Showing posts with label NSA. Show all posts
Showing posts with label NSA. Show all posts

Tuesday, April 30, 2024

Former NSA Employee Sentenced To More Than 21 Years In Prison For Attempted Espionage


The U.S. Justice Department released the below information:

Jareh Sebastian Dalke, 32, of Colorado Springs, was sentenced today to 262 months in prison for attempted espionage in connections with his efforts to transmit classified National Defense Information (NDI) to an agent of the Russian Federation.

According to court documents, Dalke pleaded guilty in 2023 to six counts of attempting to transmit classified NDI to a foreign agent. From June 6 to July 1, 2022, Dalke was an employee of the National Security Agency (NSA) where he served as an Information Systems Security Designer. Dalke admitted that between August and September 2022, in order to demonstrate both his “legitimate access and willingness to share,” he used an encrypted email account to transmit excerpts of three classified documents to an individual he believed to be a Russian agent. That person was an FBI online covert employee. All three documents from which the excerpts were taken contain NDI, are classified as Top Secret//Sensitive Compartmented Information (SCI) and were obtained by Dalke during his employment with the NSA.

“This defendant, who had sworn an oath to defend our country, believed he was selling classified national security information to a Russian agent, when in fact, he was outing himself to the FBI,” said Attorney General Merrick B. Garland. “This sentence demonstrates that that those who seek to betray our country will be held accountable for their crimes. I am grateful to the FBI Denver and Washington Field Offices for their extraordinary work on this case.”

“This sentence should serve as a stark warning to all those entrusted with protecting national defense information that there are consequences to betraying that trust,” said FBI Director Christopher Wray. “Dalke believed he was passing classified information to an agent of the Russian government. The hard work of our FBI employees prevented that from happening and any potential harm to the United States.”

“Two primary objectives of the U.S. Attorney’s Office for the District of Colorado include keeping our citizens safe, and safeguarding the United States of America,” said U.S. Attorney Cole Finegan for the District of Colorado. “Not only is this case an exceptional example of federal law enforcement cooperation, but the sentence Mr. Dalke received today reflects the seriousness of the actions he took in attempt to injure our country and help a foreign government.”

On or about Aug. 26, 2022, Dalke requested $85,000 in return for all the information in his possession. Dalke claimed the information would be of value to Russia and told the FBI online covert employee that he would share more information in the future, once he returned to the Washington, D.C.-area.

Dalke subsequently arranged to transfer additional classified information in his possession to the purported Russian agent at Union Station in downtown Denver. Using a laptop computer and the instructions provided by the FBI online covert employee, Dalke transferred five files, four of which contain Top Secret NDI. The other file was a letter, which begins (in Russian and Cyrillic characters) “My friends!” and states, in part, “I am very happy to finally provide this information to you… I look forward to our friendship and shared benefit. Please let me know if there are desired documents to find and I will try when I return to my main office.” The FBI arrested Dalke on Sept. 28, 2023, moments after he transmitted the files.

As part of his plea agreement, Dalke admitted that he willfully transmitted files to the FBI online covert employee with the intent and reason to believe the information would be used to injure the United States and to benefit Russia.

The FBI Washington and Denver Field Offices investigated the case.

Assistant U.S. Attorneys Julia K. Martinez and Jena R. Neuscheler for the District of Colorado and Trial Attorneys Christina A. Clark and Adam L. Small of the National Security Division’s Counterintelligence and Export Control Section handled the prosecution.

 

 

 

Sunday, April 28, 2024

Rook: A Look Back At A Vietnam Era Spy Sentenced In Philadelphia

My Crime Beat column below originally appeared in the South Philadelphia American in October of 1997:

Spy stories traditionally unfold in Berlin, Hong Kong or some other exotic locale, but a 30-year espionage drama ended right here in a Philadelphia courthouse last week when Robert Stephen Lipka was sentenced to 18 years in prison for spying for the Soviet Union.

Lipka, 51, a coin collector from Lancaster, PA, admitted to spying from 1965 to 1974, the years of the Vietnam War, while serving as a young soldier attached to the National Security Agency (NSA). (NSA HQ at Fort Meade in Maryland is seen in the below photo).

A series of FBI investigations originating in the 1960's led to Lipka's sentencing day in the federal court at 6th and Market Streets. U.S. District Judge Charles r. Weiner, a WWII Navy veteran, admonished Lipka by saying that the parents of military servicemen might feel his crimes caused their children's deaths or maiming during the Vietnam War. Weiner also imposed a fine of $10,000 to repay the $10,000 the FBI paid him during the undercover "sting" operation that ultimately netted him.

Lipka, who resembles the actor who plays the despicable character Newman on TV's Seinfeld, no doubt shares some of Newman's more unsavory characteristics. 

Lipka aided the Viet Cong and North Vietnamese while I, my brother and thousands of other soldiers, sailors, Marines and airmen were fighting over there. Lipka sold out his brothers-in-arms for a paltry $27,000.

Lipka's spy story began when he enlisted in the U.S. Army in 1963. He was assigned to NSA at Fort Meade in Maryland, a cushy headquarters job far from the combat zone. 

NSA, the super-secret organization we called "No Such Agency" when I was in the Navy, intercepts foreign electromagnetic, radio, radar and other transmissions for the U.S. military and intelligence agencies. Lipka's clerical job was to simply make distribution of NSA's highly classified reports. 

