Nearly a decade ago, the United States began naming and shaming China for an onslaught of online espionage, the bulk of it conducted using low-level phishing emails against American companies for intellectual property theft.
On Monday, the United States again accused China of cyberattacks. But these attacks were highly aggressive, and they reveal that China has transformed into a far more sophisticated and mature digital adversary than the one that flummoxed U.S. officials a decade ago.
The Biden administration’s indictment for the cyberattacks, along with interviews with dozens of current and former American officials, shows that China has reorganized its hacking operations in the intervening years. While it once conducted relatively unsophisticated hacks of foreign companies, think tanks and government agencies, China is now perpetrating stealthy, decentralized digital assaults of American companies and interests around the world.
Hacks that were conducted via sloppily worded spearphishing emails by units of the People’s Liberation Army are now carried out by an elite satellite network of contractors at front companies and universities that work at the direction of China’s Ministry of State Security, according to U.S. officials and the indictment.
like Microsoft’s Exchange email service and Pulse VPN security devices, which are harder to defend against and allow China’s hackers to operate undetected for longer periods.
“What we’ve seen over the past two or three years is an upleveling” by China, said George Kurtz, the chief executive of the cybersecurity firm CrowdStrike. “They operate more like a professional intelligence service than the smash-and-grab operators we saw in the past.”
China has long been one of the biggest digital threats to the United States. In a 2009 classified National Intelligence Estimate, a document that represents the consensus of all 16 U.S. intelligence agencies, China and Russia topped the list of America’s online adversaries. But China was deemed the more immediate threat because of the volume of its industrial trade theft.
But that threat is even more troubling now because of China’s revamping of its hacking operations. Furthermore, the Biden administration has turned cyberattacks — including ransomware attacks — into a major diplomatic front with superpowers like Russia, and U.S. relations with China have steadily deteriorated over issues including trade and tech supremacy.
China’s prominence in hacking first came to the fore in 2010 with attacks on Google and RSA, the security company, and again in 2013 with a hack of The New York Times.
breach of the U.S. Office of Personnel Management. In that attack, Chinese hackers made off with sensitive personal information, including more than 20 million fingerprints, for Americans who had been granted a security clearance.
White House officials soon struck a deal that China would cease its hacking of American companies and interests for its industrial benefit. For 18 months during the Obama administration, security researchers and intelligence officials observed a notable drop in Chinese hacking.
After President Donald J. Trump took office and accelerated trade conflicts and other tensions with China, the hacking resumed. By 2018, U.S. intelligence officials had noted a shift: People’s Liberation Army hackers had stood down and been replaced by operatives working at the behest of the Ministry of State Security, which handles China’s intelligence, security and secret police.
Hacks of intellectual property, that benefited China’s economic plans, originated not from the P.L.A. but from a looser network of front companies and contractors, including engineers who worked for some of the country’s leading technology companies, according to intelligence officials and researchers.
It was unclear how exactly China worked with these loosely affiliated hackers. Some cybersecurity experts speculated that the engineers were paid cash to moonlight for the state, while others said those in the network had no choice but to do whatever the state asked. In 2013, a classified U.S. National Security Agency memo said, “The exact affiliation with Chinese government entities is not known, but their activities indicate a probable intelligence requirement feed from China’s Ministry of State Security.”
announced a new policy requiring Chinese security researchers to notify the state within two days when they found security holes, such as the “zero-days” that the country relied on in the breach of Microsoft Exchange systems.
arrested its founder. Two years later, Chinese police announced that they would start enforcing laws banning the “unauthorized disclosure” of vulnerabilities. That same year, Chinese hackers, who were a regular presence at big Western hacking conventions, stopped showing up, on state orders.
“If they continue to maintain this level of access, with the control that they have, their intelligence community is going to benefit,” Mr. Kurtz said of China. “It’s an arms race in cyber.”
On a recent Tuesday evening, Jully Lee and her boyfriend curled up on the couch and turned on the TV to watch the Ovation Awards, a ceremony honoring stage work in the Los Angeles area that was held virtually this year because of the coronavirus pandemic. Ms. Lee, an actor, had been nominated for her role in the play “Hannah and the Dread Gazebo,” which was in production before the pandemic.
Ms. Lee, 40, had submitted a prerecorded acceptance speech in case she won. During the ceremony, each nominee’s photo was shown as his or her name was announced. When Ms. Lee’s category arrived, her name was called, and a photo appeared on the screen. A photo of the wrong Asian: her colleague Monica Hong. The announcer also mispronounced Ms. Lee’s name.
“I was just stunned,” Ms. Lee said. She added that after a pause, she and her boyfriend started cracking up. “When things are awkward or uncomfortable or painful, it’s much safer to laugh than to express other emotions. It’s like a polite way of responding to things.”
