Probe of Leaked NSA Hacking Tools Said to Focus on Operative's 'Mistake'

Advertisement
By Reuters | Updated: 23 September 2016 10:22 IST

A US investigation into a leak of hacking tools used by the National Security Agency is focusing on a theory that one of its operatives carelessly left them available on a remote computer and Russian hackers found them, four people with direct knowledge of the probe told Reuters.

The tools, which enable hackers to exploit software flaws in computer and communications systems from vendors such as Cisco Systems and Fortinet Inc, were dumped onto public websites last month by a group calling itself Shadow Brokers.

The public release of the tools coincided with US officials saying they had concluded that Russia or its proxies were responsible for hacking political party organizations in the run-up to the November 8 presidential election. On Thursday, lawmakers accused Russia of being responsible.

Advertisement

Various explanations have been floated by officials in Washington as to how the tools were stolen. Some feared it was the work of a leaker similar to former agency contractor Edward Snowden, while others suspected the Russians might have hacked into NSA headquarters in Fort Meade, Maryland.

Advertisement

But officials heading the FBI-led investigation now discount both of those scenarios, the people said in separate interviews.

NSA officials have told investigators that an employee or contractor made the mistake about three years ago during an operation that used the tools, the people said.

Advertisement

That person acknowledged the error shortly afterward, they said. But the NSA did not inform the companies of the danger when it first discovered the exposure of the tools, the sources said. Since the public release of the tools, the companies involved have issued patches in the systems to protect them.

Investigators have not ruled out the possibility that the former NSA person, who has since departed the agency for other reasons, left the tools exposed deliberately. Another possibility, two of the sources said, is that more than one person at the headquarters or a remote location made similar mistakes or compounded each other's missteps.

Advertisement

Representatives of the NSA, the Federal Bureau of Investigation and the office of the Director of National Intelligence all declined to comment.

After the discovery, the NSA tuned its sensors to detect use of any of the tools by other parties, especially foreign adversaries with strong cyber espionage operations, such as China and Russia.

That could have helped identify rival powers' hacking targets, potentially leading them to be defended better. It might also have allowed US officials to see deeper into rival hacking operations while enabling the NSA itself to continue using the tools for its own operations.

Because the sensors did not detect foreign spies or criminals using the tools on US or allied targets, the NSA did not feel obligated to immediately warn the US manufacturers, an official and one other person familiar with the matter said.

In this case, as in more commonplace discoveries of security flaws, US officials weigh what intelligence they could gather by keeping the flaws secret against the risk to US companies and individuals if adversaries find the same flaws.

Critics of the Obama administration's policies for making those decisions have cited the Shadow Brokers dump as evidence that the balance has tipped too far toward intelligence gathering.

The investigators have not determined conclusively that the Shadow Brokers group is affiliated with the Russian government, but that is the presumption, said one of the people familiar with the probe and a fifth person.

One reason for suspecting government instead of criminal involvement, officials said, is that the hackers revealed the NSA tools rather than immediately selling them.

The publication of the code, on the heels of leaks of emails by Democratic Party officials and preceding leaks of emails by former US Secretary of State Colin Powell, could be part of a pattern of spreading harmful and occasionally false information to further the Russian agenda, said Jim Lewis, a cyber security expert at the Center for Strategic and International Studies.

"The dumping is a tactic they've been developing for the last five years or so," Lewis said. "They try it, and if we don't respond they go a little further next time."

© Thomson Reuters 2016

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: NSA, Edward Snowden, FBI, Internet, Hacking
Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  2. Samsung Galaxy S25 FE With 50-Megapixel Camera Launched in India: See Price
  3. Oppo F31 Series Launched With 7,000mAh Battery: Check Price, Features
  4. iOS 26 Update for iPhone Releases Today: Everything You Need to Know
  5. Xiaomi 17 Pro Max Tipped to Come With a Secondary Display
  6. iOS 26 Releases Today: Check Out the Notable Features
  7. iPhone 18 Series to Feature a Smaller Dynamic Island, Tipster Claims
  8. Oppo Find X9 Launch Timeline Revealed: See Find X9 Pro Camera Samples
  9. Realme P3 Lite 5G With 6,000mAh Battery Launched in India at This Price
  1. Huawei Watch Ultimate 2 Design Renders Leaked, Could Launch Soon
  2. Marvel's Wolverine Will Reportedly Launch in 2026; Insomniac's Venom Game in 'Active Development'
  3. US President Donald Trump Challenges Block on Removing US Fed’s Lisa Cook
  4. iPhone 17 Series Outpaces iPhone 16 in Demand While iPhone 17 Pro Max Tops Pre-Orders, Analyst Says
  5. iPhone 16 Remained Top Selling Smartphone For Second Consecutive Quarter Globally: Report
  6. Samsung Galaxy S25 FE Launched in India With 6.7-Inch AMOLED Screen, 50-Megapixel Camera: Price, Features
  7. iPhone 18 Series Tipped to Feature Smaller Dynamic Island, Might Launch Without Under-Display Face ID
  8. OnePlus 15 Leaked Image Hints at Redesigned Camera Module, Three Colourways
  9. Xiaomi 17 Pro Max Leaked Image Reveals Rear Display in a Nod to the 11 Ultra Ahead of September Debut
  10. Treasure Hunters Season 1 Now Streaming on JioHotstar: Everything You Need to Know
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.