Showing posts with label national security. Show all posts
Showing posts with label national security. Show all posts

Thursday, July 23, 2026

The Department of War today announced the publication of the Fiscal Year (FY) 2025 update to the list of foreign institutions engaging in problematic activities, as required by Section 1286 of the FY19 National Defense Authorization Act (NDAA).

This update is a vital component of the Department's ongoing mission to highlight and counter unauthorized technology transfer to foreign countries of concern. The FY25 list formally identifies 130 academic and research institutions located in China, Russia and Iran. These institutions have been confirmed to engage in activities that increase the likelihood of U.S. government-funded research and development efforts being misappropriated. Such misappropriation enables adversarial government interference that directly threatens America's national security and scientific integrity.

"The Department of War is strengthening its commitment to protect taxpayer-funded research and preserving the integrity of the American scientific enterprise," said Emil Michael, Under Secretary of War for Research and Engineering.

The Department advises strict caution for domestic researchers, academic institutions and industry partners when considering collaboration, funding or data-sharing engagements with any institution named on this list. This aligns with recent directives from Under Secretary Michael establishing stricter requirements to protect fundamental research from malign foreign influence and intellectual property theft.

The Department will continue to update the list at least once a year or as appropriate based on emerging intelligence and threat assessments. The FY25 Section 1286 list is available here.

Thursday, July 16, 2026

The Department of War's Office of Strategic Capital Introduces National Security Fund Finance Program

The Department of War's Office of Strategic Capital (OSC) is pleased to announce the introduction of the National Security Fund Finance (NSFF) program, which aims to provide capital support to credit funds addressing shortages, gaps, and vulnerabilities in critical minerals vital to United States national security.  OSC's mission is to advance these strategic interests by providing direct loans and deploying other financial tools, with the NSFF program acting as the fund-level financing solution to accomplish that goal.

The One Big Beautiful Bill Act, signed into law by President Donald J. Trump, provided funding for OSC to support critical minerals and materials. The NSFF program will provide loans to qualified investment fund managers, who will combine OSC loans with private capital to invest in portfolio companies focused on addressing U.S. national security shortages related to critical minerals and materials.

"The NSFF program clearly advances OSC's goal of crowding-in private capital to address shortages that are vital to U.S. national security. Paired with private capital, NSFF will drive significant investment to address gaps and vulnerabilities in our U.S. critical minerals industry. OSC is taking decisive action to restore our domestic critical minerals supply chain, revive our industrial base, and rebuild our military to achieve President Trump's goal of peace through strength," said David A. Lorch, Director of the Office of Strategic Capital and Senior Advisor to Deputy Secretary of War Steve Feinberg.

OSC is scheduled to issue a formal Notice of Funding Opportunity (NOFO) imminently. The application link will be posted on OSC's website, accompanied by an official press release on the Department's website. The NOFO application period will open upon its official publication.

"President Trump has led the way in leveraging the strength of the United States' world-leading capital markets," said Emil Michael, Under Secretary of War for Research and Engineering. "The Office of Strategic Capital's NSFF program represents another tool that will establish true U.S. independence in the critical minerals supply chain."

Monday, July 13, 2026

Department of War Announces $25 Million Investment With ReElement Technologies to Expand U.S. Critical Minerals Refining Capacity

The Department of War's Economic Defense Unit (EDU) in partnership with the Office of the Under Secretary of War for Acquisition and Sustainment (OUSW(A&S)) today announced a $25 million investment with ReElement Technologies Corp. to expand domestic refining capacity for rare earth elements and other defense-critical minerals at the company's Marion, Indiana facility. This investment will strengthen the U.S. industrial base by securing domestic access to materials essential for advanced defense systems, aerospace components, and secure communications.

"Strengthening our domestic refining capacity for rare earth elements and other critical minerals is a national security imperative," said HON Michael Cadenazzi, Assistant Secretary of War for Industrial Base Policy. "Executed by the Economic Defense Unit (EDU) and financed by the OASW(IBP) Industrial Base Fund, this investment actively rebuilds a domestic, mine-to-magnet supply chain. This effort guarantees the joint force has reliable access to the critical materials required for advanced defense systems."

