This post was contributed by a community member. The views expressed here are the author's own.

Neighbor News

Is the Russian FSB targeting USA military recruits?

Two incidents on Facebook have caught my attention: directed hacking & a false military recruiter. I see a vulnerability.

Currently, I am working on assembling the data necessary to write an article about the intense hacking activity that my political action committee's website, https://refpac.org , has been receiving. In previous posts, such as "Washington, We have a problem." (https://patch.com/texas/housto...), I noted that it's extremely disturbing that such aggressive attention is being paid to what is essentially a minuscule organization. We are interested in local politics, particularly special districts (The MAY election cycle is almost here!), and our membership is small, the contributors tiny*.

So why is the Referee PAC website being attacked so intensely?

I don't know, but what I do know is that when I commented about it on FB (see image dated April 7th, 3:42PM) while assembling the data for the upcoming post on how this is not-normal, there was a stunning reaction:

Find out what's happening in Houstonfor free with the latest updates from Patch.

<hr>

Another hack attempt on server.

Find out what's happening in Houstonfor free with the latest updates from Patch.

Received: Sunday, April 7, 2019 12:20 PM

From: Kim Kuhlman kim@blueskydigitalstrategy.com

To: Liz Jensen [deleted]
Hi Liz,

Early this morning I got four emails from [deleted] saying someone tried to change permissions in WordPress on my [deleted] site. It's the same server your site is on. I've never seen this before, and it happened four times within a minute from two Google IPs. There were several from that IP subnet 66.249.66.*, but I don't want to shut that whole set of IPs off. I can if you want, or you could go into [deleted] Security on the live site and add them yourself. I sent an abuse report to Google, but don't expect them to do much and certainly not right away. Please keep an eye out for anything weird.

Let me know how it's going.

Kim

<hr>

Received: Sunday, April 7, 2019 8:04 PM

From: Kim Kuhlman kim@blueskydigitalstrategy.com

To: Referee PAC [deleted]
Now they’re after kimkuhlmanphoto.com from a different block of IPs [shocked emoji]. I’m not too worried about them taking it down, but we should look at the logs for some patterns.

Kim

<hr>

Fw: Report for www.kimkuhlmanphoto.com

Received: Monday, April 8, 2019 7:28 PM

From: Kim Kuhlman kim@blueskydigitalstrategy.com

To: Liz Jensen [deleted]
They were very persistent today...

https://www.kimkuhlmanphoto.co...
Date Range Processed: Yesterday, April 7, 2019

Blocked threats: 59 (critical: 19, high: 19, medium: 21)

<hr>

As it's best to be cautious, let's break down what's happened here.

(1) FB ignored me when I pointed out a bad actor as shown in "Washington, We have a problem."

(2) I went onto FB to tell friends that I trust (that's what that symbol next to the time means) that I just cannot believe I'm dealing with this.

(3) In my post, I give credit where it's due to Dr. Kim Kuhlman.

(4) Within HOURS, Dr. Kuhlman's site is under heavy attack.

THE MOST IMPORTANT THING TO UNDERSTAND RIGHT NOW IS THAT CORRELATION DOES NOT MEAN CAUSATION.

The BEST illustration of this is the famous Dilbert cartoon:

https://dilbert.com/strip/2011...

So, why the sudden uptick in attacks on Dr. Kuhlman's personal website within hours of my post? My post only went to close friends and family. BUT, it's on a 3rd party platform: Facebook. And FB has already demonstrated that they are pretty unresponsive to alerts regarding non-violent security problems like this. To whom do I complain and how that I'm concerned my post may have been picked up regardless of my privacy settings by the hostile aggressors that have been hounding Referee PAC's website? If you want a laugh, try calling the Sheriff's Office.

Relative to the hacking attempts on Referee PAC's website, we're managing, and a post is in production regarding how extremely unsettling this is. That FB could have some connection to the people doing it is even more startling.

Why do I suspect the FSB? As documented in "Washington, We have a problem.", the first hack attempt came via phishing through a colleague's account on yahoo. Who was involved in that? "DoJ Indicts Russian FSB Officers and Cybercriminals in Yahoo Breach" [1]. What country was most of the spam email coming from? Russia. What country did I find at the source of a tweet that made me wary of what was going on? Russia. Also in my data regarding attacks on Referee PAC, a majority of them were coming from St. Petersburg, Russia...until we just shut down Russia from being able to access the website.

So shifting gears, now I see this:

A friend request was received from Mystery-Salutation "Williams H Josey", "Recruitment at US Army Recruitment Command", who began their FB account as Ms. "Olivia Ogbonna" (see the http text in the image).

How many kids responding to interactions that they've already had with recruiters and military personnel are going to friend this obviously fake account? Once friended, what kind of information are they going to be fed? What information are they going to pass to some random account? How many of these accounts targeting potential military recruits are weaving their web of deceit through FB?

I don't know, but what I do know is that I'm going to send a complaint to FB, and it's probably going to be ignored. Why is this important? I know a military veteran whose FB interactions led him to question the utility of NATO and to worship Mr. Assange, who is alleged to have helped hack the US military. Now imagine the very kids who are our national security's future being convinced to think the same way.

CORRELATION DOES NOT MEAN CAUSATION, but this is concerning and should not be ignored. However, I already know that it will be. I'm in charge of a minuscule political action committee under heavy attack by a foreign state actor with zero law enforcement support. I'm writing this in a small local electronic news service that also publishes conspiracy theorist raves (with incomplete sentences and almost unreadable grammar...God bless them.) Priority-wise, this is like junk mail going into the round "filing cabinet". My people and I are on our own.

*Side note: I guarantee that Referee PAC is the ONLY political action committee funded entirely by female PhDs.

References

[1] "DoJ Indicts Russian FSB Officers and Cybercriminals in Yahoo Breach" by Kelly Higgins https://www.darkreading.com/en...

[2] "Washington, We have a problem." by E.A. Jensen https://patch.com/texas/housto...

[3] Dilbert by Scott Adams https://dilbert.com/strip/2011...

The views expressed in this post are the author's own. Want to post on Patch?