A Rise in Anti-Asian Attacks
A torrent of hate and violence against people of Asian descent around the United States began last spring, in the early days of the coronavirus pandemic.
Background:Community leaders say the bigotry was fueled by President Donald J. Trump, who frequently used racist language like “Chinese virus” to refer to the coronavirus.
Data: The New York Times, using media reports from across the country to capture a sense of the rising tide of anti-Asian bias, found more than 110 episodes since March 2020 in which there was clear evidence of race-based hate.
Underreported Hate Crimes: The tally may be only a sliver of the violence and harassment given the general undercounting of hate crimes, but the broad survey captures the episodes of violence across the country that grew in number amid Mr. Trump’s comments.
In New York:A wave of xenophobia and violence has been compounded by the economic fallout of the pandemic, which has dealt a severe blow to New York’s Asian-American communities. Many community leaders say racist assaults are being overlooked by the authorities.
What Happened in Atlanta: Eight people, including six women of Asian descent, were killed in shootings at massage parlors in Atlanta on March 16. A Georgia prosecutor said that the Atlanta-area spa shootings were hate crimes, and that she would pursue the death penalty against the suspect, who has been charged with murder.
The LA Stage Alliance, which hosted the ceremony, disbanded in the wake of outrage over the blunder.
The irony of a mix-up like this wasn’t lost on Ms. Lee. It was rare to even be performing with other Asian actors, rather than competing for the same part. “It’s so funny because when there’s so many Asians, then you can’t tell them apart, but in media there are so few Asians that you can’t tell us apart,” she said. “What is it?”
The invisibility of Asians in pop culture is part of what, scholars say, contributes to the “wrong Asian” experience: When people aren’t accustomed to seeing Asian faces onstage or onscreen, they may have more trouble telling them apart in real life. To put it another way: If all you really have to work with are John Cho, Steven Yeun, Aziz Ansari and Kal Penn, that’s not going to go a long way in training you to distinguish among men of Asian descent offscreen. In contrast, Hollywood has given everyone plenty of training on distinguishing white faces, Dr. Nadal said.
Out of Hollywood’s top 100 movies of 2018, only two lead roles went to Asian and Asian American actors (one male and one female), according to a study by the University of Southern California’s Annenberg School for Communication and Journalism.
Donatella Galella, a professor of theater history and theory at the University of California, Riverside, said that popular culture has long reflected the Western world’s xenophobic views toward Asians, which resulted in placing them in diminished roles onstage and onscreen — the villain, the sidekick. That entrenched a kind of marginalization feedback loop.
CARACAS, Venezuela — From within his presidential palace, President Nicolás Maduro regularly commandeers the airwaves, delivering speeches intended to project stability to his crumbling nation.
But as the Venezuelan state disintegrates under the weight of Mr. Maduro’s corrupt leadership and American sanctions, his government is losing control of segments of the country, even within his stronghold: the capital, Caracas.
Nowhere is his weakening grip on territory more evident than in Cota 905, a shantytown that clings to a steep mountainside overlooking the gilded halls from which Mr. Maduro addresses the nation.
policing, road maintenance, health care and public utilities, to pour dwindling resources into Caracas, home of the political, business and military elites who form his support base.
Hunkered down in his fortified Caracas residences, Mr. Maduro crushed the opposition, purged the security forces of dissent and enriched his cronies in an effort to eliminate challenges to his authoritarian rule.
In remote areas, swathes of national territory fell to criminals and insurgents. But gang control of Cota 905 and the surrounding shantytowns, which lie just two miles from the presidential palace, is evidence that his government is losing its grip even on the center of the capital.
Across the city, other armed groups have also asserted territorial control over working-class neighborhoods.
“Maduro is often seen as a traditional strongman controlling every aspect of Venezuelans’ lives,” said Rebecca Hanson, a sociologist at the University of Florida who studies violence in Venezuela. “In reality, the state has become very fragmented, very chaotic and in many areas very weak.”
As the government’s reach in Caracas’s shantytowns withered, organized crime grew, forcing Mr. Maduro’s officials to negotiate with the largest gangs to limit violence and maintain political control, according to interviews with a dozen residents, as well as police officers, officials and academics studying violence.
In the process, the most organized gangs began supplanting the state in their communities, taking over policing, social services and even the enforcement of pandemic measures.
Police officers say the gang that controls Cota 905 now has around 400 men armed with the proceeds from drug trafficking, kidnapping and extortion, and that it exerts complete control over at least eight square miles in the heart of the capital.
Gang members with automatic weapons openly patrol the shantytown’s streets and those of the surrounding communities, and guard entry points from rooftop watchtowers. The first checkpoint appears just a few minutes’ drive from the headquarters of Mr. Maduro’s secret police.
As the Venezuelan economy went into a tailspin, the Cota gang began offering financial support to the community, supplanting Mr. Maduro’s bankrupt social programs, which once offered free food, housing and school supplies for the poor.
