Banks, dam targeted by Iranian hackers, US says; 7 charged

WASHINGTON — The U.S. charged seven hackers linked to the Iranian government with executing large-scale coordinated cyberattacks on dozens of banks as well as a small dam outside New York City — intrusions that law enforcement officials said reached into America’s infrastructure, disrupted the nation’s financial system and cost tens of millions.

Indictments announced Thursday by the Justice Department show a determination by overseas hackers to cripple vital American interests, officials said, and marked the first time the FBI attributed a breach of a U.S. computer system that controls critical infrastructure to a hacker linked to a foreign government.

The hackers are accused of infecting thousands of people’s computers with malware to create a network of zombie computers they used to overwhelm servers of major institutions to knock them offline. Those included the Bank of America, NASDAQ and the New York Stock Exchange.

“The attacks were relentless, systematic and widespread,” said Attorney General Loretta Lynch. “They threatened our economic well-being and our ability to compete fairly in the global marketplace, both of which are directly linked to our national security.”

One of the alleged hackers is accused of repeatedly gaining access to the control system of the Bowman Avenue Dam, a small flood-control structure in Rye Brook, about 20 miles north of New York City. Officials termed his access “a frightening frontier on cybercrime,” and said the hacker would have been able to operate a digitally controlled sluice gate, flooding portions of the city of Rye, but the gate had been disconnected for maintenance.

The hacker was still able to gain information about the dam’s operations, including its water level, temperature and the sluice gate.

While that attack did no harm, one official said the hacker obtained knowledge about the computer system that could be used on other dams and infrastructure. The official spoke on condition of anonymity because he wasn’t authorized to speak publicly. Computer systems, such as the one controlling the dam, are considered the backbone or core of modern industries including transportation, energy, oil and gas and manufacturing.

The indictments unsealed Thursday stem from intrusions between 2011 and 2013 that officials say targeted 46 victims, disabling bank websites and interfering with customers’ ability to do online banking. The attacks, which occurred sporadically over 176 days, cost the institutions tens of millions of dollars in remediation costs, but no customers lost money or had their personal information stolen.

The accused hackers worked for two Iranian computer companies linked to the Iranian government, including the Islamic Revolutionary Guard Corps, the U.S. said. Charges include violating U.S. laws on computer hacking and gaining unauthorized access to a protected computer.

The seven defendants are Ahmad Fathi, 37; Hamid Firoozi, 34; Amin Shokohi, 25; Sadegh Ahmadzadega, 23; Omid Ghaffarinia, 25; Sina Keissar, 25, and Nader Saedi, 26. Faroozi is charged alone for hacking the dam. Shokohi received credit from the Iranian government toward his mandatory military service for his work in the attacks, the U.S. alleges.

None of the individuals is in American custody and it’s unclear whether they will ever be arrested or if criminal indictments in absentia are effective in combatting such crimes.

The Justice Department in May 2014 indicted five Chinese military officials suspected of hacking into several major American companies, including U.S. Steel and Westinghouse, and stealing trade secrets. None has been brought to the U.S. to face charges.

The Justice Department is determined to remove a cloak of “perceived anonymity” long enjoyed by foreign hackers and has focused on doing so since 2012, said John Carlin, the department’s top national security official.

“We want them looking over their shoulder, both when they travel and when they sit at a keyboard,” said FBI Director James Comey.

The criminal case comes amid warming relations between the U.S. and Iran following last year’s nuclear agreement.

Since rolling back its nuclear program this year, Iran has regained access to some $100 billion in overseas assets and the two countries’ top diplomats have been meeting and discussing global matters at their most intensive level since Iran’s 1979 overthrow of the U.S.-backed shah.

Significant tensions remain, however. Iran has conducted several ballistic missile tests in violation of a U.N. ban, prompting the latest U.S. sanctions against the Islamic Republic on Thursday.

In 2010, the so-called Stuxnet virus disrupted the operation of thousands of centrifuges at a uranium enrichment facility in Iran. Iran says that assault and other computer virus attacks are part of a concerted effort by Israel, the U.S. and their allies to undermine its nuclear program through covert operations.

The latest Iranian attacks were a reminder of U.S. vulnerabilities, said Luke Dembosky, who supervised national security-related cyber cases at the Justice Department until March 1. “We were very fortunate that this access did not lead to something catastrophic, but the next one might.”