We now know that Lipka took it upon himself to add the Soviet Union to his mailing list.

According to the FBI, Lipka used special spy cameras to clandestinely photograph sensitive documents. He also hid classified documents inside his shirt and wrapped around his legs to slip past NSA security. Using common "tradecraft" such as a prearranged "dead drop," he passed the documents to the Komitet Gosudarstevennoy Bezopasnosti (KGB), the Soviet Committee of State security. He later retrieved payment at another prearranged site.

Lipka left the Army and NSA and moved to Lancaster in 1967 and attended college. Lipka took some "souvenirs" when he left NSA and was still meeting with the KGB as late as 1974.

It was an independent FBI investigation of a couple who lived near Philadelphia that led to FBI to Lipka. Peter Fischer, whom the FBI suspected was a KGB agent, Ingeborg Fischer, whom the FBI suspected of assisting her husband in his KGB activities, made contact with Lipka in 1968. Evidence suggests the Fischers passed NSA documents from Lipka to a Soviet citizen, Artem Shokin, who worked at the United Nations in New York. The Fischers and Shokin subsequently flew the coup and returned to Mother Russia.

An FBI undercover agent posing as an official Glavnoye Razvedyvatelnoye Upravleniye (GRU), the Chief Intelligence Directorate of the Soviet General Staff, met with Lipka several times in Lancaster and Baltimore in 1993. Lipka insisted that the undercover FBI special agent provide Lipka's code word or he would end their contact. 

The undercover agent mentioned Lipka's code word "Rook," which the FBI discovered during the Fischer investigation. Lipka, ever the greedy little spy, told the undercover agent that the Soviets had not paid him enough money. He would complain again and again about money and even wrote the undercover agent letters demanding more money.

The undercover agent mailed Lipka a copy of a book called The First Directorate, which was written by former KGB Major General Oleg Kalugin. The book implicates Lipka in its detailed description of espionage committed by a "young soldier at NSA," who provided "reams of top-secret material to the KGB in the mid-1960's.

According to the FBI, an unnamed "cooperating witness" who was granted immunity told the FBI that Lipka said he took NSA documents and sold them to the KGB. Lipka told the witness he gave them to a Russian contact named "Ivan" for money. Lipka said he would contact "Ivan" and have face-to-face meetings over a chess game in a park, hence the code name "Rook."

The witness was shown the three cameras, one of which was only an inch in height. Lipka told the witness that the Russian had sent him a postcard and Lipka, accompanied by the witness, met in Maryland with the Russian.

Faced with overwhelming evidence of the cooperating witness and the FBI undercover agent, Lipka had no choice but to plead guilty. He thought he had gotten away with espionage, but the long arm of the FBI and justice finally caught up with him. 

Note: Robert Lipka died in 2013.


You can also read my later Counterterrorism magazine interview with one of the FBI special agents involved with the Lipka investigation via the below link:

http://www.pauldavisoncrime.com/2014/06/before-snowden-look-back-at-nsa-spy.html 

Saturday, November 25, 2023

Former NSA Employee Pleads Guilty To Attempted Espionage: Defendant Admits To Attempting To Transmit National Defense Information To An Agent Of A Foreign Government

 The U.S. Justice Department released the below:

Jareh Sebastian Dalke, 31, of Colorado Springs, pleaded guilty today to six counts of attempting to transmit classified National Defense Information (NDI) to an agent of the Russian Federation (Russia).

According to court documents, from June 6, 2022, to July 1, 2022, Dalke was an employee of the National Security Agency (NSA) where he served as an Information Systems Security Designer. Dalke admitted that between August and September 2022, in order to demonstrate both his “legitimate access and willingness to share,” he used an encrypted email account to transmit excerpts of three classified documents to an individual he believed to be a Russian agent. In actuality, that person was an FBI online covert employee. All three documents from which the excerpts were taken contain NDI, are classified as Top Secret//Sensitive Compartmented Information (SCI) and were obtained by Dalke during his employment with the NSA.

On or about Aug. 26, 2022, Dalke requested $85,000 in return for all the information in his possession. Dalke claimed the information would be of value to Russia and told the FBI online covert employee that he would share more information in the future, once he returned to the Washington, D.C., area.

Dalke subsequently arranged to transfer additional classified information in his possession to the purported Russian agent at Union Station in downtown Denver. Using a laptop computer and the instructions provided by the FBI online covert employee, Dalke transferred five files, four of which contain Top Secret NDI. The other file was a letter, which begins (in Russian and Cyrillic characters) “My friends!” and states, in part, “I am very happy to finally provide this information to you. . . . I look forward to our friendship and shared benefit. Please let me know if there are desired documents to find and I will try when I return to my main office.” The FBI arrested Dalke on Sept. 28, moments after he transmitted the files.

As part of his plea agreement, Dalke admitted that he willfully transmitted files to the FBI online covert employee with the intent and reason to believe the information would be used to injure the United States and to benefit Russia.

Dalke faces a maximum penalty of up to life in prison. Sentencing is scheduled for April 26, 2024. A U.S. district court judge will determine any sentence after considering the U.S. Sentencing Guidelines and other statutory factors.