After monopolizing the local drug trade, the Cota 905 gang imposed strict rules on the residents in return for stopping the once endemic violence and petty crime. And many residents welcome its hard line on crime.
“Before, the thugs robbed,” said Mr. Ojeda, a Cota 905 resident who, like others in the community, asked that his full name not be published for fear of crossing the gangsters. “Now, they are the ones who come to you, without fail, with anything that goes missing.”
During his tenure, Mr. Maduro has veered from brutal suppression of organized crime groups to accommodation in an attempt to check rising crime.
In 2013, he withdrew security forces from about a dozen troubled spots, including Cota 905, naming them “Peace Zones,” as he tried to placate the gangs. Two years later, when the policy failed to check crime, he unleashed a wave of brutal police assaults on the shantytowns.
The police operations resulted in thousands of extrajudicial killings, according to the United Nations, earning Mr. Maduro charges of committing crimes against humanity and the hatred of many shantytown residents. Faced with the onslaught, the gangs closed ranks, creating ever larger and more complex organizations, according to Ms. Hanson and her colleague, the researcher Verónica Zubillaga.
Unable to defeat the Cota gang, Mr. Maduro’s government returned to negotiations with its leaders, according to a police commander and two government officials who held talks with the gang and worked to put the agreements in place.
Security forces are once again banned from entering the community, according to the police commander, who is not authorized to discuss state policy and did so on condition of anonymity.
Under the deal with the government, the Cota gang has reduced kidnappings and murders, and began carrying out some state policies. During the pandemic, gang members strictly enforced lockdown rules and mask wearing, local residents said. And the gang is working with the government to distribute the scant remaining food and school supplies to the residents, residents and the two officials said.
“The gang is focused on the community,” said Antonio Garcia, a shantytown resident. “They make sure we get our bag of food.”
Mr. Ojeda said he received $300 from the gang the last Carnival season to buy toys and sweets for his family, a fortune in a country where the minimum monthly wage has collapsed to about $2. Residents said young people in the community are offered jobs as lookouts or safe house guards for between $50 and $100 a week, more than most doctors and engineers make in Venezuela.
Taking these jobs is easier than leaving them. Soon after the oldest son of Ms. Ramírez — who did not want to give her full name out of fear of the gang — began serving as a lookout in Cota 905, he discovered that his life now belonged to the gang.
“He had new clothes, new shoes, but he couldn’t stop crying,” Ms. Ramírez said. “He wanted to go back and couldn’t.”
Anti-government protests are banned in the shantytown, and gang members summon residents to the polling stations on elections, said the residents.
The members “tell us that if the government is toppled, we would be affected too, because the police would return,” said Ana Castro, a Cota resident. “The ‘Peace Zone’ would end, and we would all suffer.”
In private, some government officials defend the nonaggression pacts with the biggest gangs, saying the policy has drastically reduced violence.
Violent deaths in Caracas shantytowns have halved since the mid-2010s, when the Venezuelan capital was one of the world’s deadliest cities, according to figures from a local nonprofit, Mi Convive.
But academics and analysts studying crime in the city say the drop in homicides points to the growing power of Caracas’s gangs against an increasingly weak government. The imbalance, experts said, puts the government and the population in an increasingly dangerous and vulnerable position.
The power shift was evident in April, when the Cota gang shot up a police patrol car and took over a section of highway running through Caracas. The area was a five-minute drive from the presidential palace, and the blockade paralyzed the capital for several hours.
But the government stayed silent through it all. The security forces never came to retake the highway. Once the gang left, officers quietly cleared out the blasted patrol car.
JERUSALEM — More than 1,550 people have been arrested over the past two weeks, the Israeli police said on Monday, on suspicion of involvement in the recent outbreak of mob violence between Arabs and Jews that convulsed cities across Israel.
Announcing the start of an even more concerted arrest campaign, the police said in a statement that thousands of police and border police officers had spread out across the country “to bring the rioters, criminals and all those involved in the disturbances to justice.”
Micky Rosenfeld, a spokesman for the police, said that 70 percent of those arrested were Arab citizens of Israel while 30 percent were Jewish. About 150 suspects have already been charged, the police said.
“The majority of incidents that took place were carried out by Arab Israelis who took to the streets and attacked Jewish civilians and police officers,” he said.
the worst intercommunal violence Israel has seen in decades, the outburst of assaults, arson and vandalism spread to other mixed cities in northern Israel and the Arab towns of the Galilee, while Bedouin Arabs torched and ambushed Jews’ cars with stones on the roads in the southern Negev desert.
Over several nights, Arab and Jewish gangs sought out targets. Several victims on both sides were beaten unconscious; one Jewish man was badly burned; and at times the unrest turned lethal.
looming eviction of six Palestinian families from homes claimed by Jewish landlords has contributed to the unrest, and where the police continue to disperse sporadic protests.
