Internet Computer Mobile Games

Why Nation States Hack Personal Information

US Office of Personnel Management (OPM) recently announced a massive data breach, containing very personal and private data of government and military personnel.  The stolen data was originally gathered to process security clearances and contains a plethora of background information, including criminal records, mental conditions, drug usage, veteran status, birthdates, social security numbers, pay histories and pension figures, insurance data, financial records, home addresses, contacts, and other profile data.  Millions of records in total were stolen, for current and previous government workers, contractors, and partners.  Investigators concluded the attack was conducted by another nation state. 

 

This leads to the question of why would another nation launch such an attack and how will they use such personal information to their advantage?  The answers might be shocking.

 

Unlike cybercriminals, who would be interested in opening lines of credit, filing fictions tax refunds, creating false identities, siphoning financial assets, and fraudulently charging on accounts, nation states have different motivations which drive their actions.  Nation states are interested in influencing policies in their favor across the globe, boosting national economic strength, military power projection, enhancing intelligence gathering capabilities, and protecting themselves from foreign attempts to do the same against them.

 

For centuries, one of the best ways to accomplish these goals has been by influencing, manipulating, or outright controlling important people in other countries.  Employing tactics to achieve such lofty goals requires two things.  First, key foreigners with the necessary power or access must be identified.  Secondly, the means to best influence them must be determined.  History has shown that with both pieces to the puzzle, governments can maneuver in advantageous ways to achieve nothing short of world change.  

 

Many nations have elaborate infrastructures and organizations dedicated to these goals.  They use a variety of Open Source Intelligence (OSINT), Human Intelligence (HUMINT), and Cyber Intelligence (CYBINT) methods to gather insights and data.  Nowadays, OSINT is very effective and with the meteoric rise in social media sharing and personal applications, has become a highly productive tool at providing personal details of a populace.  However, the deepest secrets and most private information is still difficult to come by.  CYBINT can fill the gaps and provide the hard to come by intelligence and personal connections which are highly valuable for these campaigns. 

 

Profile Intelligence
With the wealth of personal data fleeced from OPM, an attacker can begin building a database of interlocking profiles.  The result is a network showing people, connections, access, knowledge, and spheres of influence.  This information will be blended with any other high confidence data, garnered from other sources, to paint a better picture of individuals who may be of interest.  They will likely be looking for those who are active in local and national politics, drive or enforce inter-agency government policies, leaders and technical advisors to the military, those who possess influence in the decisions of others, have internal access to valuable data, are part of the offensive/defensive intelligence apparatus, and people who have earned the trust of those in power.

 

These people become targets of focus and opportunity for various types of influencing tactics, including bribery, blackmail, marketing, facilitation of revenge, social pressure, ethical conundrums, retribution of justice, and demonstrations of patriotism.   Professional manipulators can be very creative in how to position and push people in certain directions.

 

Methods of Influence
These profiles are also intended to give insights to how people can be motivated and controlled.  Building a collective social picture can show how key individuals are influenced.  It may highlight the respected close community around a target who offer advice and guidance.  Past indiscretions can provide an understanding of how someone is vulnerable to situations involving drugs, money, , ideology, or fame.  This can be exactly what is needed by manipulators. 

 

Personal and private information can be embarrassing or give the necessary signs of weakness.  Some people can be blackmailed, threatened, tricked, cheated, bribed, or flipped to provide information, access, or facilitate the influence of others.  A cascade effect can take place as people are linked.  In rare cases, some assets may be groomed to become direct action operatives, where the risks, impacts, and rewards can be much higher. 

 

Achieving success is no easy task for nation state orchestrators.  Private information is a highly prized chip in this game.  The more sensitive, revealing, and humiliating the data, the more valuable it is to those who plan to use it as leverage for their benefit.

 

Beyond the targeting of individuals, such data can be valuable in other ways.  To disrupt the operational effectiveness of an organization, key personnel can be affected with campaigns to publicly embarrass or undermine renewals for top clearances therefore causing gaps or delays in the work of important positions.  This can also provide advancement avenues for others who may be more conducive to support the attacker’s objectives.

 

Compromising computer systems becomes much easier.  In the cybersecurity realm, private information and a list of known contacts makes phishing attacks near impossible to defend against.  Emails, texts, attachments, and files can appear to be sent from friends, family, coworkers, academia, and professional colleagues with no good way for the average person to discern the difference between legitimate and malicious, until it is too late.  These phishing attacks can bypass system defenses and allow hackers to gain access to computers, networks, databases, and cloud environments.  Follow-on attacks in this manner should be expected, both at home and work.  Infecting and controlling devices of people with security clearances is an opportunity not likely passed-up by nation state attackers.

 

The data itself has value and can be sold, traded, or given to a variety of other groups.  Terrorists, allies, political rivals, in-country revolutionaries, radicals, or other nation state intelligence agencies would be likely interested parties. 

 

There are national economic advantages as well.  Discretely providing profile data to state-owned companies can greatly improve their business negotiations, bidding, pricing, employee recruiting activities, and overall competiveness abroad.  This can boost domestic economies while undermining foreign positions.  

 

Politically, in a bit of irony, such attacks may also drive the desire of attacked nations to establish international accords governing global cybersecurity practices with their attackers.  In essence, hacking can motivate governments to come to the negotiation table and put them at a disadvantage in the agreement of terms.   

 

With the loss of millions of highly personal records, the outlook is not a pretty picture.  Time will tell which of these tactics will be employed by those who took OPM data.  But keep in mind such spycraft has been around for thousands of years.  The intents and purposes are not new, just the scale, tactics, and tools have changed to include the information rich world of cyber. 