Assistant Attorney General Matthew G. Olsen of the Justice Department’s National Security Division, U.S. Attorney Cole Finegan for the District of Colorado and Executive Assistant Director Larissa L. Knapp of the FBI's National Security Branch made the announcement.

The FBI Washington and Denver Field Offices are investigating the case.

Assistant U.S. Attorneys Julia K. Martinez and Jena R. Neuscheler for the District of Colorado and Trial Attorneys Christina A. Clark and Adam L. Small of the National Security Division’s Counterintelligence and Export Control Section are prosecuting the case.

Thursday, September 29, 2022

Former NSA Employee Arrested On Espionage-Related Charges

The U.S. Justice Department released the below information:

A Colorado Springs man will make his initial appearance in federal court today on charges that he attempted to transmit classified National Defense Information (NDI) to a representative of a foreign government.

Jareh Sebastian Dalke, 30, was an employee of the National Security Agency (NSA) where he served as an Information Systems Security Designer from June 6, 2022, to July 1, 2022. According to the affidavit in support of the criminal complaint, between August and September 2022, Dalke used an encrypted email account to transmit excerpts of three classified documents he had obtained during his employment to an individual Dalke believed to be working for a foreign government. In actuality, that person was an undercover FBI agent. Dalke subsequently arranged to transfer additional classified information in his possession to the undercover FBI agent at a location in Denver, Colorado. The FBI arrested Dalke on Sept. 28, after Dalke arrived at the specified location.

According to the affidavit in support of the criminal complaint, Dalke began communicating on or about July 29, 2022, via encrypted email with an individual he believed to be associated with a foreign government. Dalke told that individual that he had taken highly sensitive information relating to foreign targeting of U.S. systems and information on U.S. cyber operations, among other topics. Dalke represented to the undercover FBI agent that he was still employed by the U.S. government but said he was on a temporary assignment at a field location. Dalke requested compensation via a specific type of cryptocurrency in exchange for the information he possessed and stated that he was in financial need.

To prove he had access to sensitive information, Dalke transmitted excerpts of three classified documents to the undercover FBI agent. Each excerpt contained classification markings. One excerpt was classified at the Secret level, and two excerpts were classified at the Top Secret level. In return for this information, the FBI undercover agent provided the requested cryptocurrency to an address Dalke provided.

On or about Aug. 26, 2022, Dalke requested $85,000 in return for additional information in his possession. Dalke also told the FBI undercover agent that he would share additional information in the future, once he returned to the Washington, D.C., area. Although he was not employed by the NSA while communicating with the FBI, Dalke re-applied to the NSA in August 2022.

Dalke agreed to transmit additional information using a secure connection set up by the FBI at a public location in Denver. On Sept. 28, at that location, the FBI arrested Dalke based on a signed criminal complaint.

Dalke is charged by criminal complaint alleging three violations of the Espionage Act, which makes it a crime to transmit or attempt to transmit NDI to a representative of a foreign nation with intent or reason to believe that information could be used to the injury of the United States or to the advantage of a foreign nation. The Espionage Act carries a potential sentence of death or any term of years up to life.

Assistant Attorney General Matthew G. Olsen of the Justice Department’s National Security Division; U.S. Attorney Cole Finegan for the District of Colorado; Assistant Director Alan E. Kohler Jr. of the FBI’s Counterintelligence Division; Assistant Director in Charge Steven M. D’Antuono of the FBI Washington Field Office and Acting Special Agent in Charge Cheryl Mimura of the FBI Denver Field Office made the announcement.

Assistant U.S. Attorneys Julia K. Martinez and Jena R. Neuscheler for the District of Colorado, and Trial Attorneys Christina A. Clark and Adam L. Small of the National Security Division’s Counterintelligence and Export Control Section are prosecuting on behalf of the government. The case is being investigated by the FBI Denver Field Office and the FBI Washington Field Office.

A criminal complaint is merely an allegation, and all defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law.

Thursday, January 13, 2022

FBI, CISA And NSA Release Cybersecurity Advisory On Russian Cyber Threats To U.S. Critical Infrastructure


CISA, the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) have released a joint Cybersecurity Advisory (CSA) that provides an overview of Russian state-sponsored cyber operations, including commonly observed tactics, techniques, and procedures. The CSA also provides detection actions, incident response guidance, and mitigations. CISA, the FBI, and NSA are releasing the joint CSA to help the cybersecurity community reduce the risk presented by Russian state-sponsored cyber threats.  

CISA, the FBI, and NSA encourage the cybersecurity community—especially critical infrastructure network defenders—to adopt a heightened state of awareness, conduct proactive threat hunting, and implement the mitigations identified in the joint CSA. CISA recommends network defenders review CISA's Russia Cyber Threat Overview and Advisories page for more information on Russian state-sponsored malicious cyber activity. CISA recommends critical infrastructure leaders review CISA Insights: Preparing For and Mitigating Potential Cyber Threats for steps to proactively strengthen their organization’s operational resiliency against sophisticated threat actors, including nation-states and their proxies. 

Tuesday, July 27, 2021

Former Intelligence Analyst Sentenced To 45 Months In Prison For Disclosing Classified Information To Reporter


 The U.S. Justice Department released the below information: 

A Tennessee man was sentenced today to 45 months in prison followed by three years of supervised release for illegally obtaining classified national defense information and disclosing it to a reporter. 

