Shark, it consisted of a day-long simulated systems invasion, entailing sustained efforts to break into payments and accounts across the entire industry, and took place two years ago. Next month, Operation Waking Shark 2, involving the Bank, Financial Conduct Authority and Treasury, will see how the security barriers have improved.

I’m all for it but it also makes me nervous. First, the name smacks of a curiously British attitude – you imagine they must have spent hours choosing it and had great fun in the process. Then, an awful lot can change in two years – just look at the speed of technological advancement. We should be holding them every six months at least.

Likewise, when I see the official bodies running it, I shudder: I want to see the participation of real, tough, organised crime and anti-terror experts, who are used to moving quickly and decisively and are familiar with how the perpetrators think and behave. I wonder how many Whitehall memos must go back and forth agreeing on the outcome of the exercise and the new controls to be recommended, and how long the whole thing will take. The hackers, I can’t help thinking, are several steps ahead.

That’s not to knock the good intention, but are Operations Waking Shark 1 and 2 really enough? Shouldn’t we be receiving repeated warnings and advice as to what information we can safely put up online and what is dangerous? Banks have spent fortunes on their defences but this is meaningless if details that give someone access to employee or customer files can be easily obtained elsewhere.

We’ve got into a bad habit of sharing too much information about ourselves with the world at large, via Facebook, Twitter and LinkedIn. As we almost discovered to our cost, there are tonnes of material out there that could be useful to a hacker, in numerous directories that includes email addresses of ex-employees. If you receive an email that ontains some detail that is accurate or is from someone you know, you’re bound to be more likely to open it, aren’t you?

If I was the Government I would resolve that cyber-crime is the biggest threat our financial system faces and make all manner of manpower and equipment available to combat it. Have the police got their priorities right?

The IRA said after the Brighton bombing: “We only have to be lucky once – you have to be lucky always.” The same is true of the hackers.

Chris Blackhurst is Group Content Director

Latest stories from i100
Have you tried new the Independent Digital Edition apps?
iJobs Job Widget
iJobs General

Selby Jennings: VP/SVP Credit Quant- NY- Investment Bank

Not specified: Selby Jennings: VP/SVP Credit Quant Top tier investment bank i...

Ashdown Group: Senior Marketing Executive- City of London, Old Street

£40000 - £43000 per annum + benefits: Ashdown Group: Senior Marketing Executiv...

Ashdown Group: Marketing Manager

£40000 - £43000 per annum + benefits: Ashdown Group: An international organisa...

Ashdown Group: Internal Recruiter -Rugby, Warwickshire

£25000 - £30000 per annum: Ashdown Group: Internal Recruiter -Rugby, Warwicksh...

Day In a Page

Read Next
 

Errors & Omissions: pours or pores, pulverised, ‘in preference for’ and lists

Guy Keleny
Ed Miliband created a crisis of confidence about himself within Labour when he forgot to mention the deficit in his party conference speech  

The political parties aren't all the same – which means 2015 will be a 'big-choice' election

Andrew Grice
Aren’t you glad you didn’t say that? The worst wince-and-look-away quotes of the year

Aren’t you glad you didn’t say that?

The worst wince-and-look-away quotes of the year
Hollande's vanity project is on a high-speed track to the middle of nowhere

Vanity project on a high-speed track to nowhere

France’s TGV network has become mired in controversy
Sports Quiz of the Year

Sports Quiz of the Year

So, how closely were you paying attention during 2014?
Alexander Armstrong on insulting Mary Berry, his love of 'Bargain Hunt', and life as a llama farmer

Alexander Armstrong on insulting Mary Berry and his love of 'Bargain Hunt'

From Armstrong and Miller to Pointless
Sanchez helps Gunners hold on after Giroud's moment of madness

Sanchez helps Gunners hold on

Olivier Giroud's moment of madness nearly costs them
A Christmas without hope: Fears grow in Gaza that the conflict with Israel will soon reignite

Christmas without hope

Gaza fears grow that conflict with Israel will soon reignite
After 150 years, you can finally visit the grisliest museum in the country

The 'Black Museum'

After 150 years, you can finally visit Britain's grisliest museum
No ho-ho-hos with Nick Frost's badass Santa

No ho-ho-hos with Nick Frost's badass Santa

Doctor Who Christmas Special TV review
Chilly Christmas: Swimmers take festive dip for charity

Chilly Christmas

Swimmers dive into freezing British waters for charity
Veterans' hostel 'overwhelmed by kindness' for festive dinner

Homeless Veterans appeal

In 2010, Sgt Gary Jamieson stepped on an IED in Afghanistan and lost his legs and an arm. He reveals what, and who, helped him to make a remarkable recovery
Isis in Iraq: Yazidi girls killing themselves to escape rape and imprisonment by militants

'Jilan killed herself in the bathroom. She cut her wrists and hanged herself'

Yazidi girls killing themselves to escape rape and imprisonment
Ed Balls interview: 'If I think about the deficit when I'm playing the piano, it all goes wrong'

Ed Balls interview

'If I think about the deficit when I'm playing the piano, it all goes wrong'
He's behind you, dude!

US stars in UK panto

From David Hasselhoff to Jerry Hall
Grace Dent's Christmas Quiz: What are you – a festive curmudgeon or top of the tree?

Grace Dent's Christmas Quiz

What are you – a festive curmudgeon or top of the tree?
Nasa planning to build cloud cities in airships above Venus

Nasa planning to build cloud cities in airships above Venus

Planet’s surface is inhospitable to humans but 30 miles above it is almost perfect