The Department of War is funding equipment, installation, and working capital to help ReElement expand its production lines. The effort will focus on processing end-of-life magnets and other recycled materials to produce high-purity rare earth oxides, yttrium, gadolinium, germanium, and gallium.

The effort reflects the successful partnership between OUSW(A&S) and EDU. The ability to identify industrial bottlenecks, combined with commercial-sector best practices, enables the rapid execution of agreements that continue to enhance national security and military might.

"Critical minerals are fundamental to sustaining our warfighting capacity," said George K. Kollitides II, Director of the Economic Defense Unit. "The Economic Defense Unit was created to act quickly and decisively to address economic vulnerabilities and strengthen our military advantage. This agreement helps secure domestic capacity, protect the industrial base behind the warfighter, and ensure the United States has reliable access to the materials that make deterrence credible and military advantage possible."

The agreement includes robust safeguards to protect U.S. interests, including restrictions on transactions with foreign entities of concern. This $25 million investment reflects the Department's performance-driven approach: pairing targeted government support with private-sector execution to move critical industrial capabilities from concept to production at the speed of relevance.

Tuesday, December 9, 2025

The War Department Unleashes AI on New GenAI.mil Platform

The War Department today announced the launch of Google Cloud's Gemini for Government as the first of several frontier AI capabilities to be housed on GenAI.mil, the Department's new bespoke AI platform. This initiative cultivates an "AI-first" workforce, leveraging generative AI capabilities to create a more efficient and battle-ready enterprise. Additional world-class AI models will be available to all civilians, contractors, and military personnel, delivering on the White House's AI Action Plan announced earlier this year.

This past July, President Donald Trump instituted a mandate to achieve an unprecedented level of AI technological superiority. The War Department is delivering on this mandate, ensuring it is not just ink on paper. In response to this directive, AI capabilities have now reached all desktops in the Pentagon and in American military installations around the world.

The first instance on GenAI.mil, Gemini for Government, empowers intelligent agentic workflows, unleashes experimentation, and ushers in an AI-driven culture change that will dominate the digital battlefield for years to come. Gemini for Government is the embodiment of American AI excellence, placing unmatched analytical and creative power directly into the hands of the world's most dominant fighting force.

"There is no prize for second place in the global race for AI dominance," said Emil Michael, Under Secretary of War for Research and Engineering. "We are moving rapidly to deploy powerful AI capabilities like Gemini for Government directly to our workforce. AI is America's next Manifest Destiny, and we're ensuring that we dominate this new frontier."

The launch of GenAI.mil stands as a testament to American ingenuity, driven by the AI Rapid Capabilities Cell within the War Department's Office of Research & Engineering. Their achievement directly embodies the Department's core tenets of reviving the warrior ethos, rebuilding American military capabilities, and re-establishing deterrence through technological dominance and uncompromising grit.

"We are pushing all of our chips in on artificial intelligence as a fighting force. The Department is tapping into America's commercial genius, and we're embedding generative AI into our daily battle rhythm." Secretary of War Pete Hegseth remarked, "AI tools present boundless opportunities to increase efficiency, and we are thrilled to witness AI's future positive impact across the War Department."

The Department is providing no-cost training for GenAI.mil to all DoW employees. Training sessions are designed to build confidence in using AI and give personnel the education needed to realize its full potential. Security is paramount, and all tools on GenAI.mil are certified for Controlled Unclassified Information (CUI) and Impact Level 5 (IL5), making them secure for operational use. Gemini for Government provides an edge through natural language conversation, retrieval-augmented generation (RAG), and is web-grounded against Google Search to ensure outputs are reliable and dramatically reduces the risk of AI hallucinations.