According to court documents, Daniel Everette Hale, 33, of Nashville, began communicating with a reporter beginning in April 2013 while enlisted in the U.S. Air Force and assigned to the National Security Agency (NSA). Hale admitted to meeting with the reporter in person on multiple occasions and communicating with the reporter via phone, text message, email and, at times, an encrypted messaging platform. 

In February 2014, while working as a cleared defense contractor at the National Geospatial-Intelligence Agency (NGA), Hale printed six classified documents unrelated to his work at NGA and soon after exchanged a series of messages with the reporter. Each of the six documents printed were later published by the reporter’s news outlet. 

According to court records, while employed as a cleared defense contractor for NGA, Hale printed 36 documents from his Top Secret computer, including 23 documents unrelated to his work at NGA. Of the 23 documents unrelated to his work at NGA, Hale provided at least 17 to the reporter and/or the reporter’s online news outlet, which published the documents in whole or in part. Eleven of the published documents were marked as Top Secret or Secret. 

According to court records, in August 2014, Hale’s cell phone contact list included contact information for the reporter. He also possessed a thumb drive that contained a page marked “SECRET” from a classified document that Hale had printed in February 2014 and had attempted to delete from the thumb drive. In addition, Hale possessed on his home computer another document that he had stolen from NGA. 

Hale pleaded guilty to retention and transmission of national defense information on March 31.

Acting Assistant Attorney General Mark J. Lesko of the Justice Department’s National Security Division made the announcement. 

The FBI’s Baltimore Field Office investigated the case. 

Assistant U.S. Attorneys Gordon D. Kromberg and Alexander P. Berrang for the Eastern District of Virginia and Senior Trial Attorney Heather M. Schmidt of the National Security Division’s Counterintelligence and Export Control Section prosecuted the case.

Saturday, July 3, 2021

NSA, Cybercom Leader Says Efforts Have Expanded

 David Vergun at the DOD News offers the below piece: 

Adversaries have heavily invested in cyberspace operations and capabilities. As such, cyber operations, cybersecurity and information operations are increasingly important to the joint force, said the commander of U.S. Cyber Command, who's also the director of the National Security Agency. 

"The scope of what we need to defend and protect has dramatically expanded," Army Gen. Paul M. Nakasone said today during a virtual address to the U.S Naval Institute and Armed Forces Communications and Electronics Association's WEST Conference. 

The Defense Department's information network is composed of 15,000 sub-networks, 3 million users, 4 million computers, 180,000 mobility devices and 605 million website requests a day, he said.  

"We used to think about cyberspace as merely the need to protect these computer networks. And while it's a good place to start, the attack surface is much broader," Nakasone said. 

For example, protecting weapons systems is a related but distinct challenge compared to networks, he said. They require software updates and patches. In the case of the Navy, they're onboard ships that don't return to port for months at a time, making it even more challenging to provide timely updates. 

Another challenge with weapons systems is ensuring that cybersecurity considerations are implemented in the earliest phases of the acquisition cycle, he said. 

Protecting DOD's data is also a major challenge, he said. 

Understanding how state and non-state adversaries are able to successfully carry out cyberattacks is important, he said. "They learn over time in terms of what they can do. They're not static in the terms of how they approach cyberspace." 

In about the past 150 days, adversaries have successfully conducted supply chain attacks, particularly ransomware attacks, he said. In the last several years, election cybersecurity has taken on an increasingly important role. 

Terrorist groups are also mounting cyberattacks, he said. In response, the department has emphasized close teamwork between the NSA, Cybercom, and other commands — U.S. Special Operations Command, in particular. 

"We learned how to work closely with U.S. Special Operations Command, both to support their efforts against kinetic targets and to leverage their capabilities against virtual ones," he said. 

Nakasone also emphasized the importance of working with industry, academia, interagency partners like the FBI and the Department of Homeland Security, as well as with allies and partners. 

Having a skilled and motivated workforce is also critically important, he said. They need to have the right training and career paths and professional development opportunities, and the DOD must be open to their new ideas.

Sunday, August 16, 2020

Traitor, Fraud, Sneak Thief, Spy: Trump Reviewing Idea Of Pardoning Edward Snowden


President Trump told the New York Post that he was considering pardoning the NSA leaker and traitor Edward Snowden.

I trust his national security advisors will convince him to not do so.

In October of last year, I published a piece on Snowden in the Washington Times.

NSA leaker Edward Snowden has published a memoir called “Permanent Record.”

I’ve not read his book and I probably won’t.


I recall the late conservative columnist Charles Krauthammer on Fox News criticizing Mr. Snowden’s video appearance live from Russia to a conference in America in 2014. He was offended particularly by Mr. Snowden’s several references to the U.S. Constitution.

“I don’t want to be lectured by a traitor who speaks from a land that doesn’t have a constitution,” Krauthammer said. 

Like Krauthammer, I don’t want to be lectured by Mr. Snowden and I don’t think I would glean any insights from a self-aggrandizing book by this liar, fraud, sneak thief and traitor.

The former CIA employee and NSA contractor stole and subsequently released to journalists in 2013 more than 1.5 million classified documents. The broad and largely unfiltered intel dump endangered American lives worldwide, and he no doubt gave much more damaging material to his hosts and protectors, the Chinese and the Russians.

