The FBI director revealed new details Wednesday about the stunning cyberattack against Sony Pictures Entertainment Inc., part of the Obama administration’s effort to challenge persistent skepticism about whether North Korea’s government was responsible for the brazen hacking.
Speaking at the International Conference on Cyber Security at Fordham University, FBI Director James Comey revealed that the hackers “got sloppy” and mistakenly sent messages directly that could be traced to IP addresses used exclusively by North Korea. Comey said the hackers had sought to use proxy computer servers, a common ploy hackers use to disguise their identities and throw investigators off their trail by hiding their true locations.
“It was a mistake by them,” he said. “It made it very clear who was doing this.”
The Associated Press reported Dec. 20 that the FBI had discovered that computer Internet addresses known to be operated by North Korea were communicating directly with other computers used to deploy and control the hacking tools and collect the stolen Sony files. The FBI previously said its evidence also included similarities to other tools developed by North Korea in specific lines of computer code, encryption algorithms and data deletion methods.
“I have very high confidence about this attribution to North Korea, as does the entire intelligence community,” Comey said.
North Korea has denied it was involved in the hacking.
Comey said the Sony attack had “clear links” to malware developed by North Korea, Comey said. The same tools were used in an attack last year on South Korean banks and media outlets, he said.
Finally, the FBI’s Behavioral Analysis Unit studied statements and threats purporting to be from Guardians of Peace and compared them to other known attacks by the North Koreans, Comey said. The unit told him, “Easy for us - it’s the same actors,” Comey said.
Comey said the evidence should undermine persistent skepticism by some cyber experts that individual hackers or a disgruntled insider were the culprits behind a hack that sabotaged the wide release of “The Interview,” a comedy about a plot to kill North Korean leader Kim Jong Un.
“They don’t have the facts that I have, don’t see what I see,” he said.
Comey said he was hesitant to reveal more about how U.S. officials learned that North Korea was the source “because it will happen again, and we have to preserve our methods and sources.”
Earlier Wednesday, Director of National Intelligence James Clapper also warned North Korea will continue the attacks against American interests unless the United States “pushes back.”
Clapper told the audience of government and private cybersecurity experts that he had gained insight into North Korea’s anti-American mindset while dining with a top North Korean general last year when he went there to negotiate the release of two U.S. prisoners. The general would have been the one to give the green light for the attack on Sony, he said.
North Koreans “really do believe they are under siege from all directions,” and “are deadly, deadly serious about affronts to the supreme leader,” he said.
Earlier this week, Sony CEO Kazuo Hirai broke his silence about the attack, saying his employees were victims of a “vicious and malicious cyberattack,” while adding that he’s proud of them for standing against “the extortionist efforts of criminals.”
North Korea ‘hostile’ U.S. sanctions over Sony hackU.S. President Barack Obama last week authorized a new layer of sanctions on several Pyongyang institutions and officials Digital
U.S. says North Korea sanctions step one in Sony responseThe White House warned that this was just the opening move in the U.S. response Digital
Sony’s PlayStation back online after Christmas hackAn allegedly coordinated Christmas day hack brought down the gaming consoles, both hot gifts for the holiday season Technology
'The Interview' becomes Sony's No. 1 online movie of all timeThe film has also brought in $2.8 million in the limited theatrical run that began Christmas Day Digital
N. Korea blames U.S. for internet outages, calls Obama racist slurN. Korea said Obama was responsible for Sony's decision to release 'The Interview' Asia
Will 'The Interview' change how Hollywood does business?Sony is in uncharted waters now with the film, which earned $1.04 million from 331 locations Digital
Unprecedented: Where to watch ‘The Interview’ onlineTo counterstroke against hackers, ‘The Interview’ is now available to watch on: Google Play, YouTube, Xbox, Sony Digital
Obama hails Sony decision to release ‘The Interview’Sony Pictures to release the movie Digital
U.S. urges North Korea to compensate Sony for cyberattackWashington accuses Pyongyang of being behind the hack that led to the release of embarrassing Sony executives’ emails World News