December 18, 2020
24,584
188
271
1.87%
Every word spoken in this episode is indexed. Type any phrase to jump straight to the moment it was said.
Type any word or phrase that may have been spoken. Click a result to seek the player to that exact moment.
Try a name, a topic, or a quoted line
5:31Now PlayingIt was clear from the start that a cyber attack by suspected Russian hackers aimed at several U.S. government agencies was going to be bad. One clue: National Security Advisor Robert O’Brien cut short a trip overseas early this week to rush back to Washington to help manage the crisis.
But on Thursday, the reality of just how sprawling -- and potentially damaging -- the breach might be came into sharper focus. It started with a bulletin from the U.S. Cybersecurity and Infrastructure Security Agency, known as CISA, warning that the hackers were sophisticated, patient and well-resourced, representing a “grave risk” to federal, state and local governments as well as critical infrastructure and the private sector. It didn’t take long to see how accurate the agency’s assessment was.
Bloomberg News reported that at least three state governments were hacked. That was followed by reports of other breaches: the city network in Austin, Texas, and the U.S. nuclear weapons agency. Late in the day software giant Microsoft Corp. said its systems were exposed.
The U.S. Department of Energy and its National Nuclear Security Administration, which maintains the country’s nuclear stockpile, said that the malware was isolated to business networks and didn’t affect national security functions.
Nonetheless, the effect of Thursday’s revelations was confirmation that no single person or agency -- including the highest reaches of the U.S. government -- is certain of exactly what the hackers had infiltrated, let alone the full extent of what was taken. A Kremlin official has denied the allegations.
President-elect Joe Biden interrupted a series of high-profile appointment announcements to weigh in: “I want to be clear: my administration will make cybersecurity a top priority at every level of government – and we will make dealing with this breach a top priority from the moment we take office.”
So far, President Donald Trump hasn’t commented on the attack, though some members of Congress issued chilling statements, if few actual details.
“We already know enough about the hack to know that it’s deeply damaging and dangerous,” Representative Adam Schiff, chairman of the House Intelligence Committee, said on Thursday.
The hackers installed what is known as a backdoor in widely used software from Texas-based SolarWinds Corp., whose customers include myriad government agencies and Fortune 500 companies. That malicious backdoor, which was installed by some 18,000 SolarWinds customers, allowed the hackers access to their computer networks.
The suspected Russian hackers didn’t have the time nor inclination to raid the computers of all 18,000 customers, so they focused on targets of high value to one of the West’s most pernicious adversaries. U.S. authorities -- and governments around the world -- are only now beginning to uncover who was unlucky enough to get the hackers’ full attention.
For investigators, the identification of breached agencies -- a list that includes the State, Treasury and Commerce departments as well as the Department of Homeland Security -- is only the first step. The harder part is determining what the hackers stole while they were roaming through the networks.
On Thursday, CISA, the U.S. cyber agency, suggested there could be an entirely different batch of victims beyond SolarWinds’ customers. The agency said it had evidence that SolarWinds’ Orion software wasn’t the only “access vector” used by the hackers, meaning they could have had other methods of penetrating computer networks.
The Russian attack was uncovered this month after cybersecurity firm FireEye Inc. discovered that its computers had been rifled. Microsoft executives said Thursday that a number of cybersecurity companies were among those hacked. That matches a government assessment that such firms were high on the alleged Russia hackers’ priority list, according to a person familiar with the inquiry.
Subscribe to our YouTube channel
Bloomberg Quicktake brings you live global news and original shows spanning business, technology, politics and culture. Make sense of the stories changing your business and your world.
To watch complete coverage on Bloomberg Quicktake 24/7, visit or watch on Apple TV, Roku, Samsung Smart TV, Fire TV and Android TV on the Bloomberg app.
Have a story to tell? Fill out this survey for a chance to have it featured on Bloomberg Quicktake
Connect with us on…
Breaking News on YouTube
Sentinel Indexing in Progress
Metadata and chapters are available. Claim extraction for this episode is pending.
All video content is delivered via YouTube embedded players in accordance with the YouTube Terms of Service. Sentinel provides research tools that promote discovery and accountability across political media.