Rather than reading Mr. Snowden’s suspect memoir, I reread the 2016 House Intelligence Committee’s bipartisan and unclassified report, “Review of the Unauthorized Disclosures of Former National Security Agency Contractor Edward Snowden..”

According to the report’s executive summary, Edward Snowden perpetrated the largest and most damaging public release of classified information in U.S. intelligence history. In August 2014, the chairman and ranking member of the House Permanent Select Committee on Intelligence directed committee staff to carry out a comprehensive review of the unauthorized disclosures.

The two-year extensive review offered a number of unclassified findings. According to the report, “these findings demonstrate that the public narrative popularized by Snowden and his allies is rife with falsehoods, exaggerations, and crucial omissions, a pattern that began before he stole 1.5 million sensitive documents.

“Snowden caused tremendous damage to national security, and the vast majority of the documents he stole have nothing to do with programs impacting individual privacy interests — they instead pertain to military, defense, and intelligence programs of great interest to America’s adversaries,” the report stated.

You can read the rest of the piece via the below link:

Monday, June 4, 2018

Costs Of Snowden Leak Still Mounting 5 Years Later


Deb Riechmann at apnews.com offers a piece on the continuing damage of the Edward Snowden leaks of classified information.

WASHINGTON (AP) — Whistleblower or traitor, leaker or public hero?

National Security Agency contractor Edward Snowden blew the lid off U.S. government surveillance methods five years ago, but intelligence chiefs complain that revelations from the trove of classified documents he disclosed are still trickling out.

That includes recent reporting on a mass surveillance program run by close U.S. ally Japan and on how the NSA targeted bitcoin users to gather intelligence to support counterterrorism and to combat narcotics and money laundering. The Intercept, an investigative publication with access to Snowden documents, published stories on both subjects.
  
The top U.S. counterintelligence official said journalists have released only about 1 percent taken by the 34-year-old American, now living in exile in Russia, “so we don’t see this issue ending anytime soon.”

“This past year, we had more international, Snowden-related documents and breaches than ever,” Bill Evanina, who directs the National Counterintelligence and Security Center, said at a recent conference. “Since 2013, when Snowden left, there have been thousands of articles around the world with really sensitive stuff that’s been leaked.”

On June 5, 2013, The Guardian in Britain published the first story based on Snowden’s disclosures. It revealed that a secret court order was allowing the U.S. government to get Verizon to share the phone records of millions of Americans. Later stories, including those in The Washington Post, disclosed other snooping and how U.S. and British spy agencies had accessed information from cables carrying the world’s telephone and internet traffic.

You can read the rest of the piece via the below link:



You can also read my Washington Times piece on Snowden - traitor, thief, scoundrel, spy- via the below link:

Saturday, March 17, 2018

Nominee For Top NSA Post Shares Views With Senators At Confirmation Hearing


Army Sgt. 1st Class Jose Ibarra at the DoD News offers the below piece:

WASHINGTON, March 15, 2018 — President Donald J. Trump’s nominee to serve as the next director of the National Security Agency today promised to defend the nation and secure the future as he testified before lawmakers during his confirmation hearing here.

Lt. Gen. Paul M. Nakasone (seen in the above official photo), the commander of U.S. Army Cyber Command, spoke before the Senate Select Committee on Intelligence, which is considering his nomination to succeed retiring Navy Adm. Michael S. Rogers as NSA director.

Ensuring Security

“The safeguard of our national secrets, the safeguard of our capabilities is one of the most important things the next director will continue to address,” Nakasone said, “My intent is to look to ensure the security of the enterprise and the security of the network initiatives that NSA has undertaken to date are timely, are accurate, are on target to ensure that we continue to have the safeguard of our national treasures,” he said.

He emphasized two elements that will help ensure national security.

The first focus, he said, is “continuing to hire great people that work at the NSA, not only hiring them, but also training them, developing them and ensuring that their long-term careers with the NSA are well-tended-to.”

Secondly, he said, the agency needs to continue to look at control mechanisms to provide the ability to safeguard networks and secure the environment.

If confirmed to the post, Nakasone will assume the current dual-hat arrangement of leading both U.S. Cyber Command and the NSA.

Strong Public-Private Partnership

The general emphasized the importance of working with the private sector on technology to secure the future and to continue to attract the best and the brightest to serve.

“If confirmed, I know that a strong public-private partnership will be needed to ensure this country benefits from the leading-edge technology being developed and implemented today and into the future,” Nakasone said, adding that the agency’s mission and technological advances are what sets the NSA apart from the public sector and helps to attract young talent.

“We have to continue broad abilities to continue to recruit from a very diverse population -- academia, and industry, [and] within inside our government,” Nakasone said, noting he admires the agency’s ability to look at a broad range of capabilities, including people who have disabilities, and to provide the necessary infrastructure that will support them.

Securing the Future

Nakasone addressed security concerns ranging from Russian and Chinese cyber threats to private-sector encryption platforms to soldiers wearing geolocation devices. He also touched on insider threats and how to reconsider looking at networks, data and weapons systems.

“Ten, 15, 20 years ago, we were concerned about what we said on phones. Today we’re concerned about what our soldiers wear, where they’re talking, where they’re able to be monitored,” he said. “This is indicative of how we have to approach the future. We are technologically informed -- we also have to be informed for operational security as well.”   