GenAI.mil is another building block in America's AI revolution. The War Department is unleashing a new era of operational dominance, where every warfighter wields frontier AI as a force multiplier. The release of GenAI.mil is an indispensable strategic imperative for our fighting force, further establishing the United States as the global leader in AI.

Thursday, November 20, 2025

Department of War Awards $29.9 Million to Create a U.S. Domestic Supply of Gallium and Scandium

The Department of War announced today a $29.9 million a Defense Production Act (DPA) Title III award to ElementUS Minerals, LLC (ElementUSA). ElementUSA will use this award to enable the development of a demonstration facility in Gramercy, Louisiana to separate and purify gallium and scandium from existing industrial waste.  The company will also conduct initial development work at their Critical Resource Accelerator in Cedar Park, Texas.

This investment uses funds from the Additional Ukraine Supplemental Appropriations Act of 2022. It also supports the Administration's goal to increase the production of processed critical minerals and other derivative products as articulated in the March 20, 2025, Executive Order 14241 - Immediate Measures to Increase American Mineral Production.

"Gallium and scandium are critical minerals essential to a wide range of defense manufacturing industries and equipment," said Assistant Secretary of War for Industrial Base Policy Mike Cadenazzi. "Developing domestic production of both is a DOW priority."

ElementUSA is a leading expert in recovering minerals and metals from industrial waste streams to create domestic supply chains of critical minerals necessary for national defense.  Using DPA Title III funds to construct the demonstration facility, the company will become one of the first U.S. producers of both gallium and scandium. Systems such as missile defense platforms, sensors, fighter aircraft, and hypersonic weapons all require these elements in their manufacture.  The company will use a proprietary process to separate and extract these critical minerals from over 30 million tons of mineral-rich bauxite residue, a byproduct of the alumina refining process.  As such, not only will ElementUSA create a domestic supply chain of critical minerals, but it will do so while cleaning up a waste product with no additional mining required.

"By enabling ElementUSA to recover gallium and scandium from processing waste, this award will support the DOW's work to expand the supply of critical minerals needed for numerous defense components and platforms," added Mr. Jeffrey Frankston, Acting Deputy Assistant Secretary of War for Industrial Base Resilience, which oversees the Manufacturing Capability Expansion and Investment Prioritization (MCEIP) directorate.  "Such awards are essential for reconstituting domestic capabilities, diversifying supply chains, reducing dependence on foreign sources, and enhancing national security."

This is one of 18 awards made by the DPA Purchases Office totaling $887.0 million in fiscal year 2025. Recipient cost shares total $88.0 million in FY 2025.  The MCEIP directorate oversees the DPA Purchases Office.


 

Sunday, August 31, 2025

Silent Sabotage: The Rising Threat of Cyberattacks on Critical Infrastructure

In modern warfare and terrorism, silence can be more lethal than the roar of an explosion. Cyberattacks on critical infrastructure—those systems underpinning energy, healthcare, transportation, finance, and communication—have emerged as one of the most pressing threats of the 21st century. Unlike traditional assaults, cyber operations leave no craters or smoke plumes. Instead, they quietly paralyze hospitals, darken cities, disrupt fuel pipelines, and sow chaos. The vulnerability of societies that rely on complex digital networks makes cyber sabotage both an attractive and underestimated weapon.


Historical Precedents and Case Studies

Cyber warfare and infrastructure sabotage have moved from theoretical to demonstrable reality. Several high-profile incidents underscore how adversaries can reach into the vital organs of modern society:

  • Stuxnet (2010): Widely believed to have been developed jointly by the United States and Israel, the Stuxnet worm targeted Iranian nuclear centrifuges at Natanz. It represented the first known digital weapon to cause real-world physical destruction, proving that code could achieve what bombs once did (Zetter, 2014).

  • Ukraine Power Grid Attacks (2015, 2016): Hackers attributed to Russian groups infiltrated Ukraine’s electrical grid, causing widespread blackouts affecting hundreds of thousands of citizens (Assante & Lee, 2015). These incidents marked the first confirmed cyberattacks to disable a national power system.