The police have come in for harsh criticism from both Jewish and Arab witnesses and victims of the mob violence. Many said they had tried to call the police as their properties came under attack during the disturbances but got no response.
Mr. Rosenfeld said that at that time too many incidents were occurring simultaneously and that it was impossible to place an officer by every door.
The government called in hundreds of border police officers from the occupied West Bank to restore order in Lod.
When crime involved only Arab citizens, as both perpetrators and victims, the police showed little interest, said Ms. Touma-Sliman, the lawmaker, adding, “we’ve been pleading for years for them to take action.”
Only now, she said, when the violence affected the Jewish population, were the police talking about gathering video footage from security cameras and using other technological means to locate and identify suspects.
“I have lost confidence in the police,” she said. “They will have to earn it.”
On Monday alone, the police said, they had arrested 74 suspects, including dozens who had thrown stones, fireworks and firebombs and assaulted officers in Jerusalem and Arab-populated areas of central Israel. They said they had also seized illegal weapons, including an M16 assault rifle, and ammunition.
Three Israeli Jews, including a minor, 16, were charged on Monday for what the prosecution called the “attempted terrorist murder” of an Arab Israeli driver in Bat Yam, a Tel Aviv suburb. He was dragged from his car and beaten almost to death at the height of the intercommunal violence.
BRUSSELS — A diplomatic flurry from the White House and Europe added pressure on Israel and Palestinian militants in Gaza on Wednesday to halt their 10-day-old conflict before it turned into a war entangling more of the Middle East.
President Biden spoke with Prime Minister Benjamin Netanyahu of Israel — their second phone call in three days — telling the Israeli leader he “expected a significant de-escalation today on the path to a cease-fire,” administration officials said. Although they portrayed the call as consistent with what Mr. Biden had been saying, his decision to set a deadline was an escalation.
And in Europe, France and Germany, both strong allies of Israel that had initially held back from pressuring Mr. Netanyahu in the early days of the conflict, intensified their push for a cease-fire.
French diplomats sought to advance their proposed United Nations Security Council resolution that would call on the antagonists to stop fighting and to allow unfettered humanitarian access to Gaza. It remained unclear on Wednesday if the United States, which has blocked all Security Council attempts to even issue a statement condemning the violence, would go along with the French resolution.
Twitter post afterward, he said, “I especially appreciate the support of our friend @POTUS Joe Biden, for the State of Israel’s right to self-defense.”
confronted Mr. Biden during his trip to a Ford plant, and pleaded with him to address the growing violence in the region and protect Palestinian lives.
Representative Debbie Dingell of Michigan, who witnessed that interaction, said in an interview on Wednesday that Mr. Netanyahu’s reluctance to negotiate a cease-fire had made it harder for Democrats across the political spectrum to defend Israel’s actions.
Some saw the second phone call between Mr. Biden and Mr. Netanyahu as messaging to placate domestic constituents.
Democrats have been pushing Mr. Biden “to take a tougher line and this was his opportunity to demonstrate that he is doing so,” said Jonathan Schanzer, senior vice president for research at the Foundation for Defense of Democracies, a Washington group that supports Mr. Netanyahu’s policies. He also said Mr. Netanyahu “does not want to give the impression that he’s been told to end this conflict before it’s the right time to do so.”
For European nations, the intensified push for a cease-fire also is based partly on political calculations.
pro-Palestinian demonstrations have sometimes turned into anti-Israeli protests and anti-Semitic attacks, including assaults on synagogues. Governments fear such protests and internal violence will worsen the longer the conflict lasts.
France is on alert for acts of Islamist terrorism, often from French-born Muslims outraged by events in the Middle East. Germany, which welcomed a million mostly Muslim migrants in 2015, is struggling to contain their anger about Israel.
At the same time, the election of Mr. Trump in 2016 also encouraged a right-wing European populism that is anti-immigration and often anti-Islamic, with a clear political identification with “Judeo-Christian values” and strong support for Israel. That is clear in France, with the far-right party of Marine Le Pen, as well as in Germany, with the far-right Alternative for Germany party.
Hugh Lovatt, a policy fellow at the European Council on Foreign Relations.
Up until now at least, there also had been a gradual de-emphasis of the Palestinian issue by governments, said Kristina Kausch, a senior fellow at the German Marshall Fund.
The Israeli-Palestinian Conflict
She attributed that de-emphasis partly to Israel’s shelved plans to annex the occupied West Bank, which Palestinians want as part of their own ambitions for an independent state, and to the 2020 Abraham Accords, Israel’s normalization of ties with the United Arab Emirates, Bahrain and Sudan, all big defenders of Palestinian rights. Ms. Kausch said there had been a sense that “the Palestinian cause can be put on the back burner, that Arab countries and people don’t care anymore.”