Tuesday, February 27, 2018

Cybercom Commander Discusses Evolving Cyber Threats


Navy Petty Officer 2nd Class Ignacio D. Perez at the DoD News offers the below piece:

WASHINGTON, Feb. 27, 2018 — Although competitors such as China and Russia remain the greatest threat to U.S. security, rogue regimes such as Iran and North Korea have increased in capabilities and have begun using aggressive methods to conduct malicious cyberspace activities, the military’s top cyber officer told Congress today.

Navy Adm. Michael S. Rogers (seen in the below photo), director of the National Security Agency, commander of U.S. Cyber Command and chief of the Central Security Service, testified at a Senate Armed Services Committee hearing.


“Our adversaries have grown more emboldened, conducting increasingly aggressive activities to extend their influence without fear of significant consequence,” Rogers said. “We must change our approaches and responses here if we are to change this dynamic.”

But as the cyber domain has evolved, Rogers told the senators, Cybercom’s three major mission areas endure: protecting the Department of Defense Information Network; enabling other joint force commanders by delivering effects in and through cyberspace; and defending the nation against cyber threats through support to the Department of Homeland Security and others when directed to do so by the president or secretary of defense.

Joint Force Headquarters DODIN, the subordinate headquarters responsible for securing, operating and defending the Defense Department's complex information technology infrastructure, has achieved full operational capability, he said.

Joint Task Force Ares, created to lead the fight in cyber against the Islamic State of Iraq and Syria, has successfully integrated cyberspace operations into broader military campaigns, has achieved some “excellent results,” and will continue to pursue ISIS in support of the nation's objectives, the admiral told the Senate panel.

Cybercom also has significantly enhanced training in cyber operation platforms to prepare the battlespace against key adversaries, he said.

Milestones expected to be achieved this year include Cyber Command’s elevation to a combatant command responsible for providing mission-ready cyberspace operations forces to other combatant commanders, Rogers said.

In addition, the admiral said, Cybercom will be moving into a state-of-the-art integrated cyber center and joint operations facility at Fort Meade, Maryland, enhancing the coordination and planning of operations against cyber threats.

“Without cyberspace superiority in today's battlefield, risk to mission increases across all domains and endangers our security,” Rogers said.

Cybercom’s focus on innovation and rapid tech development has extended all the way to small businesses and working with the private sector while maintaining cybersecurity, Rogers told the committee.

“We intend in the coming year to create an unclassified collaboration venue where businesses and academia can help us tackle tough problems without needing to jump over clearance hurdles, for example, which for many are very difficult barriers,” Rogers explained.

After serving more than four years as a commander of Cybercom and after nearly 37 years of service as a naval officer, Rogers is set to retire this spring.

“I will do all I can during the intervening period to ensure the mission continues, that our men and women remain ever motivated, and that we have a smooth transition,” he said.  

Friday, August 18, 2017

President Elevates U.S. Cyber Command To Unified Combatant Command


Jim Garamone and Lisa Ferdinando at the DoD News offer the below piece:

WASHINGTON, Aug. 18, 2017 — At the direction of the president, the Defense Department today initiated the process to elevate U.S. Cyber Command to a unified combatant command.

"This new unified combatant command will strengthen our cyberspace operations and create more opportunities to improve our nation’s defense," President Donald J. Trump said in a written statement.

The elevation of the command demonstrates the increased U.S. resolve against cyberspace threats and will help reassure allies and partners and deter adversaries, the statement said.  The elevation also will help to streamline command and control of time-sensitive cyberspace operations by consolidating them under a single commander with authorities commensurate with the importance of those operations and will ensure that critical cyberspace operations are adequately funded, the statement said.

Defense Secretary Jim Mattis is examining the possibility of separating U.S. Cyber Command from the National Security Agency, and is to announce his recommendations at a later date.

Growing Mission

The decision to elevate U.S. Cyber Command is consistent with Mattis' recommendation and the requirements of the fiscal year 2017 National Defense Authorization Act, Kenneth P. Rapuano, assistant secretary of defense for homeland defense and global security, told reporters at the Pentagon today.

"The decision is a welcome and necessary one that ensures that the nation is best positioned to address the increasing threats in cyberspace," he added.

Cybercom's elevation from its previous subunified command status demonstrates the growing centrality of cyberspace to U.S. national security, Rapuano said, adding that the move signals the U.S. resolve to "embrace the changing nature of warfare and maintain U.S. military superiority across all domains and phases of conflict."

Cybercom was established in 2009 in response to a clear need to match and exceed enemies seeking to use the cyber realm to attack the United States and its allies. The command is based at Fort George G. Meade, Maryland, with the National Security Agency. Navy Adm. Michael S. Rogers is the commander of U.S. Cyber Command and the National Security Agency director. The president has directed Mattis to recommend a commander for U.S. Cyber Command, and Rogers for now remains in the dual-hatted role, Rapuano said.

More Strategic Role

Since its establishment, Cybercom has grown significantly, consistent with DoD's cyber strategy and reflective of major increases in investments in capabilities and infrastructure, Rapuano said. The command reached full operational capability Oct. 31, 2010, but it is still growing and evolving. The command is concentrating on building its Cyber Mission Force, which should be complete by the end of fiscal year 2018, he said.