  • WannaCry and NotPetya (2017): While not targeted exclusively at critical infrastructure, these ransomware campaigns spread globally, paralyzing hospitals in the United Kingdom and disrupting logistics companies and shipping giants, leading to billions in damages (Greenberg, 2018).

  • Colonial Pipeline Ransomware (2021): In the United States, a ransomware attack forced the shutdown of a major fuel pipeline, creating panic buying, shortages, and significant economic loss along the East Coast (CISA, 2021).

These cases reveal a trajectory: cyberattacks are growing in frequency, sophistication, and direct impact on civilian life.


Why Infrastructure Is an Attractive Target

Critical infrastructure provides a uniquely vulnerable and symbolically powerful target for adversaries. Unlike military facilities, which are hardened against attack, infrastructure is largely operated by private companies or local governments with limited resources for cybersecurity.

  • High Impact: Interrupting electricity, fuel, or water causes immediate disruptions to millions of people.

  • Psychological Effect: Infrastructure failures undermine public confidence in government and industry, creating fear disproportionate to the actual damage.

  • Geopolitical Leverage: Cyberattacks can serve as coercive tools, allowing hostile states to exert pressure without firing a shot.

  • Low Visibility: Unlike kinetic warfare, cyber sabotage can be cloaked in plausible deniability, complicating retaliation.

In short, infrastructure represents both the lifeblood of modern society and a soft underbelly ripe for exploitation.


Methods of Attack

Cyber operations against infrastructure exploit both technical vulnerabilities and human weakness:

  • Ransomware and Malware: Malicious code encrypts or disrupts systems until ransom is paid, as seen in Colonial Pipeline.

  • Phishing and Social Engineering: Attackers exploit human error to gain access credentials, often the weakest link in the chain.

  • Supply Chain Compromise: Adversaries infiltrate third-party vendors to insert vulnerabilities, as in the SolarWinds breach.

  • Insider Threats: Disgruntled or coerced employees with system access can inflict catastrophic damage.

  • Zero-Day Exploits: Attackers exploit previously unknown software flaws, striking before patches exist.

The methods may differ, but the commonality is disruption through invisibility and stealth.


Potential Consequences of a Major Cyberattack

The cascading consequences of cyberattacks on infrastructure can equal or exceed those of traditional attacks:

  • Energy Grid Failures: Prolonged blackouts could paralyze communication, healthcare, and commerce. A widespread outage during winter could prove deadly.

  • Water Systems: Hackers could manipulate treatment processes, either shutting down supply or contaminating it, creating a public health crisis.

  • Healthcare Systems: Hospitals rely on digital infrastructure for patient care, medical records, and devices. An attack could delay surgeries, disable emergency services, and cost lives.

  • Transportation: Airports, rail systems, and shipping routes all depend on digital coordination. Sabotage could halt supply chains or cause accidents.

  • Financial Systems: Attacks on banks or markets could trigger mass economic panic, collapsing trust in currency and trade.

Thus, cyber sabotage offers adversaries the ability to achieve widespread paralysis without conventional weapons.


Obstacles in Defense and Mitigation

Defending against cyberattacks on infrastructure presents unique challenges:

  • Attribution Difficulties: Determining who launched an attack is often difficult, allowing adversaries to deny involvement.

  • Aging Infrastructure: Much of the world’s grid, water, and transport systems run on outdated technology never designed for cybersecurity.

  • Public-Private Divide: Most infrastructure is privately owned, creating uncertainty about which entities are responsible for defending it.

  • Talent Shortage: There are not enough trained cybersecurity professionals to meet the growing demand.

  • Regulatory Gaps: Standards are inconsistent across industries and nations, leaving critical vulnerabilities unaddressed.

These weaknesses leave societies in a precarious position: highly dependent on technology yet insufficiently protected against those who would weaponize it.


Strategies for Protection

Despite the challenges, meaningful steps can be taken to reduce the risk:

  • Strengthening Public-Private Partnerships: Governments and private companies must share intelligence, resources, and training.