But this new outbreak, Ms. Kausch said, hadshown “that the Palestinian cause is alive and kicking.” And no longer ignorable, at least for a while.
Julien Barnes-Dacey, director of the Middle East and North Africa program for the European Council on Foreign Relations.
At the beginning of this conflict, he said, the United States and Europe had been“largely sympathetic to the Israeli narrative, willing to give them some space to accomplish their military ambitions.”
similar two-page resolution passed by the Security Council during another fierce Gaza war in January 2009, and on which the United States abstained.
The draft resolution seeks a cessation of hostilities, humanitarian access to Gaza, the condemnation of the rocket barrages and any incitement to violence, the official said.
In Germany, traditional support for Israel and patience with its military campaign appears to be waning.
After speaking with Mr. Netanyahu on Monday, Chancellor Angela Merkel “sharply condemned the continued rocket attacks from Gaza on Israel and assured the prime minister of the German government’s solidarity,” said her spokesman, Steffen Seibert.
But given the many civilian lives lost “on both sides,” Mr. Seibert said, “the chancellor expressed her hope that the fighting will end as soon as possible.”
Mr. Maas, the German foreign minister, said on Tuesday that “ending the violence in the Middle East is the first priority,” followed by political negotiations. But he also blamed Hamas for the escalation.
He appeared to be responding to domestic criticism that the government has been too lenient in the face of pro-Palestinian and sometimes anti-Semitic protests.
The conservative Frankfurter Allgemeine Zeitung commented that Germany should “concentrate on internal affairs and reflect that the ‘welcome culture’ extended to refugees was astoundingly naïve when it came to anti-Semitism.”
The question for Germany now, the paper said, “is how do we teach those for whom a hatred of Israel is in their DNA that Israel’s security is part of their adopted homeland’s raison d’être?”
Steven Erlanger reported from Brussels, and Jim Tankersley and Katie Rogers from Washington. Michael Crowley contributed reporting from Washington.
When the history of this global moment is written, there will need to be an entire chapter on police forces’ spectacular own goals as force for change.
Around the world, the police have cracked down violently on protests — only to discover that their attacks, captured on camera and shared across social and conventional media, have been the catalyst that helped turn issue-based campaigns into mass movements.
Movements like Black Lives Matter in the United States, the 2019 uprising in Chile that led to a new constitution, and, now, Colombia’s protests grew out of political wounds unique to each society. But each was transformed into a broad, potentially generation-defining cause once protesters were confronted with police violence.
shaped the culture and training of Colombian police, who amid the protests have often appeared to draw little distinction between peaceful protesters who object to the government’s policies and violent guerrillas who wanted to overthrow the state.
In Chile in 2019, protests initially began as opposition to an increase in transit fares. It was the government’s fateful decision to restore order by calling out the army — for the first time since Gen. Augusto Pinochet’s military dictatorship ended in 1990 — that transformed the protests into a national movement with widespread political support.
Army tanks rolling through the streets sent a message that the country’s transition to democracy was incomplete, and at risk of collapse. Protesters carried placards printed with the face of Victor Jara, a folk singer murdered in the early days of the Pinochet regime, drawing a direct connection between the modern protests and the tanks that brought General Pinochet to power.
Just a year after the protests exploded, Chileans voted to scrap the constitution drafted during the Pinochet years and replace it with a new one.
‘This is not the country we want’
In Colombia, the violence against protesters, and the heavy militarization of the streets in cities like Bogotá, has likewise sent a message that the country’s democratic project is not just unfinished, but is perhaps in jeopardy.
The 2016 peace agreement was supposed to end the armed conflict between the government and the FARC. But the actions of the state security forces over the past two weeks have many questioning whether peacetime democracy ever began at all.
“I think that the story of this country is about the armed conflict,” said Erika Rodríguez Gómez, 30, a lawyer and feminist activist from Bogotá. “We signed a peace agreement in 2016. And maybe at that moment we felt like, OK, we are going to move on.”
“But actually we have all of the military forces on the streets. And we have these attacks against us, the civil society,” she said. “So we think now that actually, they were never gone.”
It is too soon to say whether the protests will lead to lasting change. The attacks on protesters have made state violence visible to more people, said Dr. González, the Harvard researcher, but she believes that they are still considering it through the lens of “their usual scripts about understanding society, and understanding the police, and understanding everything. So it hasn’t quite come to the point of people converging.”
But Leydy Diossa-Jimenez, a Colombian researcher and Ph.D. candidate in sociology at the University of California, Los Angeles, said that she sees this moment as a turning point for change across generations. “Gen Z, they are now rethinking their country, and thinking about what has been left by prior generations,” she said in an interview. “They are saying ‘No, this is not what we want.’ ”
“And I think for the first time now, the older generations in Colombia are allying with that idea, that this is not the country we want,” she said.
