Ex official says US blaming Iran hackers for Persian Gulf cyberattacks
American authorities firmly believe that Iranian hackers, likely supported by the Tehran government, were responsible for recent cyberattacks against oil and gas companies in the Persian Gulf and that they appeared to be in retaliation for the latest round of U.S. sanctions against the country, a former U.S. government official said, AP reported.
The former official spoke to The Associated Press shortly before Defense Secretary Leon Panetta, in a speech to business leaders in New York City Thursday night, became the first U.S. official to publicly acknowledge the computer-based assaults. He called them probably the most destructive cyberattacks the private sector has seen to date.
And while Panetta did not directly link Iran to the Gulf attacks, he made it clear that the U.S. has developed advanced techniques to identify cyberattackers and is prepared to take action against them.
A U.S. official said the Obama administration knows who launched the cyberattacks against the Gulf companies and that it was a government entity.
U.S. agencies have been assisting in the Gulf investigation and concluded that the level of resources needed to conduct the attack showed there was some degree of involvement by a nation state, said the former official. The officials spoke on condition of anonymity because the investigation is classified as secret.
"Potential aggressors should be aware that the United States has the capacity to locate them and hold them accountable for their actions that may try to harm America," Panetta said in a speech to the Business Executives for National Security. He later noted that Iran has "undertaken a concerted effort to use cyberspace to its advantage."
The cyberattacks hit Saudi Arabian state oil company Aramco and Qatari natural gas producer RasGas using a virus, known as "Shamoon", which can spread through networked computers and ultimately wipes out files by overwriting them.
Senior defense officials said the information was declassified so that Panetta could make the public remarks.
The officials added that the Pentagon is particularly concerned about the growing Iranian cyber capabilities, as well as the often discussed threats from China and Russia.
The two officials spoke on condition of anonymity because they were not authorized to discuss the cyberthreats publicly.
In his speech, Panetta said the "Shamoon" virus replaced crucial system files at Aramco with the image of a burning U.S. flag, and also overwrote all data on the machine, rendering more than 30,000 computers useless and forcing them to be replaced. He said the Qatar attack was similar.
Panetta offered no new details on the Pentagon's growing cyber capabilities or the military rules of engagement the department is developing to guide its use of computer-based attacks when the U.S. is threatened.
He said the department is investing more than $3 billion a year in cybersecurity to beef up its ability to defend against and counter cyberthreats, including investment in U.S. Cyber Command. And the Pentagon is honing its policies so that any actions comply with the law of armed conflict.
Panetta used the Persian Gulf attacks in his remarks as a warning to business community that it must embrace stalled legislation that would encourage companies to meet certain cybersecurity standards.
And he is endorsing a planned move by President Barack Obama to use his executive powers to put some of those programs, including voluntary standards, in place until Congress is able to act.
"These attacks mark a significant escalation of the cyber threat," Panetta said. "And they have renewed concerns about still more destructive scenarios that could unfold."
Edited by: S. Isayev