The force is expected to consist of almost 6,200 personnel organized into 133 teams. All of the teams have already reached initial operational capability, and many are actively conducting operations. The force incorporates reserve component personnel and leverages key cyber talent from the civilian sector.

"This decision means that Cyber Command will play an even more strategic role in synchronizing cyber forces and training,  conducting and coordinating military cyberspace operations, and advocating for and prioritizing cyber investments within the department,"  Rapuano said.

Cybercom already has been performing many responsibilities of a unified combatant command. The elevation also raises the stature of the commander of Cyber Command to a peer level with the other unified combatant command commanders, allowing the Cybercom commander to report directly to the secretary of defense, Rapuano pointed out.

The new command will be the central point of contact for resources for the department's operations in the cyber domain and will serve to synchronize cyber forces under a single manager. The commander will also ensure U.S. forces will be interoperable.

"This decision is a significant step in the department's continued efforts to build its cyber capabilities, enabling Cyber Command to provide real, meaningful capabilities as a command on par with the other geographic and functional combat commands," Rapuano said. 

Friday, June 16, 2017

Fort Meade To Celebrate 100 Years Of Secrecy, Cybersecurity And Military Innovation


I began doing security work for the U.S. Navy in 1970 while serving as a young sailor aboard the USS Kitty Hawk as the aircraft carrier was stationed on “Yankee Station” off the coast of Vietnam during the war.

Back then we joked that the ultra-secret NSA stood for “No Such Agency,” rather than the National Security Agency.

Some years later, while serving as the civilian administrative officer for a Defense Department command in Philadelphia, I oversaw and coordinated security programs for the command and I worked with and was trained by NSA. I visited NSA headquarters at Fort Meade and I was impressed with the professionalism and patriotism of NSA’s military and civilian employees.

NSA is far better known by the public today. 

As a writer, I recently attended former NSA director and retired Air Force General Michael Hayden’s talk at the Philadelphia World Affairs Council. Previous to the event, I read his book, Playing to the Edge: American Intelligence in the Age of Terror.

General Hayden (seen in the below photos), also a former CIA director, offered a frank and interesting discussion of modern intelligence work and spoke of how NSA responded to the 9/11 terrorist attack on the World Trade Center and the Pentagon.

I covered the event for Counterterrorism magazine and I’ll post the piece when it comes out

So with my interest in NSA, I was pleased to read Emma Ayers' Washington Times piece on the 100 year anniversary of Fort Meade, home to NSA and other commands.

The hub of U.S. cybersecurity, Fort George G. Meade in Anne Arundel County, Maryland, remains the game-changer in defense that it has been since its inception.

To celebrate, Fort Meade is hosting a public gala Saturday that will include a visual walk-through of its history.

“For 100 years, from saddles to cyberspace, Fort Meade has been the home to Doughboys and Hello Girls of World War One, Patton and Eisenhower as they established our first tank corps, the National Security Agency, and now: US CYBER Command,” Army Col. Tom Rickard, the fort’s garrison commander, said in a statement to The Washington Times. “Through the years, Fort Meade has always been a key installation for our national defense.”

It makes sense, then, that the 5,000-acre fort was named for the Union general who helped win the Battle of Gettysburg, which turned the tide of the Civil War.

Nestled along Interstate 295, the Army base has changed the tide of the Maryland job market. It is the state’s No. 1 employer, with 55,568 employees — nearly twice as many as the Pentagon. Some 138,000 people enter the base daily, and the average household income for the area is more than $84,000.

You can read the rest of the piece via the below link:





Monday, June 5, 2017

Government Contractor Arrested For Leaking Top-Secret NSA Documents On Russian Hacking


Chris Perez at the New York Post reports that a government contractor has been arrested and charges with leaking highly classified NSA information about Russian hacking.

A 25-year-old Federal contractor was charged Monday with leaking a top secret NSA report — detailing how Russian military hackers targeted US voting systems just days before the election.

The highly classified intelligence document, published Monday by The Intercept, describes how Russia managed to infiltrate America’s voting infrastructure using a spear-phishing email scheme that targeted local government officials and employees.

It claims the calculated cyberattack may have even been more far-reaching and devious than previously thought.

The report is believed to be the most detailed US government account of Russia’s interference to date.

It was allegedly provided to the Intercept by 25-year-old Reality Leigh Winner, of Augusta, who appeared in court Monday after being arrested at her home over the weekend.

You can read the rest of the piece via the below link:

Thursday, October 20, 2016

‘Not If, But When’: NSA Official Discusses Importance Of Cyber Vigilance


Amaani Lyle at the DoD News offers the below piece;

WASHINGTON, Oct. 20, 2016 — In the wake of major intrusions into U.S. government computer networks over the last 24 months, the National Security Agency's deputy national manager for national security systems outlined his agency’s role in developing cyber defense mitigations, and its critical response to public- and private-sector cyber incidents.

During his remarks Oct. 18 at the American Enterprise Institute, Curt Dukes (seen in the above photo) offered an inside look at NSA’s incident-response work, and described the agency’s way ahead in improving government cyber defense in the aftermath of intrusions at the Office of Personnel Management, State Department, DoD’s Joint Staff and two commercial companies that conducted background checks for the U.S. government.

