SALON

Google says Chinese hackers broke into Gmail

Senior U.S. government officials, military personnel and political activists appear to have been targeted

Topics: Google, China,

Google Inc. is blaming computer hackers in China for a high-tech ruse that broke into the personal Gmail accounts of several hundred people, including senior U.S. government officials, military personnel and political activists.

The breach announced Wednesday marks the second time in 17 months that Google has publicly identified China as the home base for a scheme aimed at hijacking information stored on Google’s vast network of computers.

This round of attacks isn’t believed to be tied to a more sophisticated assault originating from China in late 2009 and early last year. That intrusion went after some of Google’s trade secrets and triggered a high-profile battle with China’s Communist government over online censorship that has made it more difficult for the company to do business in the world’s most populous country.

The latest duplicity appeared to rely on so-called “phishing” scams and other underhanded behavior that hackers frequently use to obtain passwords from people and websites that aren’t vigilant about protecting the information.

Google credited its own security measures for detecting and disrupting the intrusions. All the victims have been notified and their Gmail accounts secured, according to the company. Mila Parkour, a security researcher who helped alert Google to the Gmail breach, said the attacks had been occurring for at least a year before they were finally uncovered.

“It was persistent and bold,” Mila Parkour said of the hacking scheme in a Wednesday email exchange with The Associated Press. Parkour first shared her suspicions about the breach in a Feb. 17 post on her Contagio blog.

Google wouldn’t say what parts of the U.S. government were targeted or whether any confidential information may have been contained in the trespassed Gmail accounts. Besides senior government officials, other people whose Gmail accounts were infiltrated included Chinese political activists, military personnel, journalists and officials in other countries, mainly in South Korea.

The U.S. Department of Homeland Security didn’t shed any light in its statement on the attacks. “We are working with Google and our federal partners to review the matter, offer analysis of any malicious activity, and develop solutions to mitigate further risk,” agency spokesman Chris Ortman said.

Google traced the origin of the attacks to Jinan, China. That’s the home city of a military vocational school whose computers were linked to the assault more than a year ago on Google’s computer systems, along with those of more than 20 other U.S. companies.

That break-in prompted Google to move its Chinese-language search engine from mainland China last year so it wouldn’t have to censor content that the government didn’t want the general public to see. The search engine is now based in Hong Kong, which isn’t subject to Beijing’s censorship rules.

Before the shift, the tensions escalated amid reports that the Chinese government had at least an indirect hand in the 2009 and 2010 hacking attacks, a possibility that Google didn’t rule out.

This time around, the hackers appeared to rely on tactics commonly used to fool people into believing they are dealing with someone they know or a company that they trust. Once these “phishing” expeditions get the information needed to break into an email account, the access can be used to send messages that dupe other victims.

The culprits behind the Gmail breaches appeared to have specific targets in mind. That is known as “spear phishing” in high-tech circles.

Computer security specialist says spear phishing often provides the means for even broader attacks.

The Gmail attackers were intent on spying on inboxes, according to Google, but their ambitions beyond that were unclear.

Parkour said the hackers’ scam proved highly effective “because they used information from the emails for future phishing emails, often using information that would be known only to (the) victim — thus gaining more trust.” She said the ruse served as a reminder of the security weaknesses of Web-based email services such as Google’s.

Gmail has 221 million users worldwide, ranking it third behind the Microsoft Corp.’s Hotmail at 327 million and Yahoo Inc.’s webmail service at 277 million, according to the research firm comScore Inc.

Both Google and the Department of Homeland Security advised email users to take steps to protect their accounts. Google posted its safety tips on its blog, http://googleblog.blogspot.com/2011/06/ensuring-your-information-is-safe.html

Next Article

Featured Slide Shows

Gripping photos: The people of the Turkey protests (slideshow)

close X
  • Share on Twitter
  • Share on Facebook
  • Thumbnails
  • Fullscreen
  • 1 of 11
  • The protests take on a festive element as police forces move out of the park and square. Wearing a gas mask, this young man dances to traditional Turkish music in front of Taksim Square’s Ataturk Monument.

  • In Gezi Park since March 31st, this protester, originally caught off-guard by the Government’s teargas and water cannons, went out and bought a Russian army mask from WWII, preparing for what was to come.

  • This rambunctious boy seems to be enjoying the chaos. After taking this picture he threw a stone at the already destroyed building in the background.

  • Forming a line, the police face off directly with protesters in Taksim Square. After a while, they retreated and there was a general cheer – a back-and-forth dance that has been common since the beginning of this protest.

  • An elderly woman in Gezi Park reads the news. The tent community occupying the park was violently destroyed on June 16th.

  • Many different groups had set up booths to promote their cause in Taksim Square and Gezi Park. Standing in front of one, this man waves his flag while posing with conviction.

  • Many home-remedies are used to minimize the effects of tear gas. This woman has put a milky solution on her face, removing her mask after the tear gas dissipated. Before sunrise, the police came again for another round of teargasing.

  • People capitalize on the uprising -- selling flags, beer, gas masks, sky lanterns and spray paint to name just a few of the popular items.

  • On Monday morning, June 11, the police execute a strong offensive. Many plain-clothed police officers, like the ones seen here, clash with protesters in the side streets away from the main stand-off in Taksim.

  • The authorities seem to be most aggressive in the night, pushing protesters away from the square and park. After being teargassed this young woman catches her breath with other protesters on Siraselviler Street.

  • Recent Slide Shows

  • Share on Twitter
  • Share on Facebook
  • Thumbnails
  • Fullscreen
  • 1 of 11

Comments

2 Comments

Comment Preview

Your name will appear as username ( settings | log out )

You may use these HTML tags and attributes: <a href=""> <b> <em> <strong> <i> <blockquote>