Hacker group claims responsibility for cyberattacks

Disruptive Cyberattack

Dyn, a New Hampshire internet service company, is located in the old mill section of the city, On Friday, Oct. 21, 2016, cyberattacks on the key internet firm repeatedly disrupted the availability of popular websites across the United States (AP Photo/Jim Cole)

STATEN ISLAND, N.Y. -- Withering cyberattacks on server farms of a key internet  firm repeatedly disrupted access to major websites -- including SILive.com -- and online services including Twitter, Netflix and PayPal across the United States on Friday.

The White House called the disruption malicious and a hacker group claimed responsibility, though its assertion couldn't be verified.

Manchester, New Hampshire-based Dyn Inc. said its data centers were hit by three waves of distributed denial-of-service attacks, which overwhelm targeted machines with junk data traffic. The attacks, shifting geographically, had knock-on effects for users trying to access popular websites across the U.S. even in Europe.

"The complexity of the attacks is what is making it so difficult for us," said Kyle York, the company's chief strategy officer. "What they are actually doing is moving around the world with each attack." He said an East Coast data center was hit first; attacks on an offshore target followed later.

The data flood came from tens of millions of different Internet-connected machines -- including increasingly popular but highly insecure household devices such as web-connected cameras. It was an onslaught whose global shifts suggested a sophisticated attacker, though Dyn said it had neither suspect nor motive.

BROAD EFFECTS

The level of disruption was difficult to gauge, but Dyn serves some of the biggest names on the web, providing the domain name services that translate the numerical internet addresses into human-readable destinations such as "twitter.com."

Steve Grobman, chief technology officer at Intel Security, compared an outage at a domain name services company to tearing up a map or turning off GPS before driving to the department store. "It doesn't matter that the store is fully open or operational if you have no idea how to get there," he said in a telephone interview.

Jason Read, founder of the internet performance monitoring firm CloudHarmony, owned by Gartner Inc., said his company tracked a half-hour-long disruption early Friday in which roughly one in two end users would have found it impossible to access various websites from the East Coast.

"We've been monitoring Dyn for years and this is by far the worst outage event that we've observed," said Read.

Dyn provides services to some 6 percent of America's Fortune 500 companies, he said. A full list of affected companies wasn't immediately available but Twitter, Netflix, PayPal and the coder hangout Github said they experienced problems.

HACKERS CLAIM RESPONSIBILITY

Members of a shadowy collective that calls itself New World Hackers claimed responsibility for the attack via Twitter. They said they organized networks of connected "zombie" computers called botnets that threw a staggering 1.2 terabits per second of data at the Dyn-managed servers.

"We didn't do this to attract federal agents, only test power," two collective members who identified themselves as "Prophet" and "Zain" told an AP reporter via Twitter direct message exchange. They said more than 10 member participated in the attack. It was not immediately possible to verify the claim.

Dyn officials said they have received no claim of responsibility, but are working with law enforcement.

The collective, @NewWorldHacking on Twitter, has in the past claimed responsibility for similar attacks against sites including ESPN.com in September and the BBC on Dec. 31. The attack on the BBC marshaled half the computing power of Friday's onslaught.

The collective has also claimed responsibility for cyberattacks against Islamic State. The two said about 30 people have access to the @NewWorkdHacking Twitter account. They claim 20 are in Russia and 10 in China. "Prophet" said he is in India. "Zain" said he is in China. The two claimed to their actions were "good," presumably because they highlighted

internet

security problems.

Another collective member the AP previously communicated with via direct message called himself "Ownz" and identified himself as a 19-year-old in London. He told the AP that the group -- or at least he -- sought only to expose security vulnerabilities.

During the attack on the ESPN site, "Ownz" was asked if the collective made any demands on sites it attacked, such as demanding blackmail money. "We will make one demand actually. Secure your website and get better servers, otherwise be attacked again," he said.

For James Norton, the former deputy secretary at the Department of Homeland Security who now teaches on cybersecurity policy at Johns Hopkins University, the incident was an example of how attacks on key junctures in the network can yield massive disruption.

If you purchase a product or register for an account through a link on our site, we may receive compensation. By using this site, you consent to our User Agreement and agree that your clicks, interactions, and personal information may be collected, recorded, and/or stored by us and social media and other third-party partners in accordance with our Privacy Policy.