“The adversary took advantage of poorly secured, poorly patched systems,” Dukes said. “Once they had that initial foothold, they elevated privileges and then moved to mission objective, which was exfiltration of personally identifiable information, exfiltration of intelligence, or in some cases, the actual destruction of the host.”

Raising Costs to Adversaries

With so much at stake, Dukes said U.S. vigilance of computer networks is vital, and ultimately needs to stack the odds against cyber attackers.

“[An adversary] could easily attack us [and] achieve mission objective … so I want to raise the cost to the adversary,” he said. “By the time we actually respond to an intrusion -- it takes hours to days -- by then, in cyber time, an adversary has already met their objective.”
Dukes explained typical cyberattack life cycles and various mitigations that he said will force adversaries to alter their intrusion methods, while helping industry to better prepare the U.S. government and military for those types of attacks at each step of the cycle.

As networks become increasingly interconnected, Dukes said, adversaries will find proportionately more exploitation opportunities. He maintains that it pays to invest in network defense.

“Look at what we currently spend in remediation for the [Office of Personnel Management] breach … if we had put just put one-tenth of that into good security at the very beginning, we’d have been much better prepared for any type of attack in that regard,” Dukes said of the 2015 intrusions that cost the government millions to address and impacted millions of current, former and prospective federal employees and contractors. “There’s an imbalance right now in what we spend on offense capabilities, and what we spend on defense.” 

Cyberattack Lifecycles

The cycle, Dukes explained, begins with an initial exploitation of open-source literature or the defense industrial base. When a vendor wins a contract, that information becomes publicly available and adversaries use a phishing attack, such as crafting emails that appear to come from a senior official.

“They want you to either click on that link or open that attachment,” he said, “and this creates a classic spear-phishing avenue that they’re going to continue to use until we actually remove that as a capability for them.”

Dukes also described “watering holes,” in which adversaries lead unsuspecting users to a site they’ve already corrupted. “From that point,” he said, “they can then put the initial install onto your device, and get access through a classic thumb drive or some type of media.”
And, while these vulnerabilities help cyber attackers gain access to very basic network levels, their next move is to establish persistence, Dukes explained.

“It gives them the ability to have multiple ingress and egress points,” once they establish a virus and assesses to a network and its connectivity, Dukes said. “So they’ve maybe found that host, but they’ve already moved to other hosts and to multiple ways in and out of the network.”

But entry points, he noted, are only part of the problem.

“Once they understand your system, if you’re not particularly well-patched or configured, then, they’re going to [seek] privileged escalation [and] they can then download tools … or hide inside normal traffic,” he added.

And that “normal traffic,” Dukes said, can include secure websites or encrypted web mail, which appears innocuous -- until it isn’t.

“Defense tools will not be able to protect you,” he said. “They basically ‘own’ you at that point in time.”

Dukes recounted the OPM intrusion had multiple ingress and egress points. “They had the initial attack,” he said, “then they moved laterally across it, and it became very difficult for network defenders to actually find them and eradicate them from that network.”

As a result, he said, NSA network defenders mapped an objective attack life cycle, consisting of phases including intelligence collection, intellectual property collection, and destructive programs such as ransomware.

“It doesn’t matter whether it’s a foreign nation such as Russia, China [or] Iran” Dukes said. “It could even be a terrorist organization. It could be a criminal network. They tend to follow the exact same life cycle in that regard.”

Life Cycle Mitigation Techniques

To mitigate the attacker’s life cycle, he said, NSA implemented anti-exploitation features in a Windows environment, which, along with a secure host baseline, is now core to the Windows 10 operating system. NSA also developed an application whitelist of known and trusted websites that can be refined over time, Dukes said.

Additionally, the Defense Department implements a host-based security or intrusion prevention system, for daily antivirus protection through assessing an adversary’s ability to attack, he said.

About five years ago, Dukes said, the antivirus industry changed technology by moving host reputation services to a cloud-based presence, allowing network defenders the ability to globally detect malware.

“Adversaries like to hide and fake who they actually are, so with reputation service, you can check what websites and [internet protocol] addresses map back to,” he said. “It’s a pretty impactful tool.”

Aside from antivirus protection, Dukes praised controlled administrative privileges.
“You want to limit the number of folks that actually have admin privileges on your network,” he said. “By doing that, you reduce the ability for an adversary to find that one weak host to take advantage of.”

Not If, But When

Dukes asserts that it’s not a matter of if an adversary will attack, but when, so he emphasized the value of network segregation and offline backup.

“By only allowing certain folks certain access to certain parts of the network, you limit the damage that the adversary can do on your network, and you limit their ability for them to achieve their mission in that regard,” Dukes said. “If something happens, have a backup copy of files whether daily, weekly, biweekly or monthly -- you have to be ready to reinstall should some unforeseen event occur.”

Overall, Dukes said, NSA has supported the Department of Homeland Security, Federal Bureau of Investigation and other agencies through requests for technical services to examine life cycles and host mitigation techniques that secure national security systems, and the same guidance applies to both commercial industry and home users.

“As a nation we have to rethink how we’re actually organized when we do cyber defense to protect the whole of the nation -- not only government, but also our key industry sectors,” Dukes said.”