The Joint Staff’s unclassified networks remain down nearly two weeks after a reported phishing attempt compromised the organization’s email systems, and some fingers are pointing to a group of busy Russia-linked hackers.
The cybersecurity incident appears to have come through the Joint Staff’s unclassified email network via spear-phishing sometime around July 25. The perpetrators may be the same Russian hackers who broke into White House and State Department networks earlier this year, according to published reports.
The Pentagon isn’t saying who they suspect to be behind the attacks, but Defense Department officials say they have kept the network offline while they work to resolve the problems.
“Joint Staff unclassified networks for all users are currently down. We continue to identify and mitigate cybersecurity risks across our networks,” Lt. Col. Valerie Henderson, DoD spokeswoman, said in a statement. “With those goals in mind, we have taken the Joint Staff network down and continue to investigate. Our top priority is to restore services as quickly as possible. As a matter of policy and for operational security reasons, we do not comment on the details of cyber incidents or attacks against our networks.”
In an Aug. 7 debate between potential Republican presidential nominees, Sen. Ted Cruz (R-Texas) raised the question of whether the attack was linked to behind-the-scenes meetings between a high-level Iranian army official and Russian leaders in Moscow. The meetings coincide with ongoing debate in Congress over a U.S. nuclear weapons deal with Iran.
According to Cruz, the day that Qassem Soleimani, a major general in the Iranian army, returned from Moscow “was the day we believe Russia used cyber warfare against the Joint Chiefs,” he said when asked about the cyberattack.
The Russian hackers reportedly behind the White House and State Department breaches also reportedly compromised Pentagon networks last month. Additionally, they appear to be targeting more than just government agencies. Last month at least one reporter at C4ISR & Networks’ sister publication, Federal Times, also was targeted in a spear-phishing campaign linked to the same group.
It is not known when the Joint Staff’s unclassified network may be up and running again.




