U.S. Army Captain Michael Kelvington, commander of the Battle company, 1-508 Parachute Infantry battalion, 4th Brigade Combat Team, 82nd Airborne Division, bows next to remains of Gulam Dostager, a member of Afghan Local Police who was killed in the blast of an Improvised Explosive Device (IED) during the joint Tor Janda (Black Flag in Pashtu) operation, in Zahri district of Kandahar province, southern Afghanistan May 25, 2012.  REUTERS/Shamil Zhumatov  (AFGHANISTAN - Tags: MILITARY CIVIL UNREST CONFLICT TPX IMAGES OF THE DAY)

Reuters Photojournalism

Our day's top images, in-depth photo essays and offbeat slices of life. See the best of Reuters photography.  See more | Photo caption 

Members of the U.S. Navy Blue Angels fly over the World Trade Center in lower Manhattan as part of the 25th annual Fleet Week celebration in New York, May 23, 2012.  REUTERS/Eduardo Munoz (UNITED STATES - Tags: MILITARY ANNIVERSARY TPX IMAGES OF THE DAY)

Fleet Week

The U.S. Navy takes Manhattan for a week.  Slideshow 

Photo

The SpaceX mission

A privately owned unmanned rocket blasts off on a mission to be the first commercial flight to the International Space Station.  Slideshow 

Spies behind 2008 cyber attack, U.S. official says

Related Topics

U.S Army soldiers from Task Force Yukon use computers to surf the internet, at FOB Clark in Khowst province, December 5, 2009. REUTERS/Zohra Bensemra

U.S Army soldiers from Task Force Yukon use computers to surf the internet, at FOB Clark in Khowst province, December 5, 2009.

Credit: Reuters/Zohra Bensemra

WASHINGTON | Thu Aug 26, 2010 8:17am EDT

WASHINGTON (Reuters) - A foreign spy agency led a 2008 cyber attack on U.S. military computer systems, a top Pentagon official said, shedding light on what he called the most significant breach of American military cyber security.

Deputy Defense Secretary William Lynn said the attack took place after an infected flash-drive was inserted into a U.S. military laptop at a base in the Middle East, uploading malicious computer code onto the Central Command network.

"That code spread undetected on both classified and unclassified systems, establishing what amounted to a digital beachhead from which data could be transferred to servers under foreign control," Lynn wrote in an article for Foreign Affairs magazine published on Wednesday.

"This previously classified incident was the most significant breach of U.S. military computers ever."

Lynn did not say which country's spy agency was behind the attack. But he said that more than 100 foreign intelligence organizations were trying to break into U.S. networks.

"Some governments already have the capacity to disrupt elements of the U.S. information infrastructure," he wrote.

Every year, he said, hackers steal enough data from U.S. government agencies, businesses and universities to fill the U.S. Library of Congress many times over.

When it comes to attacks on the military, the difficulty identifying culprits behind attacks make them very hard to respond to and alluring for hostile governments, he said.

"Cyber attacks offer a means for potential adversaries to overcome overwhelming U.S. advantages in conventional military power and to do so in ways that are instantaneous and exceedingly hard to trace," he wrote.

KILL SWITCHES

Counterfeit hardware had already been detected in systems that had been procured by the Defense Department, Lynn said -- a danger since computer chips can be written with remotely operated "kill switches" and hidden backdoors.

"The risk of compromise in the manufacturing process if very real and is perhaps the least understood cyber threat," Lynn wrote.

Rogue code, including so-called "logic bombs" that cause malfunctions, can also be inserted into software as its being developed, he said.

Lynn said the attack was a wake-up call for the Pentagon, which has since launched a Cyber Command and taken measures to bolster defenses.

Policymakers now need to consider whether Pentagon capabilities should be extended to shield civilian infrastructure from attack, Lynn said. He noted that U.S. defense contractors have already been targeted "and sensitive weapons systems have been compromised."

"The U.S. government has only just begun to broach the larger question of whether it is necessary and appropriate to use national resources, such as defenses that now guard military networks, to protect civilian infrastructure," he said.

(Editing Xavier Briand)

We welcome comments that advance the story through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of Reuters. For more information on our comment policy, see http://blogs.reuters.com/fulldisclosure/2010/09/27/toward-a-more-thoughtful-conversation-on-stories/
Comments (2)
cynicalme wrote:
Knowledge IS power. The power to steal knowledge is more insidious than any enemy we can physically see.

Aug 26, 2010 1:46pm EDT  --  Report as abuse
Vertigo wrote:
Not denying that there may be a threat but let’s be certain that any measures taken to shield “civilian infrastructure” are not simply end-runs around our Constitution.

Aug 26, 2010 2:28pm EDT  --  Report as abuse
This discussion is now closed. We welcome comments on our articles for a limited period after their publication.