“I don’t know if the politicians are up to the challenge, and up to the historical moment,” she added. “I just hope they are.”
BRUSSELS — European Union foreign ministers overwhelmingly called for an immediate cease-fire between Israel and the Palestinians in an emergency meeting on Tuesday, according to the bloc’s foreign policy chief, Josep Borrell Fontelles.
All of the member states except Hungary backed a statement that condemned rocket attacks by Hamas and supported Israel’s right to self-defense but also cautioned that it had “to be done in a proportional manner and respecting international humanitarian law,’’ Mr. Borrell said at a news conference.
He said that the number of civilian casualties in Gaza, “including a high number of women and children,’’ was “unacceptable.’’ And he said that the European Union, as part of the quartet with the United States, Russia and the United Nations that seeks peace in the Middle East, would push to restart a serious diplomatic process.
“The priority is the immediate cessation of all violence and the implementation of a cease-fire,” Mr. Borrell said. Foreign policy in the European Union works by unanimity, so Mr. Borrell’s comments, despite Hungary’s opposition, were an effort, he said, “to reflect the overall agreement.”
evictions of Palestinians from East Jerusalem.
“The representatives of the European public, the ministers of foreign affairs in this case, are trying very hard to deal with the situation and find the best possible contribution by the E.U. to de-escalate and stop the violence,” he said. “And I think that’s it. I can only repeat that of course the casualties are unacceptable.”
Isabel Kershner contributed reporting from Jerusalem.
For years, government officials and industry executives have run elaborate simulations of a targeted cyberattack on the power grid or gas pipelines in the United States, imagining how the country would respond.
But when the real, this-is-not-a-drill moment arrived, it didn’t look anything like the war games.
The attacker was not a terror group or a hostile state like Russia, China or Iran, as had been assumed in the simulations. It was a criminal extortion ring. The goal was not to disrupt the economy by taking a pipeline offline but to hold corporate data for ransom.
The most visible effects — long lines of nervous motorists at gas stations — stemmed not from a government response but from a decision by the victim, Colonial Pipeline, which controls nearly half the gasoline, jet fuel and diesel flowing along the East Coast, to turn off the spigot. It did so out of concern that the malware that had infected its back-office functions could make it difficult to bill for fuel delivered along the pipeline or even spread into the pipeline’s operating system.
What happened next was a vivid example of the difference between tabletop simulations and the cascade of consequences that can follow even a relatively unsophisticated attack. The aftereffects of the episode are still playing out, but some of the lessons are already clear, and demonstrate how far the government and private industry have to go in preventing and dealing with cyberattacks and in creating rapid backup systems for when critical infrastructure goes down.
nearly $5 million in digital currency to recover its data, the company found that the process of decrypting its data and turning the pipeline back on again was agonizingly slow, meaning it will still be days before the East Coast gets back to normal.
seeks to mandate changes in cybersecurity.
And he suggested that he was willing to take steps that the Obama administration hesitated to take during the 2016 election hacks — direct action to strike back at the attackers.
“We’re also going to pursue a measure to disrupt their ability to operate,” Mr. Biden said, a line that seemed to hint that United States Cyber Command, the military’s cyberwarfare force, was being authorized to kick DarkSide off line, much as it did to another ransomware group in the fall ahead of the presidential election.
Hours later, the group’s internet sites went dark. By early Friday, DarkSide, and several other ransomware groups, including Babuk, which has hacked Washington D.C.’s police department, announced they were getting out of the game.
Darkside alluded to disruptive action by an unspecified law enforcement agency, though it was not clear if that was the result of U.S. action or pressure from Russia ahead of Mr. Biden’s expected summit with President Vladimir V. Putin. And going quiet might simply have reflected a decision by the ransomware gang to frustrate retaliation efforts by shutting down its operations, perhaps temporarily.
The Pentagon’s Cyber Command referred questions to the National Security Council, which declined to comment.
The episode underscored the emergence of a new “blended threat,” one that may come from cybercriminals, but is often tolerated, and sometimes encouraged, by a nation that sees the attacks as serving its interests.That is why Mr. Biden singled out Russia — not as the culprit, but as the nation that harbors more ransomware groups than any other country.
“We do not believe the Russian government was involved in this attack, but we do have strong reason to believe the criminals who did this attack are living in Russia,” Mr. Biden said. “We have been in direct communication with Moscow about the imperative for responsible countries to take action against these ransomware networks.”
With Darkside’s systems down, it is unclear how Mr. Biden’s administration would retaliate further, beyond possible indictments and sanctions, which have not deterred Russian cybercriminals before. Striking back with a cyberattack also carries its own risks of escalation.
The administration also has to reckon with the fact that so much of America’s critical infrastructure is owned and operated by the private sector and remains ripe for attack.