 

My heart goes out to those whose data was part of the recent breach, their families, friends, and associates.  In a very personal way, they are all now part of a larger geopolitical game.  Take all necessary precautions to protect your name, reputation, finances, history, and honor.  Although the attack cannot be undone, governments around the world can learn from these situations and institute better controls, data policies, and political responses to protect future generations.


Top similar posts to Why Nation States Hack Personal Information

Hp pavilion dv6 notbook pc /product number LS308EA [Personal Information Removed]

Recovery to factory recovery  / Bootmgr missing /iso not active /usp  cd/dvd  drive cannot boot  / pwhe7.iso no response   ...

Forum policies about personal contact information

It's usual for an online forum to have a specific rule about not publicly disclose personal information such as email address, phone numbers, Facebook pages and so on and so fourth. Such policy aims to protect users (from themselves). I haven't noticed such policy and/or practice here so I'm asking for a clarification. My concern was triggered by this: http://ubuntuforums.org/showthread.php?t=2248938 ...

Personal information of almost 100,000 people exposed through flaw on site for transcripts

The personal information of almost 100,000 people seeking their high school transcripts was recently exposed on a Web site that helps students obtain their records. The site, NeedMyTranscript.com, facilitates requests from all 50 states and covers more than 18,000 high schools around the country, according to its Web site and company chief executive officer. The data included names, addresses, e-mail addresses, phone numbers, dates of birth, mothers' maiden names and the last four...

Concerned about streaming personal information DNLA

Hi there! Im just discovering the amazing world of DNLA. I have streamed my videos from my computer and I can see them in my phone and vice versa and i must say that it was great, but I am concened about my security and personal information as Im sharing my internet conection with 3 more computers from my flatmates. I would like to know how I could block the access of my media to my flatmates as well as restrict the access of pictures in particular to any device.  Thank you....

how to remove personal information in excel 2013

Hi, How to remove personal information in excel 2013? However, I find the below link but its not working in excel 2013. http://www.exceldigest.com/myblog/20...om-a-workbook/ Regards, Ashish ...

18.5 Million Californians’ Personal Information Put at Risk

Quote: Attorney General Kamala D. Harris today released the second annual report detailing the 167 data breaches reported to the Attorney General’s office in 2013 that impacted18.5 million Californians by putting their personal information at risk. The report is accompanied by recommendations from the Attorney General for consumers, businesses and lawmakers on how to protect against data breaches and prevent them in the future. “Data breaches pose a serious threat to...

United States - Information and Discussion on TWC

United States of America Lead Developers Developers Modeler: Textures: DB Editor/ Historical Researchers: Unit List To be placed here Building ChainBuilding Chain Technology TreeTechnology Tree Graphics DevelopmentGraphics Development ...

Caucasus States Faction - Information and Discussion on TWC

CHERKESS (CIRCASSIA) | KHANATE OF AVARISTAN | CRIMEAN KHANATE | GEORGIA The States of the Caucasus: At the crossroads of Europe and Asia It is believed that improvements in this region will present a greater challenge to the Russian game-play. We renamed Dagestan, created Cherkess faction, and make improvement to Georgia and Crimean Khanate. [Reserved] ...

Why can't I turn down a personal union especially with a really strong nation.

I have a Prussia game I was playing and I was in a delicate situation with a pretty large kingdom and trying to calm things down and suddenly I ended up with a personal union with France. I didn't want this. I was using them as an ally while I ate everyone else and suddenly they were in a union with me and had firehatred on me. I put a diplomat on them the very second they turned and got them to liking me about 130 and they still revolted with several allies. (they had positive like to me but ...

Personal Information and Service Tag/Express Code?

I'm planning on selling my Alienware M17xR3 and am curious is there any personal info attached to my service tag, express service code or s? Should someone call about this pc in the future could they get any info from DELL or their customer service/order information?...

Personal Information and Service Tag/Express Code?

They could try which is why you need to transfer the ownership of the service tag to the buyer using this form BEFORE you send the laptop to them. The form will require the buyers data = Full name Shipping address Phone Email...

Don’t Use Personal Information in Your Wi-Fi Network Name

Routers often come with easy-to-guess passwords out of the box, which is why you always need to change the default settings . For the wireless network name, many people choose something easy to remember, like your name or your address. If you use that personal information for the network name, you might make a hacker's job easier.Read more......

[all variants] Personal Information...MY Information

My brother posed a question to me a few weeks back that got me thinking. I'll first off start with saying he is a die hard Microsoft Windows fan. He goes on and on touting the security of Windows concerning it's security that's built in as well as anit-virus software that helps keep your information yours. Keeping on this train of thought, and ONLY keeping on this train of throught, his thought process is this: Microsoft is a corporation that sells Windows computers. LInux is community driv...

Personal screen and flight information

Can you pull up a onscreen map of where your flight is and track its progress? ...

Passing information between states?

So I've been learning about gamestates lately. Learning from here: http://gamedevgeek.com/tutorials/managing-game-states-in-c/   And I get the idea of how you can 'push' new states onto the stack and resume for later, but I'm concerned about passing relative information between them.   Say I have a 'menuState' showing available levels and the user clicks 'level1' starting a new state 'gameState'. How would the gameState I just created know what level to load, and also how would it...

Design Apple Development Security Automobile Network Photography Health Money Travel Shopping Issues Operating systems Drivers Software Programming Tech Home Science Sport Solution