{"id":4900,"date":"2017-08-20T23:16:56","date_gmt":"2017-08-20T23:16:56","guid":{"rendered":"http:\/\/www.theblackvault.com\/documentarchive\/?p=4900"},"modified":"2017-08-20T23:16:56","modified_gmt":"2017-08-20T23:16:56","slug":"rasputin-hacker-attack-government-agencies-universities","status":"publish","type":"post","link":"https:\/\/www.theblackvault.com\/documentarchive\/rasputin-hacker-attack-government-agencies-universities\/","title":{"rendered":"Rasputin Hacker Attack on Government Agencies and Universities"},"content":{"rendered":"<h3>Background<\/h3>\n<p>In February of 2017, the magazine Computer World published the following article:<\/p>\n<p style=\"padding-left: 30px;\"><em><strong>A \u201cRussian-speaking and notorious financially-motivated\u201d hacker known as Rasputin has been at it again, hacking into universities and government agencies this time, before attempting to sell the stolen data on the dark web.<\/strong><\/em><\/p>\n<p style=\"padding-left: 30px;\"><em><strong>According to the security company\u00a0Recorded Future, which has been tracking the cybercriminal\u2019s breaches, Rasputin\u2019s most recent victims include 63 \u201cprominent universities and federal, state, and local U.S. government agencies.\u201d The security firm has been following Rasputin\u2019s activity since late 2016 when the hacker reportedly\u00a0breached\u00a0the\u00a0U.S. Electoral Assistance Commission\u00a0and then sold EAC access credentials.<\/strong><\/em><\/p>\n<p style=\"padding-left: 30px;\"><em><strong>Recorded Future claims that Rasputin\u2019s victims are \u201cintentional targets of choice based on the organization\u2019s perceived investment in security controls and the respective compromised data value. Additionally, these databases are likely to contain significant quantities of users and potentially associated personally identifiable information (PII).\u201d<\/strong><\/em><\/p>\n<p style=\"padding-left: 30px;\"><em><strong>All of the hacked agencies and universities have been notified about the breaches by Recorded Future. There were 16 U.S. state government victims, 6 U.S. cities and four federal agencies. Additionally, there were two \u201cother\u201d .gov sites which included\u00a0Fermi National Accelerator Laboratory, \u201cAmerica\u2019s premier particle physics lab,\u201d and the\u00a0Child Welfare Information Gateway, which is \u201ca service of the Children&#8217;s Bureau, Administration for Children and Families, U.S. Department of Health and Human Services.\u201d<\/strong><\/em><\/p>\n<p>They printed a list of those that were attacked and breached:<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"aligncenter size-full wp-image-4901\" src=\"http:\/\/www.theblackvault.com\/documentarchive\/wp-content\/uploads\/2017\/08\/2017-08-20_16-09-01.jpg\" alt=\"\" width=\"627\" height=\"591\" srcset=\"https:\/\/www.theblackvault.com\/documentarchive\/wp-content\/uploads\/2017\/08\/2017-08-20_16-09-01.jpg 627w, https:\/\/www.theblackvault.com\/documentarchive\/wp-content\/uploads\/2017\/08\/2017-08-20_16-09-01-600x566.jpg 600w, https:\/\/www.theblackvault.com\/documentarchive\/wp-content\/uploads\/2017\/08\/2017-08-20_16-09-01-300x283.jpg 300w, https:\/\/www.theblackvault.com\/documentarchive\/wp-content\/uploads\/2017\/08\/2017-08-20_16-09-01-150x141.jpg 150w, https:\/\/www.theblackvault.com\/documentarchive\/wp-content\/uploads\/2017\/08\/2017-08-20_16-09-01-450x424.jpg 450w\" sizes=\"(max-width: 627px) 100vw, 627px\" \/><\/p>\n<p>I filed FOIA requests to the various agencies attacked, and will archive the responsive records below.<\/p>\n<h3>Document Archive<\/h3>\n<h4>Postal Regulatory Commission<\/h4>\n<p><img decoding=\"async\" src=\"https:\/\/www.theblackvault.com\/images\/pdf.gif\" \/>\u00a0<a href=\"https:\/\/documents.theblackvault.com\/documents\/usps\/PRC-RasputinHack-March2017.pdf\">Documents Released March 31, 2017<\/a> [124 Pages, 26.7MB] &#8211; It appears that although reported to have been hit by the attack, internal documents show they were clean and there were no signs of an intrusion.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Background In February of 2017, the magazine Computer World published the following article: A \u201cRussian-speaking and notorious financially-motivated\u201d hacker known as Rasputin has been at it again, hacking into universities and government agencies this time, before attempting to sell the stolen data on the dark web. According to the security company\u00a0Recorded Future, which has been<\/p>\n","protected":false},"author":1,"featured_media":4902,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"episode_type":"","audio_file":"","transcript_file":"","podmotor_file_id":"","podmotor_episode_id":"","cover_image":"","cover_image_id":"","duration":"","filesize":"","filesize_raw":"","date_recorded":"","explicit":"","block":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[2],"tags":[],"class_list":{"0":"post-4900","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-government"},"aioseo_notices":[],"jetpack_featured_media_url":"https:\/\/www.theblackvault.com\/documentarchive\/wp-content\/uploads\/2017\/08\/2017-08-20_16-16-03.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.theblackvault.com\/documentarchive\/wp-json\/wp\/v2\/posts\/4900","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.theblackvault.com\/documentarchive\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.theblackvault.com\/documentarchive\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.theblackvault.com\/documentarchive\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.theblackvault.com\/documentarchive\/wp-json\/wp\/v2\/comments?post=4900"}],"version-history":[{"count":0,"href":"https:\/\/www.theblackvault.com\/documentarchive\/wp-json\/wp\/v2\/posts\/4900\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.theblackvault.com\/documentarchive\/wp-json\/wp\/v2\/media\/4902"}],"wp:attachment":[{"href":"https:\/\/www.theblackvault.com\/documentarchive\/wp-json\/wp\/v2\/media?parent=4900"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.theblackvault.com\/documentarchive\/wp-json\/wp\/v2\/categories?post=4900"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.theblackvault.com\/documentarchive\/wp-json\/wp\/v2\/tags?post=4900"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}