After Russian Cyberattack, Looking for Answers and Debating Retaliation

Among those who testified at the hearing was Sudhakar Ramakrishna, the new chief executive of SolarWinds, who took over weeks after the breach was discovered and has since been peeling back the layers of the intrusion. He told the Senate committee that the code had been eradicated from the company’s products. But that is little use to the government agencies and companies that were already breached, because once the hackers are inside their targeted computer networks, they are free to roam.

Mr. Ramakrishna also said that SolarWinds was still unclear on how the Russian hackers got into the software it was developing, embedding themselves there as early as fall 2019. When asked about the possibility that software tools made by JetBrains, which speeds the development and testing of code, was the pathway, Mr. Ramakrishna said there was still no evidence. The New York Times reported in January that JetBrains was under investigation, but the company’s senior executives, some of whom are Russian, said there was no evidence.

Mr. Smith, who has called for a “digital Geneva convention” that would begin to create norms barring some kinds of attacks, estimated that “at least a thousand very skilled, capable engineers” were involved in the hacking.

“This was an act of recklessness, in my opinion,” he said, because it infected thousands of systems that the Russians had no interest in to give them access to only a few. “It was done in a very indiscriminate way.”

Mr. Warner, Senator Marco Rubio of Florida, the ranking Republican on the committee, and others noted repeatedly that Amazon — which runs the C.I.A.’s network cloud services and is seeking other major federal contracts — was the only company that refused to send a senior executive to explain its role in the hacking. Amazon has said nothing publicly about what it knew about the command-and-control operation run from its servers in the United States.

That is a crucial issue, because the hackers appeared to understand that American intelligence agencies are prohibited from examining network activity in the United States. So by initiating the attack within American borders, they were taking advantage of domestic privacy protections to avoid being detected.

Several senators said they were concerned that such a technique, once known, would be widely used by others. “The bottom-line question is how did we miss this, and what are we still missing?” Mr. Rubio said.

All countries
195,294,055
Total confirmed cases
Updated on July 26, 2021 11:42 pm
Italy
4,320,530
Total confirmed cases
Updated on July 26, 2021 11:42 pm
Spain
4,342,054
Total confirmed cases
Updated on July 26, 2021 11:42 pm
Iran
3,723,246
Total confirmed cases
Updated on July 26, 2021 11:42 pm
Germany
3,764,419
Total confirmed cases
Updated on July 26, 2021 11:42 pm

Latest Updates

Without Backpackers to Pick Them, Crops Rot by the Ton in Australia

SHEPPARTON, Australia — Peter Hall ran a hand over the Gala apples sitting in a wooden crate on his orchard in southeastern Australia, lamenting...

U.S. Will Have Enough COVID-19 Vaccines for All Adults by End of May, Biden Says

You have reached your limit of 4 free articles. Get unlimited access to TIME.com.99¢ for the first month Subscribe Now You have...

Biden Vows Enough Vaccine ‘for Every Adult American’ by End of May

But Johnson & Johnson and its partners fell behind in their manufacturing. The company was supposed to deliver its first 37 million doses by...

Popular Articles

Without Backpackers to Pick Them, Crops Rot by the Ton in Australia

SHEPPARTON, Australia — Peter Hall ran a hand over the Gala apples sitting in a wooden crate on his orchard in southeastern Australia, lamenting...

U.S. Will Have Enough COVID-19 Vaccines for All Adults by End of May, Biden Says

You have reached your limit of 4 free articles. Get unlimited access to TIME.com.99¢ for the first month Subscribe Now You have...

Biden Vows Enough Vaccine ‘for Every Adult American’ by End of May

But Johnson & Johnson and its partners fell behind in their manufacturing. The company was supposed to deliver its first 37 million doses by...

Twitch gamer Sodapoppin quits fake GTA jobs because they’re too hard

Sometimes being a fake fast-food restaurant manager can be as taxing as being a real one. This is especially true when you also have pretend...

Sarkozy says could take corruption appeal to European human rights court

France's former president Nicolas Sarkozy said Tuesday that he might consider taking his appeal against a corruption conviction to the European Court of...

Where Biden’s Foreign Policy Is Taking the U.S.

One day before the administration announced its decision on Saudi Arabia, Biden gave the first major indication of his presidency that he would be...

Interviews