US security secrets stolen in Russian NSA hack: reports

Hacking tools allegedly snatched when worker loaded them onto home computer

NSA data

Russian state-sponsored hackers stole highly classified US cyber security information from the NSA in 2015, it has been claimed.

According reports from the Wall Street Journal and Washington Post, the breach occurred when a person working in the US spy agency's "elite hacking unit" Tailored Access Operations (TAO) loaded the information onto their home computer.

TAO is the division of the NSA that "develops tools to penetrate computers overseas to gather foreign intelligence", according to the Washington Post's sources. In particular, the information taken by the person involved included hacking tools that were being developed to replace those considered compromised in the Snowden leaks.

It's currently unclear if the individual was an independent contractor, as claimed by the WSJ, or an employee, as claimed by the Washington Post, but they are unified in their claim that Kaspersky Lab antivirus software installed on the individual's computer was used as the conduit to identify and access the material.

Kaspersky Lab has hit back at the allegations, reiterating it "does not have inappropriate ties to any government, including Russia, and the only conclusion seems to be that Kaspersky Lab is caught in the middle of a geopolitical fight".

The statement also hints at what some independent security researchers had speculated that its software detected the programmes brought home by the individual and classified them as threats, uploading their signatures and other information to its database of threats.

The Washington Post claims the incident, which resulted in the person being removed from their post in November 2015, is still under investigation.

This is the latest in a series of embarrassing breaches for the NSA. While the leaks from Edward Snowden in May 2013 may be the most famous, another contractor Harold Martin was arrested last year in relation to a separate 2013 breach. Then, in 2016, hacking group Shadow Brokers stole a vast cache of hacking tools, once again linked to TAO, from the NSA and leaked them to the public.

These latest reports haven't been confirmed by the NSA, however, with the agency telling Reuters: "[We] never to comment on our affiliates or personnel issues."

Featured Resources

Navigating the new normal: A fast guide to remote working

A smooth transition will support operations for years to come

Download now

Leading the data race

The trends driving the future of data science

Download now

How to create 1:1 customer experiences at scale

Meet the technology capable of delivering the personalisation your customers crave

Download now

How to achieve daily SAP releases

Accelerate the pace of SAP change to support your digital strategy

Download now

Recommended

How to protect against a DDoS attack
Security

How to protect against a DDoS attack

17 Sep 2020
NSA warns smartphone users of ‘large scale data tracking’
privacy

NSA warns smartphone users of ‘large scale data tracking’

5 Aug 2020
Fitness Depot notifies customers of data breach
data breaches

Fitness Depot notifies customers of data breach

8 Jun 2020
Printing company exposes 343GB of sensitive military data
data breaches

Printing company exposes 343GB of sensitive military data

20 Mar 2020

Most Popular

16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

16 Sep 2020
Windows XP source code allegedly leaked online
Microsoft Windows

Windows XP source code allegedly leaked online

25 Sep 2020
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

16 Sep 2020