Pakistanis angry over detentions in Times Sq. case Monday, May 24, 2010
ISLAMABAD – Relatives of three men detained by Pakistan for alleged links to the suspect in the attempted Times Square bombing say the men are innocent.
They
AFP - Thursday, August 6TAIPEI (AFP) - - Taiwan's Beijing-friendly government on Wednesday denied boycotting an Australian film festival amid a row over the e
BERLIN (Reuters) - Chancellor Angela Merkel suffered a double blow on Thursday as a senior party ally in east German
Minister seeks closure of anti-Berlusconi websites Wednesday, December 16, 2009
ROME (AFP) - – The Italian government moved Tuesday to close down Internet sites encouraging further violence against Prime Minister Silvio Berlusconi, who
By ELAINE KURTENBACH,AP Business Writer AP - Wednesday, March 18SHANGHAI - Asia's stock market rally seemed to be running out of steam Wednesday, despite an
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Home
Business
Business Home
Economy
Technology
Media
Small Business
Legal
Deals
Earnings
Social Pulse
Business Video
The Freeland File
Aerospace & Defense
Markets
Markets Home
U.S. Markets
European Markets
Asian Markets
Global Market Data
Indices
M&A
Stocks
Bonds
Currencies
Commodities
Futures
Funds
peHUB
World
World Home
U.S.
Brazil
China
Euro Zone
Japan
Mexico
Russia
India Insight
World Video
Reuters Investigates
Decoder
Politics
Politics Home
Election 2012
Campaign Polling
Political Punchlines
Supreme Court
Politics Video
Tech
Technology Home
MediaFile
Science
Tech Video
Tech Tonic
Social Pulse
Opinion
Opinion Home
Chrystia Freeland
John Lloyd
Felix Salmon
Jack Shafer
David Rohde
Bernd Debusmann
Nader Mousavizadeh
Lucy P. Marcus
David Cay Johnston
Bethany McLean
Anatole Kaletsky
Edward Hadas
Hugo Dixon
Ian Bremmer
Lawrence Summers
Susan Glasser
The Great Debate
Steven Brill
Jack & Suzy Welch
Frederick Kempe
Christopher Papagianis
Mark Leonard
Breakingviews
Equities
Credit
Private Equity
M&A
Macro & Markets
Politics
Breakingviews Video
Money
Money Home
Tax Break
Lipper Awards 2012
Global Investing
MuniLand
Unstructured Finance
Linda Stern
Mark Miller
John Wasik
James Saft
Analyst Research
Alerts
Watchlist
Portfolio
Stock Screener
Fund Screener
Personal Finance Video
Money Clip
Investing 201
Life
Health
Sports
Arts
Faithworld
Business Traveler
Entertainment
Oddly Enough
Lifestyle Video
Pictures
Pictures Home
Reuters Photographers
Full Focus
Video
Reuters TV
Reuters News
Article
Comments (0)
Follow Reuters
Facebook
Twitter
RSS
YouTube
Read
Grim jobs market confronts Obama, Fed
12:11pm EDT
Family feud in focus as French seek clues to Alps slaying
11:41am EDT
Simon Cowell lashes out over "Voice," "X Factor" showdown
06 Sep 2012
Obama convention glow dimmed by grim jobs data
|
12:11pm EDT
U.S. congressman confirms high-level U.S.-Israel spat over Iran
3:33am EDT
Discussed
82
Democrats attack Romney, defend Obama at convention
81
Obama, Democrats to make their case as convention opens
78
At Jackson Hole, a growing fear for Fed’s independence
Sponsored Links
Exclusive: Insiders suspected in Saudi cyber attack
Tweet
Share this
Email
Print
Related News
Qatar's Al Jazeera website hacked by Syria's Assad loyalists
Tue, Sep 4 2012
Exclusive: White House studying potential oil reserve release
Fri, Aug 17 2012
WRAPUP 5-Assad's brother may have lost leg in bombing -sources
Thu, Aug 16 2012
Lebanon kidnap fans fear of Syria spillover
Wed, Aug 15 2012
WRAPUP 9-Syria air raid kills 30; Lebanon kidnap worries region
Wed, Aug 15 2012
Analysis & Opinion
Saudi Arabia approves $16.5 bln Mecca transport revamp
The coming glut in oil – and its impact
Related Topics
Tech »
Cyber Crime »
By Jim Finkle
Fri Sep 7, 2012 4:52am EDT
(Reuters) - One or more insiders with high-level access are suspected of assisting the hackers who damaged some 30,000 computers at Saudi Arabia's national oil company last month, sources familiar with the company's investigation say.
The attack using a computer virus known as Shamoon against Saudi Aramco - the world's biggest oil company - is one of the most destructive cyber strikes conducted against a single business.
Shamoon spread through the company's network and wiped computers' hard drives clean. Saudi Aramco says damage was limited to office computers and did not affect systems software that might hurt technical operations.
The hackers' apparent access to a mole, willing to take personal risk to help, is an extraordinary development in a country where open dissent is banned.
"It was someone who had inside knowledge and inside privileges within the company," said a source familiar with the ongoing forensic examination.
Hackers from a group called "The Cutting Sword of Justice" claimed responsibility for the attack. They say the computer virus gave them access to documents from Aramco's computers, and have threatened to release secrets. No documents have so far been published.
Reports of similar attacks on other oil and gas firms in the Middle East, including in neighboring Qatar, suggest there may be similar activity elsewhere in the region, although the attacks have not been linked.
Saudi Aramco declined to comment. "Saudi Aramco doesn't comment on rumors and conjectures amidst an ongoing probe," it said.
The hacking group that claimed responsibility for the attack described its motives as political.
In a posting on an online bulletin board the day the files were wiped, the group said Saudi Aramco was the main source of income for the Saudi government, which it blamed for "crimes and atrocities" in several countries, including Syria and Bahrain.
The Saudi interior ministry did not respond to requests for comment. The foreign ministry was not available for comment.
Saudi Arabia sent troops into Bahrain last year to back the Gulf state's rulers, fellow Sunni Muslims, against Shi'ite-led protesters. Riyadh is also sympathetic to mainly Sunni rebels in Syria.
Saudi Arabia's economy is heavily dependent on oil. Oil export revenues have accounted for 80-90 percent of total Saudi revenues and above 40 percent of the country's gross domestic product, according to U.S. data.
DESTRUCTIVE
Saudi Aramco, which supplies about a tenth of the world's oil, has hired at least six firms with expertise in hacking attacks, bringing in dozens of outside experts to investigate the attack and repair computers, the sources say.
According to analysis of Shamoon by computer security firm Symantec, the way the virus gets into networks may vary, but once inside it tries to infect every computer in the local area network before erasing files to render PCs useless.
"We don't normally see threats that are so destructive," Liam O Murchu, who helped lead Symantec's research into the virus, said. "It's probably been 10 years since we saw something so destructive."
The state-run oil company - whose 260 billion barrels of crude oil alone would value it at over 8 trillion dollars, or 14 times the market value of Apple Inc. - was well protected against break-in attempts over the Internet, according to people familiar with its network operations.
Yet those sources say such protections could not prevent an attack by an insider with high-level access.
It is unusual for insiders to be fingered in cyber attacks. Verizon Business, which publishes the most comprehensive annual survey of data breaches, said that insiders were implicated in just 4 percent of cases last year.
The hackers behind the Shamoon attack siphoned off data from a relatively small number of computers, delivering it to a remote server, the sources said. They later threatened to release that information.
Because the virus wiped the hard drives, it is difficult for Saudi Aramco to determine exactly what information the hackers obtained.
An email address and password, which the poster claimed belonged to Aramco CEO Khalid Al-Falih, was posted on a website often used by hackers to show off their achievements, this time signed by the "Angry Internet Lovers". No sensitive Aramco files have been uploaded on that site.
Sources who spoke to Reuters said they were not aware whether the hackers had made specific demands, what they might have been or whether they were met.
The sources would not say whether the suspected mole or moles are Saudi Aramco employees or outside contractors, or whether they accessed a workstation inside Saudi Aramco's offices or accessed the network remotely.
The Saudi interior ministry was unavailable to comment on whether anyone has been arrested as part of the investigation.
VIRUS TARGETS PCS
The Shamoon virus is designed to attack ordinary business computers. It does not belong to the category of sophisticated cyber warfare tools - like the Stuxnet virus that attacked Iran's nuclear program in 2010 - which target industrial control systems and can paralyze critical infrastructure.
"Based on initial reporting and analysis of the malware, no evidence exists that Shamoon specifically targets industrial control systems components or U.S. government agencies," the Department of Homeland Security's United States Computer Emergency Readiness Team said in an August 29 advisory.
Saudi Aramco has said that only office PCs running Microsoft Windows were damaged. Its oil exploration, production, export, sales and database systems all remained intact as they ran on isolated and heavily protected systems.
"All our core operations continued smoothly," CEO Khalid Al-Falih told Saudi government and business officials at a security workshop on Wednesday.
"Not a single drop of oil was lost. No critical service or business transaction was directly impacted by the virus."
It is standard industry practice to shield plant operating networks from hackers by running them on separate operating systems that are protected from the Internet.
Qatar's natural gas firm Rasgas was also hit by a cyber attack last week, although it has not said how much damage was caused or whether Shamoon was the virus involved. Qatar, also a Sunni Gulf kingdom, has similar foes to Saudi Arabia.
Its parent firm Qatar Petroleum, which also owns Qatar's other main natural gas firm Qatargas, said it was unaffected but implied that other companies had been hit.
"Qatar Petroleum has not been affected by the computer virus that hit several oil and gas firms. All QP operations are continuing as normal," it said in an official tweet on Monday.
(Additional reporting by Daniel Fineren and Humeyra Pamuk in Dubai; Editing by Peter Graff and Janet McBride)
Tech
Cyber Crime
Tweet this
Link this
Share this
Digg this
Email
Reprints
We welcome comments that advance the story through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can flag it to our editors by using the report abuse links. Views expressed in the comments do not represent those of Reuters. For more information on our comment policy, see http://blogs.reuters.com/fulldisclosure/2010/09/27/toward-a-more-thoughtful-conversation-on-stories/
Comments (0)
Be the first to comment on reuters.com.
Add yours using the box above.
Edition:
U.S.
Africa
Arabic
Argentina
Brazil
Canada
China
France
Germany
India
Italy
Japan
Latin America
Mexico
Russia
Spain
United Kingdom
Back to top
Reuters.com
Business
Markets
World
Politics
Technology
Opinion
Money
Pictures
Videos
Site Index
Legal
Bankruptcy Law
California Legal
New York Legal
Securities Law
Support & Contact
Support
Corrections
Connect with Reuters
Twitter
Facebook
LinkedIn
RSS
Podcast
Newsletters
Mobile
About
Privacy Policy
Terms of Use
AdChoices
Copyright
Our Flagship financial information platform incorporating Reuters Insider
An ultra-low latency infrastructure for electronic trading and data distribution
A connected approach to governance, risk and compliance
Our next generation legal research platform
Our global tax workstation
Thomsonreuters.com
About Thomson Reuters
Investor Relations
Careers
Contact Us
Thomson Reuters is the world's largest international multimedia news agency, providing investing news, world news, business news, technology news, headline news, small business news, news alerts, personal finance, stock market, and mutual funds information available on Reuters.com, video, mobile, and interactive television platforms. Thomson Reuters journalists are subject to an Editorial Handbook which requires fair presentation and disclosure of relevant interests.
NYSE and AMEX quotes delayed by at least 20 minutes. Nasdaq delayed by at least 15 minutes. For a complete list of exchanges and delays, please click here.