  • Investment in Cyber Hygiene: Regular updates, patches, and system hardening are low-cost but critical measures.

  • Artificial Intelligence and Analytics: AI-driven monitoring systems can detect anomalies and intrusions faster than human analysts.

  • Red Team/Blue Team Exercises: Simulated attacks help organizations stress-test their defenses and identify weaknesses.

  • Legislation and Standards: National governments must enforce minimum cybersecurity standards for industries managing critical systems.

  • International Cooperation: Norms, treaties, and cooperative defense mechanisms must evolve to address globalized cyber threats.

Without such measures, societies risk continuing to lag behind adversaries who innovate faster than defenders can respond.


The Future of Cyber Threats

Looking forward, cyberattacks against infrastructure will likely evolve alongside technological innovation:

  • Hybrid Warfare Integration: Cyber operations will increasingly complement kinetic warfare, creating multi-domain battlefields.

  • AI-Powered Attacks: Just as AI aids defenders, it will empower attackers with self-adaptive malware.

  • Deepfake and Social Engineering: Advanced digital manipulation will compromise decision-makers and disrupt response coordination.

  • Quantum Computing Risks: Once operational, quantum systems could break today’s encryption standards, rendering existing defenses obsolete.

  • Expanding Target List: The rise of smart cities, Internet of Things (IoT) devices, and autonomous systems offers new vulnerabilities to exploit.

The battlefield of the future may be silent, digital, and ubiquitous.


Conclusion

Cyberattacks on critical infrastructure represent one of the most insidious threats of our time. They are silent, deniable, and potentially catastrophic, capable of crippling entire societies without a single bullet fired. The threat is not hypothetical—incidents like Stuxnet, Ukraine’s power grid attacks, and the Colonial Pipeline hack prove that silent sabotage is already here.

To counter this threat, governments, industries, and citizens must acknowledge cyberattacks as a matter of national survival. Investment, vigilance, and international cooperation are paramount. In an age when society’s heartbeat is digital, silence may be the deadliest sound of all.


References

Assante, M. J., & Lee, R. M. (2015). The industrial control system cyber kill chain. SANS Institute.

CISA. (2021). DarkSide ransomware: Best practices for preventing business disruption from ransomware attacks. Cybersecurity and Infrastructure Security Agency.

Greenberg, A. (2018). Sandworm: A new era of cyberwar and the hunt for the Kremlin’s most dangerous hackers. Doubleday.

Zetter, K. (2014). Countdown to Zero Day: Stuxnet and the launch of the world’s first digital weapon. Crown.


Do you want me to also prepare a companion infographic (like the pathogen profiles chart you liked) that maps infrastructure sectors vs. attack types for quick visual impact?

Monday, March 25, 2024

Seven Hackers Associated with Chinese Government Charged with Computer Intrusions Targeting Perceived Critics of China and U.S. Businesses and Politicians

An indictment was unsealed today charging seven nationals of the People’s Republic of China (PRC) with conspiracy to commit computer intrusions and conspiracy to commit wire fraud for their involvement in a PRC-based hacking group that spent approximately 14 years targeting U.S. and foreign critics, businesses, and political officials in furtherance of the PRC’s economic espionage and foreign intelligence objectives.

The defendants are Ni Gaobin (倪高彬), 38; Weng Ming (翁明), 37; Cheng Feng (程锋), 34; Peng Yaowen (彭耀文), 38; Sun Xiaohui (孙小辉), 38; Xiong Wang (熊旺), 35; and Zhao Guangzong (赵光宗), 38. All are believed to reside in the PRC.

“The Justice Department will not tolerate efforts by the Chinese government to intimidate Americans who serve the public, silence the dissidents who are protected by American laws, or steal from American businesses,” said Attorney General Merrick B. Garland. “This case serves as a reminder of the ends to which the Chinese government is willing to go to target and intimidate its critics, including launching malicious cyber operations aimed at threatening the national security of the United States and our allies.”

“Over 10,000 malicious emails, impacting thousands of victims, across multiple continents. As alleged in today’s indictment, this prolific global hacking operation – backed by the PRC government – targeted journalists, political officials, and companies to repress critics of the Chinese regime, compromise government institutions, and steal trade secrets,” said Deputy Attorney General Lisa Monaco. “The Department of Justice will relentlessly pursue, expose, and hold accountable cyber criminals who would undermine democracies and threaten our national security.” 

"Today's announcement exposes China's continuous and brash efforts to undermine our nation's cybersecurity and target Americans and our innovation,” said FBI Director Christopher Wray. "As long as China continues to target the US and our partners, the FBI will continue to send a clear message that cyber espionage will not be tolerated, and we will tirelessly pursue those who threaten our nation’s security and prosperity. This indictment underscores our unwavering commitment to disrupt and deter malicious cyber activity, and safeguard our citizens, businesses, and critical infrastructure from threats in cyberspace."

“The indictment unsealed today, together with statements from our foreign partners regarding related activity, shed further light on the PRC Ministry of State Security’s aggressive cyber espionage and transnational repression activities worldwide,” said Assistant Attorney General Matthew G. Olsen of the Justice Department’s National Security Division. “Today’s announcements underscore the need to remain vigilant to cybersecurity threats and the potential for cyber-enabled foreign malign influence efforts, especially as we approach the 2024 election cycle. The Department of Justice will continue to leverage all tools to disrupt malicious cyber actors who threaten our national security and aim to repress fundamental freedoms worldwide.”

“These allegations pull back the curtain on China’s vast illegal hacking operation that targeted sensitive data from U.S. elected and government officials, journalists, and academics; valuable information from American companies; and political dissidents in America and abroad. Their sinister scheme victimized thousands of people and entities across the world, and lasted for well over a decade,” said U.S. Attorney Breon Peace for the Eastern District of New York. “America’s sovereignty extends to its cyberspace. Today’s charges demonstrate my office’s commitment to upholding and protecting that jurisdiction, and to putting an end to malicious nation state cyber activity.”

“The recent indictments against the Chinese actors reaffirm the FBI’s relentless dedication to combating cyber threats,” said Assistant Director Bryan Vorndran of the FBI Cyber Division. “They serve as a reminder that cyber adversaries who seek to compromise our nation’s systems and target US officials cannot rely on the cloak of anonymity and will face consequences for their actions.”

“APT31 Group’s practices further demonstrate the size and scope of the PRC’s state-sponsored hacking apparatus,” said Special Agent in Charge Robert W. “Wes” Wheeler Jr. of the FBI Chicago Field Office. “FBI Chicago worked tirelessly to uncover this complex web of alleged foreign intelligence and economic espionage crimes. Thanks to these efforts, as well as our partnerships with the U.S. Attorneys’ Offices and fellow Field Offices, the FBI continues to be successful in holding groups accountable and protecting national security.”

Overview

As alleged in the indictment and court filings, the defendants, along with dozens of identified PRC Ministry of State Security (MSS) intelligence officers, contractor hackers, and support personnel, were members of a hacking group operating in the PRC and known within the cybersecurity community as Advanced Persistent Threat 31 (the APT31 Group). The APT31 Group was part of a cyberespionage program run by the MSS’s Hubei State Security Department, located in the city of Wuhan. Through their involvement with the APT31 Group, since at least 2010, the defendants conducted global campaigns of computer hacking targeting political dissidents and perceived supporters located inside and outside of China, government and political officials, candidates, and campaign personnel in the United States and elsewhere and American companies.

The defendants and others in the APT31 Group targeted thousands of U.S. and foreign individuals and companies. Some of this activity resulted in successful compromises of the targets’ networks, email accounts, cloud storage accounts, and telephone call records, with some surveillance of compromised email accounts lasting many years.

Hacking Scheme

The more than 10,000 malicious emails that the defendants and others in the APT31 Group sent to these targets often appeared to be from prominent news outlets or journalists and appeared to contain legitimate news articles. The malicious emails contained hidden tracking links, such that if the recipient simply opened the email, information about the recipient, including the recipient’s location, internet protocol (IP) addresses, network schematics, and specific devices used to access the pertinent email accounts, was transmitted to a server controlled by the defendants and those working with them. The defendants and others in the APT31 Group then used this information to enable more direct and sophisticated targeted hacking, such as compromising the recipients’ home routers and other electronic devices.

The defendants and others in the APT31 Group also sent malicious tracking-link emails to government officials across the world who expressed criticism of the PRC government. For example, in or about 2021, the conspirators targeted the email accounts of various foreign government individuals who were part of the Inter-Parliamentary Alliance on China (IPAC), a group founded in 2020 on the anniversary of the 1989 Tiananmen Square protests whose stated purpose was to counter the threats posed by the Chinese Communist Party to the international order and democratic principles. The targets included every European Union member of IPAC, and 43 United Kingdom parliamentary accounts, most of whom were members of IPAC or had been outspoken on topics relating to the PRC government.

To gain and maintain access to the victim computer networks, the defendants and others in the APT31 Group employed sophisticated hacking techniques including zero-day exploits, which are exploits that the hackers became aware of before the manufacturer, or the victim were able to patch or fix the vulnerability. These activities resulted in the confirmed and potential compromise of economic plans, intellectual property, and trade secrets belonging to American businesses, and contributed to the estimated billions of dollars lost every year as a result of the PRC’s state-sponsored apparatus to transfer U.S. technology to the PRC.

Targeting of U.S. Government Officials and U.S. and Foreign Politicians and Campaigns

The targeted U.S. government officials included individuals working in the White House, at the Departments of Justice, Commerce, Treasury, and State, and U.S. Senators and Representatives of both political parties. The defendants and others in the APT31 Group targeted these individuals at both professional and personal email addresses. Additionally in some cases, the defendants also targeted victims’ spouses, including the spouses of a high-ranking Department of Justice official, high-ranking White House officials, and multiple U.S. Senators. Targets also included election campaign staff from both major U.S. political parties in advance of the 2020 election.

The allegations in the indictment regarding the malicious cyber activity targeting political officials, candidates, and campaign personnel are consistent with the March 2021 Joint Report of the Department of Justice and the Department of Homeland Security on Foreign Interference Targeting Election Infrastructure or Political Organization, Campaign, or Candidate Infrastructure Related to the 2020 US Federal Elections. That report cited incidents when Chinese government-affiliated actors “materially impacted the security of networks associated with or pertaining to U.S. political organizations, candidates, and campaigns during the 2020 federal elections.” That report also concluded that “such actors gathered at least some information they could have released in influence operations,” but which the Chinese actors did not ultimately deploy in such a manner. Consistent with that conclusion, the indictment does not allege that the hacking furthered any Chinese government influence operations against the United States. The indictment’s allegations nonetheless serve to underscore the need for U.S. (and allied)

 olitical organizations, candidates, and campaigns to remain vigilant in their cybersecurity posture and in otherwise protecting their sensitive information from foreign intelligence services, particularly in light of the U.S. Intelligence Community’s recent “[t]he PRC may attempt to influence the U.S. elections in 2024 at some level because of its desire to sideline critics of China and magnify U.S. societal divisions.”

Targeting of U.S. Companies

The defendants and others in the APT31 Group also targeted individuals and dozens of companies operating in areas of national economic importance, including the defense, information technology, telecommunications, manufacturing and trade, finance, consulting, legal, and research industries. The defendants and others in the APT31 Group hacked and attempted to hack dozens of companies or entities operating in these industries, including multiple cleared defense contractors who provide products and services to the U.S. military, multiple managed service providers who managed the computer networks and security for other companies, a leading provider of 5G network equipment, and a leading global provider of wireless technology, among many others.

Targeting for Transnational Repression of Dissidents

The defendants and the APT31 Group also targeted individual dissidents around the world and other individuals who were perceived as supporting such dissidents. For example, in 2018, after several activists who spearheaded Hong Kong’s Umbrella Movement were nominated for the Nobel Peace Prize, the defendants and the APT31 Group targeted Norwegian government officials and a Norwegian managed service provider. The conspirators also successfully compromised Hong Kong pro-democracy activists and their associates located in Hong Kong, the United States, and other foreign locations with identical malware.

The charged defendants’ roles in the conspiracy consisted of testing and exploiting the malware used to conduct these intrusions, managing infrastructure associated with these intrusions, and conducting surveillance and intrusions against specific U.S. entities. For example:

  • Cheng Feng, Sun Xiaohui, Weng Ming, Xiong Wang, and Zhao Guangzong were involved in testing and exploiting malware, including malware used in some of these intrusions.
  • Cheng and Ni Gaobin managed infrastructure associated with some of these intrusions, including the domain name for a command-and-control server that accessed at least 59 unique victim computers, including a telecommunications company that was a leading provider of 5G network equipment in the United States, an Alabama-based research corporation in the aerospace and defense industries, and a Maryland-based professional support services company.
  • Sun and Weng operated the infrastructure used in an intrusion into a U.S. company known for its public opinion polls. Sun and Peng Yaowen conducted research and reconnaissance on several additional U.S. entities that were later the victims of the APT31 Group’s intrusion campaigns.
  • Ni and Zhao sent emails with links to files containing malware to PRC dissidents, specifically Hong Kong legislators and democracy advocates, as well as targeting U.S. entities focusing on PRC-related issues.

Assistant U.S. Attorneys Douglas M. Pravda, Saritha Komatireddy, and Jessica Weigel for the Eastern District of New York are prosecuting the case, with valuable assistance from Matthew Anzaldi and Matthew Chang of the National Security Division’s National Security Cyber Section.

An indictment is merely an allegation. All defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.

Wednesday, July 29, 2015

DoD Releases Report on Security Implications of Climate Change



DoD News, Defense Media Activity

WASHINGTON, July 29, 2015 – Global climate change will aggravate problems such as poverty, social tensions, environmental degradation, ineffectual leadership and weak political institutions that threaten stability in a number of countries, according to a report the Defense Department sent to Congress yesterday.

The Senate Appropriations Committee requested the report in conjunction with the Defense Appropriations Act for Fiscal Year 2015, asking that the undersecretary of defense for policy provide a report that identifies the most serious and likely climate-related security risks for each combatant command and the ways those commands integrate risk mitigation into their planning processes.

Fragile States Vulnerable to Disruption

The report finds that climate change is a security risk, Pentagon officials said, because it degrades living conditions, human security and the ability of governments to meet the basic needs of their populations. Communities and states that already are fragile and have limited resources are significantly more vulnerable to disruption and far less likely to respond effectively and be resilient to new challenges, they added.

“The Department of Defense's primary responsibility is to protect national security interests around the world,” officials said in a news release announcing the report’s submission. “This involves considering all aspects of the global security environment and planning appropriately for potential contingencies and the possibility of unexpected developments both in the near and the longer terms.

“It is in this context,” they continued, “that the department must consider the effects of climate change -- such as sea level rise, shifting climate zones and more frequent and intense severe weather events -- and how these effects could impact national security.”

Integrating Climate-Related Impacts Into Planning

To reduce the national security implications of climate change, combatant commands are integrating climate-related impacts into their planning cycles, officials said. The ability of the United States and other countries to cope with the risks and implications of climate change requires monitoring, analysis and integration of those risks into existing overall risk management measures, as appropriate for each combatant command, they added.

The report concludes the Defense Department already is observing the impacts of climate change in shocks and stressors to vulnerable nations and communities, including in the United States, the Arctic, the Middle East, Africa, Asia and South America, officials said.