CISA boss swatted: 'While my own experience was certainly harrowing, it was unfortunately not unique'
- Reference: 1706034614
- News link: https://www.theregister.co.uk/2024/01/23/cisa_easterly_swatted/
- Source link:
Easterly described the incident as a "harrowing" experience in an official statement:
One of the most troubling trends we have seen in recent years has been the harassment of public officials across the political spectrum, including extreme incidents involving swatting and direct personal threats. These incidents pose a serious risk to the individuals, their families, and in the case of swatting, to the law enforcement officers responding to the situation.
While my own experience was certainly harrowing, it was unfortunately not unique. In particular, several of our nation's election officials have also been targeted with this type of harassment and other threats of violence. The men and women of both parties who run our elections work tirelessly to ensure their security and integrity. We at CISA, along with our partners, will continue to support these election heroes as they work every day to safeguard our most sacred democratic process.
Swatting — calling in a hoax an emergency report for a serious crime to bring heavily armed law enforcement officers onto the scene can sometimes [1]turn deadly , as was the case with a Kansas man who was killed by police in 2017 when a California gamer made a fake emergency call after a dispute over a Call of Duty session.
Over the last few months, criminals have also been using this tactic in [2]extortion attempts and trying to force victim organizations, specifically hospitals and medical clinics, to pay ransom demand by swatting their patients.
[3]After injecting cancer hospital with ransomware, crims threaten to swat patients
[4]Bomb scare causes mass evacuation at DEF CON
[5]Future of America's Cyber Safety Review Board hangs in balance amid calls for rethink
[6]US agencies warn made-in-China drones might help Beijing snoop on the world
Local paper, The Record [7]first reported that police in Arlington County, Virginia, were investigating a 911 call on the evening of December 30 that falsely claimed a shooting had occurred inside a home on Easterly's block. The CISA declined to answer questions about who was behind the crime or why Easterly was targeted.
Several politicians and election officials have been targeted by swatting attempts over the last couple months as the US gears up for a contentious 2024 presidential election. These include [8]Maine Secretary of State Shenna Bellows , following her decision that Donald Trump was ineligible to be on her state's primary ballot.
[9]Other calls have targeted judges overseeing cases against Trump, Democratic and Republican politicians of both parties, a prosecutor, the White House, and [10]state capital buildings in at least eight states. ®
[11]
Get our [12]Tech Resources
[1] https://www.theregister.com/2018/05/24/swatting_death_indictment/
[2] https://www.theregister.com/2024/01/05/swatting_extorion_tactics/
[3] https://www.theregister.com/2024/01/05/swatting_extorion_tactics/
[4] https://www.theregister.com/2023/08/14/def_con_bomb_scare/
[5] https://www.theregister.com/2024/01/18/cyber_safety_review_board_rethink/
[6] https://www.theregister.com/2024/01/19/drone_cisa_fbi/
[7] https://therecord.media/cisa-jen-easterly-swatting-incident
[8] https://thehill.com/regulation/court-battles/4418594-swatting-incident-was-meant-to-intimidate-says-maine-secretary-of-state/
[9] https://www.cbsnews.com/news/swatting-attacks-public-officials-targeted/
[10] https://www.nytimes.com/2024/01/04/us/politics/threats-election-officials-swatting.html
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZbBFGEQwggdJBRC2hUDaqgAAAEw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[12] https://whitepapers.theregister.com/
one would hope, but telcos still somehow escape all responsibility, allowing call spoofing, robo calls (millions of calls from one source)
Back in the day when they charged $2 a min for long distance calls, (equal to $6 today) they didn't allow anyone to do anything. Now they don't GAF.
Hey, they had to make up that revenue someplace, including by allowing probable bad actors network access as long as they paid the connection fees!
Yes, I just heard a gun shot at the address followed by a lot of screaming... yes, I know I'm 5,000 miles away, I've just got very acute hearing.
I'm not sure how the police shooting people so often that they're used as an instrument of revenge makes it the phone companies' problem.
Someone could use a VPN to disguise where they're coming from, and there are probably laws preventing 911 centers from deciding to ignore calls they think are fake. They probably have to pass them all along, and leave it up to the judgment of local emergency personnel to make that determination.
They probably aren't using one directly, but a local VOIP provider. It might be a giveaway if it's all coming from international numbers, but if it's a number from that country, there's less that can be done to identify whether it's being proxied for an international origin. In addition, it's probably not being proxied in this or many other cases. The people who want to attack a US election official are probably in the US to begin with, so wherever they're calling from, it's in the country. You would have to use geolocation data to identify where the caller was, and I don't think the systems for collecting and reporting it are fast enough to let them filter it. With all of these obstacles, they probably send the calls to the local authorities rather than deal with the risk that someone actually has an emergency and they ignored it.
Thought Experiment
Can anyone name another country where this happens?
Re: Thought Experiment
https://www.newstatesman.com/science-tech/2015/08/swatting-uk-trolls-newest-intimidation-and-harassment-tool-and-police-need-take-it
The UK for a start.
But really anywhere that has an emergency dispatch number that can deliver lumps of firearm wielding meat to your doorstep, which is most countries.
Re: Thought Experiment
Dystopia
Swatting only works because of how trigger happy yank cops are.
Yeah yeah yeah.
Militarism of the police, mass shootings, swatting...move on, nothing will change.
Thoughts and Prayers etc, etc.
Some background
Swatting is toxic but ElReg readers may be unaware of just why emotions are running high over there.
Note what she very oddly chose to bring up then emphasise:
>work tirelessly to ensure their security and integrity. We at CISA, along with our partners, will continue to support these election heroes as they work every day to safeguard our most sacred democratic process.
A/ General Note: This wildly overflown black&white us&"them" heroes-vs-evil melodramatic language is characteristic of activist deceit/manipulation.
B/ Tech.Note: It is over 6mths since the public release of the tech.investigation of the Dominion election machines. First & only one with hands-on access. Readers of this site might understand the implications of some of the larger findings re Easterley's oddly-referenced topic: Election Security:
* You get full Root access + tools if you plug in an external keyboard.
* If you have a staff card, for your convenience you get this by just triggering the onscreen keyboard.
* All election setup data (eg candidate names) is centrally prepared then distributed & manually loaded by Zip files. Which are mini file systems. Dominion wrote their own Zip file extractor. It has full Zip Slip compatibility. It will place any file any where in the file system with whatever self-assigned permissions it comes with. This includes the core election app binaries. So any BadActor at any point in the distribution process can invisibly hijack every machine downstream of that point. This will only be detectable on site if people can read the QR codes on their printed ballot.
I would hope that 911 centers would be told by the telco that the call was routed via an overseas VOIP provider and thus was probably fake.