Don’t do SECURITY. Do business SECURELY.

Democratic National Committee reveals Russian-linked hack of its network

The DNC disclosed that hackers linked by investigators to the Russian government had breached its network and stolen research.

The Democratic National Committee disclosed that its computer network had been breached, and security firm CrowdStrike linked the intrusions to two groups associated with Russian intelligence. The stolen material was later leaked during the US presidential campaign. The breach became one of the defining cyber security stories of the 2016 US presidential election.

What happened

  • The Washington Post reported on 14 June 2016 that intruders had gained access to the network and stolen opposition research.
  • CrowdStrike attributed the intrusions to two groups known as Cozy Bear and Fancy Bear.
  • In July 2016 WikiLeaks published thousands of DNC emails, and the committee’s chair resigned.
  • In October 2016 US intelligence agencies publicly attributed the hacking to the Russian government, and in 2018 a US grand jury indicted 12 Russian military intelligence officers.

Why it mattered

The incident brought ‘hack and leak’ operations to the centre of politics and prompted governments worldwide to review the cyber security of elections and political parties.

Lessons for organisations

Phishing awareness, multi-factor authentication, and prompt incident response are vital for any organisation handling politically or commercially sensitive information. Political parties, campaigns, and think tanks should assume they are targets of state-backed attackers.

Source: The Washington Post

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights