False Clues Make It Tough to Find WADA Hackers

Advertisement
By Associated Press | Updated: 16 September 2016 14:22 IST

Medical data from some of the world's leading athletes has been posted to the web and the World Anti-Doping Agency says Russians are to blame. Even the hackers seem to agree, adopting the name "Fancy Bears" - a moniker long associated with the Kremlin's electronic espionage operations.

But as cybersecurity experts pore over the hackers' digital trail, they're up against a familiar problem. The evidence has been packed with possible red herrings - including registry data pointing to France, Korean characters in the hackers' code and a server based in California.

Advertisement

(Also see: World Anti-Doping Agency Condemns Russian Hack Attack)

"Anybody can say they are anyone and it's hard to disprove," said Jeffrey Carr, the chief executive of consulting firm Taia Global and something of a professional skeptic when it comes to claims of state-backed hacking.

Advertisement

Many others in the cybersecurity industry see the WADA hack as a straightforward act of Russian revenge, but solid evidence is hard to find.

What's known is that it was only days after scores of Russian athletes were banned from the Olympic Games that suspicious looking emails began circulating . Purporting to come from WADA itself, the booby trapped messages were aimed at harvesting passwords to a sensitive database of drug information about athletes worldwide. Among other things, the Anti-Doping Administration and Management System carries information about which top athletes use otherwise-banned substances for medical reasons - prize information for a spurned Olympic competitor seeking to embarrass its rivals.

Advertisement

On September 1 someone registered a website titled "Fancy Bears' Hack Team." A few days later, a Twitter account materialized carrying a similar name. Just after midnight Moscow time on September 13, the Fancy Bears Twitter account came alive, broadcasting the drugs being taken by gold medal-winning gymnast Simone Biles, seven-time Grand Slam champion Venus Williams and other US Olympians. It followed up Thursday with similar information about the medication used by British cyclists Bradley Wiggins and Chris Froome, among many others.

(Also see: WADA Confirms Another Hacking of Its Athletes Database)

There is no suggestion any of the athletes broke any rules, but Russians seized on the leak as evidence that US and British players were using forbidden drugs with the blessing of anti-doping officials.

Advertisement

"Hypocrisy" Russia's embassy to London tweeted in reaction to the news. Kremlin channel RT broadcast a cartoon showing a WADA official picking up a bulky American player's steroid bottle with a smile. "All good! You're cleared to compete!" he says.

Citing law enforcement sources, WADA said the attacks "are originating out of Russia." Russian officials dismissed the allegation; in an email, WADA said it wouldn't be commenting further.

With little to go on, independent investigators have still made some intriguing connections.

Virginia-based intelligence firm ThreatConnect said that whoever compromised WADA did so using websites registered through an obscure domain name company that also set up the fake sites used in a variety of other hacks blamed on the Kremlin, including the one that hit the Democratic National Committee. In a telephone interview, the company's chief intelligence officer, Rich Barger said he had been cautious at first about tying the WADA breach to Russian hackers but that "confidence is certainly growing as more and more people weigh in and lend their voice."

Even the meaning of the name "Fancy Bears" is unclear. California-based threat intelligence firm CrowdStrike has long applied that nickname to an allegedly Russian state-backed group, but the hackers' adoption isn't necessarily a brazen acknowledgement of CrowdStrike's research. It might be an attempt to hold it up to ridicule. Which interpretation the group favors hasn't been made clear. Repeated messages to email addresses associated with Fancy Bears have gone unreturned.

Fancy Bears' website doesn't necessarily provide any more insight. Some its artistry appears to have been lifted from a Russian clip art page. But tech podcaster Vince Tocce also found Korean script in the site's code - characters which vanished shortly after he made his discovery public . In a telephone interview, he said that showed how difficult it was to take anything for granted.

Some pieces of Fancy Bears' infrastructure were almost certainly structured to sow confusion.

The site, for example, appears to be hosted in California but was registered at an address in the town of Pomponne, east of Paris, under the name "Jean Guillalime."

A man residing at that address, Jean-Francois Guillaume, told The Associated Press the registry information was bogus and that he was mystified as to why the hackers had picked on him.

"I have absolutely nothing to do with this," he said, adding that he ran a consulting shop and a flower business and wasn't particularly interested in sports. "I don't know any Russians," he said.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. New iPhone 18 Pro Leak Suggests It Could Arrive in These Battery Variants
  2. Google Drive's Document Scanner Gets Updated With These New Features
  3. AI Is Fundamentally Changing What Users Expect From PCs: AMD's Vinay Sinha
  4. Apple Brings New Wallpaper, Apple Music Playlist Ahead of WWDC 2026
  5. Itel Aqua Launched in India With IP67 Rating, 1,200mAh Battery: See Price
  6. Xiaomi's Phones Now Let You Share Files With iPhone Models via AirDrop
  7. Samsung Galaxy Fit 4 Could Debut Alongside Galaxy S26 FE
  8. Huawei Nova 16 Pro, Nova 16 Ultra Debut With 7,000mAh Battery: See Price
  9. Apple's First Foldable iPhone May Get White Colourway, VC Cooling
  1. Apple Releases New ‘Glow All Out’ Wallpaper, Apple Music Playlist Hinting at Next Week’s WWDC 2026 Theme
  2. Xiaomi's HyperOS 3 Adds AirDrop Support on Select Models With Ability to Share Files With Apple Devices
  3. iPhone 18 Pro Leak Hints at Two Battery Variants With Slightly Different Capacities
  4. Samsung Galaxy Fit 4 Launch Timeline Reportedly Leaked; May Debut Alongside Galaxy S26 FE
  5. iPhone Ultra Tipped to Launch in White Colourway; May Feature Vapour Chamber Cooling
  6. Asus ROG Edition 20 Lineup Unveiled at Computex 2026 to Commemorate 20 Years of ROG Series Products
  7. Indian Startup Pawzeeble Is Building a Pet-Focused Social Networking Space for Indian Users
  8. Asus ROG Strix Scar 18 (2026) With 240Hz 4K Mini-LED Display Showcased at Computex 2026
  9. Huawei Nova 16 Pro, Nova 16 Ultra Launched With Kirin 9010S SoC, 7,000mAh Battery: Price, Specifications
  10. Huawei Nova 16 Launched With 7,000mAh Battery, 50-Megapixel Camera, Nova 16z Tags Along: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.