The Democratic National Committee disclosed that its computer network had been breached, and security firm CrowdStrike linked the intrusions to two groups associated with Russian intelligence. The stolen material was later leaked during the US presidential campaign. The breach became one of the defining cyber security stories of the 2016 US presidential election.
What happened
- The Washington Post reported on 14 June 2016 that intruders had gained access to the network and stolen opposition research.
- CrowdStrike attributed the intrusions to two groups known as Cozy Bear and Fancy Bear.
- In July 2016 WikiLeaks published thousands of DNC emails, and the committee’s chair resigned.
- In October 2016 US intelligence agencies publicly attributed the hacking to the Russian government, and in 2018 a US grand jury indicted 12 Russian military intelligence officers.
Why it mattered
The incident brought ‘hack and leak’ operations to the centre of politics and prompted governments worldwide to review the cyber security of elections and political parties.
Lessons for organisations
Phishing awareness, multi-factor authentication, and prompt incident response are vital for any organisation handling politically or commercially sensitive information. Political parties, campaigns, and think tanks should assume they are targets of state-backed attackers.
Source: The Washington Post
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.