“This attack has exposed just how poor our resilience is,” said Kiersten E. Todt, the managing director of the nonprofit Cyber Readiness Institute. “We are overthinking the threat, when we’re still not doing the bare basics to secure our critical infrastructure.”
The good news, some officials said, was that Americans got a wake-up call. Congress came face-to-face with the reality that the federal government lacks the authority to require the companies that control more than 80 percent of the nation’s critical infrastructure adopt minimal levels of cybersecurity.
The bad news, they said, was that American adversaries — not only superpowers but terrorists and cybercriminals — learned just how little it takes to incite chaos across a large part of the country, even if they do not break into the core of the electric grid, or the operational control systems that move gasoline, water and propane around the country.
Something as basic as a well-designed ransomware attack may easily do the trick, while offering plausible deniability to states like Russia, China and Iran that often tap outsiders for sensitive cyberoperations.
It remains a mystery how Darkside first broke into Colonial’s business network. The privately held company has said virtually nothing about how the attack unfolded, at least in public. It waited four days before having any substantive discussions with the administration, an eternity during a cyberattack.
Cybersecurity experts also note that Colonial Pipeline would never have had to shut down its pipeline if it had more confidence in the separation between its business network and pipeline operations.
“There should absolutely be separation between data management and the actual operational technology,” Ms. Todt said. “Not doing the basics is frankly inexcusable for a company that carries 45 percent of gas to the East Coast.”
Other pipeline operators in the United States deploy advanced firewalls between their data and their operations that only allow data to flow one direction, out of the pipeline, and would prevent a ransomware attack from spreading in.
Colonial Pipeline has not said whether it deployed that level of security on its pipeline. Industry analysts say many critical infrastructure operators say installing such unidirectional gateways along a 5,500-mile pipeline can be complicated or prohibitively expensive. Others say the cost to deploy those safeguards are still cheaper than the losses from potential downtime.
Deterring ransomware criminals, which have been growing in number and brazenness over the past few years, will certainly be more difficult than deterring nations. But this week made the urgency clear.
“It’s all fun and games when we are stealing each other’s money,” said Sue Gordon, a former principal deputy director of national intelligence, and a longtime C.I.A. analyst with a specialty in cyberissues, said at a conference held by The Cipher Brief, an online intelligence newsletter. “When we are messing with a society’s ability to operate, we can’t tolerate it.”
JERUSALEM — Hundreds were injured as clashes between Israeli police and Palestinian protesters broke out Monday morning at the Aqsa mosque compound in Jerusalem, a site sacred to both Muslims and Jews, after a week of rising tension in the city. Police fired rubber-tipped bullets and stun grenades at stone-throwing Palestinians who had stockpiled stones at the site in expectation of a standoff with Jewish far-right groups.
By midmorning, more than 50 people had been transferred to the hospital, according to a representative of the Palestinian Red Crescent. One person was hit in the head by a bullet and was in a critical condition, the medical aid group said. Nine police officers were injured, a police spokesman said.
Videos posted on Twitter showed chaos both outside and inside the mosque, where some worshipers could be seen sheltering from explosions while others threw stones and set off fireworks. In another clip, police officers were seen striking a man being detained in part of the mosque compound.
Another video released by the police showed young men throwing stones from the perimeter of the mosque compound onto the land below. A separate clip, taken by a surveillance camera, appeared to show a Jewish man driving into a passer-by after stones hit his car.
Jerusalem Day is always fraught. But the atmosphere was especially febrile on Monday because the confrontations followed weeks of escalating tensions in the city, where restrictions on Palestinian access to the Old City during the holy month of Ramadan, a far-right march through the city center in April, and street assaults by both Jews and Arabs have all contributed to a feverish atmosphere.
the looming expulsion of several Palestinian families from their homes in Sheikh Jarrah, East Jerusalem. For Palestinians and their advocates, the case has become a stand-in for the wider campaign to force out Palestinians from parts of East Jerusalem and for their past displacement in the occupied territories and within Israel.
Tensions escalated again Friday night, as the police fired rubber-tipped bullets and stun grenades and Palestinians threw stones following prayers at the Aqsa compound. Video showed some grenades landing inside the mosque.
Militants in Gaza fired rockets into Israel overnight Sunday, after sending incendiary balloons into Israeli farmland for the past several days. Israel has returned fire, barred fishermen from the territory from accessing the sea and shut a key crossing between Gaza and Israel — but avoided a major escalation.
was postponed on Sunday, in part to diffuse these rising tensions. The Israeli police also made a last-minute decision Monday morning to block Jews from accessing the Aqsa compound, known to Jews as the Temple Mount and to Muslims as the Noble Sanctuary.
The Palestinian Authority recently canceled what would have been the first Palestinian elections in 15 years.
