7 July 2021

Russia-linked hackers reportedly breached RNC computer systems


Russia-linked hackers reportedly breached RNC computer systems

Hackers compromised the computer systems of the Republican National Commitee last week, around the same time the Florida-based software vendor Kaseya was hit by a REvil ransomware attack, Bloomberg reported, citing people familiar with the matter.

The attack was launched by a threat actor affiliated with the Russia-linked APT 29 (or Cozy Bear) hacking group, which previously was accused of breaching the Democratic National Committee in 2016 and of carrying out a supply chain cyberattack involving SolarWinds Corp that came to light in December last year.

It’s not clear if the hackers stole or viewed any data. The RNC has repeatedly denied that it was hacked. “There is no indication the RNC was hacked or any RNC information was stolen,” spokesman Mike Reed said.

In a statement Chief of Staff Richard Walters said the RNC learned over the weekend that a third-party provider Synnex Corp was hacked.

“We immediately blocked all access fr om Synnex accounts to our cloud environment,” he said. “Our team worked with Microsoft to conduct a review of our systems and after a thorough investigation, no RNC data was accessed. We will continue to work with Microsoft, as well as federal law enforcement officials, on this matter.”

The sources told Bloomberg that the hackers may have targeted the RNC through Synnex.

In a statement the California-based company has confirmed that it is “aware of a few instances wh ere outside actors have attempted to gain access, through SYNNEX, to customer applications within the Microsoft cloud environment. These actions could potentially be in connection with the recent cybersecurity attacks of Managed Service Providers, or MSPs.”

“While SYNNEX provides many services as part of its overall IT distribution business, including supporting Microsoft cloud applications, it is not an MSP in the context mentioned in recent media,” the company said.

Back to the list

Latest Posts

Black Basta-linked social engineering campaign bombards orgs with spam emails

Black Basta-linked social engineering campaign bombards orgs with spam emails

The threat actors escalate their attack by directly contacting affected users via phone calls.
14 May 2024
Google patches second Chrome zero-day in two weeks

Google patches second Chrome zero-day in two weeks

The tech giant didn’t reveal any additional details regarding the nature of the exploitation of the vulnerability.
14 May 2024
North Korean hackers steal sensitive data from South Korean court computer network

North Korean hackers steal sensitive data from South Korean court computer network

The threat actor had been breaking into the court's computer network since at least January 2021.
13 May 2024