Feeds

Don't let hackers know Mandiant founder checks his email on an iPad. Oh.

Mandia prefers face-to-face natter to avoid piles of spyware booby-traps

Boost IT visibility and business value

Infosec 2014 Mandiant boss Kevin Mandia says he has cut back on email and only uses an iPad to check his inbox as he fends off counterattacks from hackers.

In 2013, the company published a landmark report on the so-called APT1 espionage crew: the detailed dossier claimed Shanghai-based People's Liberation Army Unit 61398 had hacked and injected malware into 141 organisations globally over seven years, and swiped terabytes of corporate secrets as a result.

Months later it emerged hackers had lifted personal information from CorporateCarOnline, a limousine-booking firm used by Mandia as well as basketball star LeBron James, Donald Trump and many other famous figures.

Data grabbed from the limo biz included names and addresses and credit numbers in a plain-text archive, plus travel records and instructions to drivers. The records were found on the same servers used by hackers to store information stolen from PR Newswire as well as source code taken from Adobe, investigative journalist Brian Krebs reported in November 2013.

Around that time, Mandia received emails with spyware-loaded PDFs of limo invoices. The US Air Force officer-turned-businessman said he strongly suspected the Chinese were behind that phishing expedition.

"People try to hack us all the time," Mandia told The Reg at the Infosec trade show in London last week.

Mandiant was acquired by FireEye in a stock-and-cash deal worth more than $1bn, a move that installed Mandia as FireEye's COO. In his new role, and as before, Mandia insists security breaches of one sort or another are inevitable, so his strategy is to minimise the consequences of a system compromise.

"I try to do as much business as I can either face-to-face or on the phone," Mandia explained by way of example. "I don't do a lot of email and, when I do, I use an iPad."

The Kremlin raised ripples in the security world this year by ditching iPads for Android tablets from Samsung. Politicians, government officials and high-profile business folk have long been the target of espionage, online and offline, but as the world becomes more and more connected, spying is likely to increase.

"I'd advise firms not to keep what they don't need and to keep their internet presence small – contrary to what marketing may say," he advised.

Hall of mirrors

APT1 is very much back in business after a "brief hiatus", according to Mandia. The hacking gang is using a whole new infrastructure built after infiltrating systems at universities and small businesses in the US. These compromised assets – "thousands of new victims", we're told – are used as launch pads for lucrative espionage missions, Mandia said.

He also argued the actions of NSA whistleblower Edward Snowden have had no effect on cyber-espionage activity. "Nation states that are hacking are still hacking," Mandia noted.

The self-styled Syrian Electronic Army, miscreants in Iran, Russia, Ukraine and China, and Anonymous hacktivists are the main cast in Mandiant's cyber-threat theatre. Most of the firm's clients are either US organisations or multi-national corps.

Mandia, who served in Uncle Sam's air force and in the Pentagon before leaving for the private sector, said Mandiant "hadn't seen" any cyber-espionage activity that traced back to the United States, maintaining that US spooks hack foreigners for "security reasons and not economic" reasons. Judging by Snowden-sourced documents, NSA cyber-spies allegedly raided oil giant Petrobras in Brazil and the Mexican president's email inbox for those aforementioned security reasons, it seems. ®

Gartner critical capabilities for enterprise endpoint backup

More from The Register

next story
Microsoft: We plan to CLEAN UP this here Windows Store town
Paid-for apps that provide free downloads? Really
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Hear ye, young cyber warriors of the realm: GCHQ wants you
Get involved, get a job and then never discuss work ever again
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
7 Elements of Radically Simple OS Migration
Avoid the typical headaches of OS migration during your next project by learning about 7 elements of radically simple OS migration.
BYOD's dark side: Data protection
An endpoint data protection solution that adds value to the user and the organization so it can protect itself from data loss as well as leverage corporate data.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?