And after a fourth Israeli election in just two years, Israeli opposition parties are locked in negotiations to form a coalition government and replace Benjamin Netanyahu, the country’s prime minister. Mr. Netanyahu is serving in a caretaker capacity as he stands trial on corruption charges.
Myra Noveck contributed reporting from Jerusalem and Iyad Abuheweila from Gaza City.
President Biden, declaring that the United States had long ago accomplished its mission of denying terrorists a safe haven in Afghanistan, announced April 14 that all American troops would leave the country by Sept. 11.
A combat mission that has dogged four presidents — who reckoned with American casualties, a ruthless enemy and an often corrupt and confounding Afghan government partner — will at last come to an end.
Mr. Biden conceded that after nearly 20 years of war, America’s longest on foreign soil, it was clear that the U.S. military could not transform Afghanistan into a modern, stable democracy.
President George W. Bush announced that American forces had launched attacks against the terrorist group and Taliban targets in Afghanistan.
an end to major combat operations in the country.
stolen or misappropriated. The government proved unable to meet the most basic needs of its citizens. Often, its writ barely extended beyond the capital, Kabul, and other major cities.
In 2003, with 8,000 American troops in Afghanistan, the United States began shifting combat resources to the war in Iraq, launched in March of that year.
deployed thousands more troops to Afghanistan as part of a “surge,” reaching nearly 100,000 by mid-2010. But the Taliban only grew stronger, inflicting heavy casualties on Afghan security forces despite American combat power and airstrikes.
killed Osama bin Laden in a compound in Abbottabad, Pakistan, where he had been living for years near a Pakistan military training academy. In June, Mr. Obama announced that he would start bringing American forces home and hand over responsibility for security to the Afghans by 2014.
By then, the Pentagon had concluded that the war could not be won militarily and that only a negotiated settlement could end the conflict — the third in three centuries involving a world power. Afghan fighters defeated the British army in the 19th century and the Russian military in the 20th century.
With the war at a stalemate, Mr. Obama ended major combat operations on Dec. 31, 2014, and transitioned to training and assisting Afghan security forces.
Nearly three years later, President Donald J. Trump said that although his first instinct had been to withdraw all troops, he would nonetheless continue to prosecute the war. He stressed that any troop withdrawal would be based on combat conditions, not predetermined timelines.
But the Trump administration also had been talking to the Taliban since 2018, leading to formal negotiations that excluded the Afghan government, led by President Ashraf Ghani.
an agreement with the Taliban that called for all American forces to leave Afghanistan by May 1, 2021. In return, the Taliban pledged to cut ties with terrorist groups such as Al Qaeda and the Islamic State affiliate in Afghanistan, reduce violence and negotiate with the American-backed Afghan government.
release 5,500 Taliban prisoners while receiving little in return, further alienating the Afghan government.
After the deal was signed, the Taliban stopped attacking American troops and refrained from major terrorist bombings in Afghan cities. The United States reduced air support for government forces, generally restricting them to instances in which Afghan troops were in danger of being overrun.
The primary objectives of the 2020 deal were for Afghan leaders and the Taliban to negotiate a political road map for a new government and constitution, reduce violence and ultimately forge a lasting cease-fire.
But the government accused the Taliban of assassinating Afghan government officials and security force members, civil society advocates, journalists and human rights workers — including several women shot in broad daylight.
Because of their strong battlefield position and the imminent U.S. troop withdrawal, the Taliban have maintained the upper hand in talks with the Afghan government, which began in September in Doha, Qatar, but have since stalled. The Pentagon has said the militants have not honored pledges to reduce violence or cut ties with terrorist groups.
After Mr. Biden announced in April the U.S. withdrawal of American forces, NATO said its 7,000 troops in Afghanistan would coordinate their withdrawal with the United States.
The Biden administration says it continues to support peace talks, but the Taliban appear in no hurry to negotiate. Nor have they explicitly said they would agree to a power-sharing government, implying instead that they intend to seek a monopoly on power.
impose tolls and taxes on truckers and motorists, providing official receipts valid anywhere in the country. The militants also have set up checkpoints on the outskirts of major cities, raising fears that they will attempt to wrest control of cities from the government after international forces depart.
The United States has spent at least $4 billion a year on the Afghan military — $74 billion since the start of the war. The Biden administration has pledged to continue supporting Afghan forces after American troops depart.
A classified intelligence assessment presented to the Biden administration this spring said Afghanistan could fall largely under Taliban control within two to three years after the departure of international forces.
And the Taliban have given no indication they will abandon their annual spring offensive, when they typically ratchet up combat operations with the arrival of warmer weather.
“The Taliban is confident it can achieve military victory,” the threat assessment concluded.
The report added: “The Taliban is likely to make gains on the battlefield, and the Afghan government will struggle to hold the Taliban at bay if the coalition withdraws support.”