In December, hackers linked to Russia used a coordinated attack to take down part of Ukraine’s power grid, blacking out more than 225,000 people after hitting regional electric power distribution companies. U.S. officials called that the realization of a nightmare scenario — that hackers can remotely take down a critical system on which a country depends.

Talk to us

More in Herald Business Journal

Members of Gravitics' team and U.S. Rep. Rick Larsen stand in front of a mockup of a space module interior on Thursday, August 17, 2023 at Gravitics' Marysville facility. Left to right: Mark Tiner, government affairs representative; Jiral Shah, business development; U.S. Rep. Rick Larsen; Mike DeRosa, marketing; Scott Macklin, lead engineer. (Gravitics.)
Marysville startup prepares for space — the financial frontier

Gravitics is building space station module prototypes to one day house space travelers and researchers.

Orca Mobility designer Mike Lowell, left, and CEO Bill Messing at their office on Wednesday, Aug. 16, 2023 in Granite Falls, Washington. (Olivia Vanni / The Herald)
Could a Granite Falls startup’s three-wheeler revolutionize delivery?

Orca Mobility’s battery-powered, three-wheel truck is built on a motorcycle frame. Now, they aim to make it self-driving.

Catherine Robinweiler leads the class during a lab session at Edmonds College on April 29, 2021. (Kevin Clark / The Herald)
Grant aids apprenticeship program in Mukilteo and elsewhere

A $5.6 million U.S. Department of Labor grant will boost apprenticeships for special education teachers and nurses.

Peoples Bank is placing piggy banks with $30 around Washington starting Aug. 1.
(Peoples Bank)
Peoples Bank grant program seeks proposals from nonprofits

Peoples Bank offers up to $35,000 in Impact Grants aimed at helping communities. Applications due Sept. 15.

Workers build the first all-electric commuter plane, the Eviation Alice, at Eviation's plant on Wednesday, Sept. 8, 2021 in Arlington, Washington.  (Andy Bronson / The Herald)
Arlington’s Eviation selects Seattle firm to configure production plane

TLG Aerospace chosen to configure Eviation Aircraft’s all-electric commuter plane for mass production.

Jim Simpson leans on Blue Ray III, one of his designs, in his shop on Friday, August 25, 2023, in Clinton, Washington. (Ryan Berry / The Herald)
Whidbey Island master mechanic building dream car from “Speed Racer”

Jim Simpson, 68, of Clinton, is using his knowledge of sports cars to assemble his own Mach Five.

Inside the new Boeing 737 simulator at Simulation Flight in Mukilteo, Washington on Wednesday, Sept. 20, 2023. (Annie Barker / The Herald)
New Boeing 737 simulator takes ‘flight’ in Mukilteo

Pilots can test their flying skills or up their game at Simulation Flight in Mukilteo.

An Amazon worker transfers and organizes items at the new PAE2 Amazon Fulfillment Center on Thursday, Sept. 14, 2023, in Arlington, Washington. (Ryan Berry / The Herald)
Amazon cuts ribbon on colossal $355M fulfillment center in Arlington

At 2.8 million square feet, the facility is the largest of its kind in Washington. It can hold 40 million “units” of inventory.

A computer rendering of the North Creek Commerce Center industrial park in development at 18712 Bothell-Everett Highway. (Kidder Mathews)
Developer breaks ground on new Bothell industrial park

The North Creek Commerce Center on Bothell Everett Highway will provide warehouse and office space in three buildings.

Dan Bates / The Herald
Funko president, Brian Mariotti is excited about the growth that has led his company to need a 62,000 square foot facility in Lynnwood.
Photo Taken: 102312
Former Funko CEO resigns from the Everett company

Brian Mariotti resigned Sept. 1, six weeks after announcing he was taking a six-month sabbatical from the company.

Cash is used for a purchase at Molly Moon's Ice Cream in Edmonds, Washington on Wednesday, Aug. 30, 2023. (Annie Barker / The Herald)
Paper or plastic? Snohomish County may require businesses to take cash

County Council member Nate Nehring proposed an ordinance to ban cashless sales under $200. He hopes cities will follow suit.

A crowd begins to form before a large reception for the opening of Fisherman Jack’s at the Port of Everett on Wednesday, August 30, 2023, in Everett, Washington. (Ryan Berry / The Herald)
Seafood with a view: Fisherman Jack’s opens at Port of Everett

“The port is booming!” The new restaurant is the first to open on “restaurant row” at the port’s Waterfront Place.