• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechHacking

Russia ‘Cozy Bear’ breached GOP as ransomware attack hit

By
William Turton
William Turton
,
Jennifer Jacobs
Jennifer Jacobs
and
Bloomberg
Bloomberg
Down Arrow Button Icon
By
William Turton
William Turton
,
Jennifer Jacobs
Jennifer Jacobs
and
Bloomberg
Bloomberg
Down Arrow Button Icon
July 6, 2021, 7:22 PM ET

Russian government hackers breached the computer systems of the Republican National Committee last week, around the time a Russia-linked criminal group unleashed a massive ransomware attack, according to two people familiar with the matter.

The government hackers were part of a group known as APT 29 or Cozy Bear, according to the people. That group has been tied to Russia’s foreign intelligence service and has previously been accused of breaching the Democratic National Committee in 2016 and of carrying out a supply-chain cyberattack involving SolarWinds Corp., which infiltrated nine U.S. Government agencies and was disclosed in December.

It’s not known what data the hackers viewed or stole, if anything. The RNC has repeatedly denied that it was hacked. “There is no indication the RNC was hacked or any RNC information was stolen,” spokesman Mike Reed said.

In a statement following the publication of this story, Chief of Staff Richard Walters said the RNC learned over the weekend that a third-party provider, Synnex Corp., had been breached.

“We immediately blocked all access from Synnex accounts to our cloud environment,” he said. “Our team worked with Microsoft to conduct a review of our systems and after a thorough investigation, no RNC data was accessed. We will continue to work with Microsoft, as well as federal law enforcement officials, on this matter.”

A spokesperson for the Russian Embassy in Washington didn’t respond to a request for comment.

The attack on the RNC, coupled with the recent ransomware attack, is a major provocation to President Joe Biden, who warned Russian President Vladimir Putin about cyberattacks at a June 16 summit. It’s not clear if the attack on the RNC is connected in any way to the ransomware attacks, which exploited multiple previously unknown vulnerabilities in software from Miami-based Kaseya Ltd.

The hackers are suspected to have attacked the RNC through Fremont, California-based Synnex, the people said, asking not to be identified as they weren’t authorized to discuss confidential matters. In a press release, Synnex said “it is aware of a few instances where outside actors have attempted to gain access, through Synnex, to customer applications within the Microsoft cloud environment.”

“As our review continues, we are unable to provide any specific details,” said Michael Urban, president of worldwide technology solutions distribution at Synnex in a statement to Bloomberg News. “As with any security issue, a full review of all companies, systems, third-party applications and related IT solutions must be completed before final determinations can be made.”

Russian intelligence hackers are taking advantage of the chaos created by the global ransomware campaign to attack valuable intelligence targets, one of the people familiar with the matter said. The ransomware attack — which cybersecurity experts attributed to a Russia-linked group called REvil — may have hit more than 1,000 victims., provides software for managed service providers, who in turn offer IT services to small- and medium-sized businesses.

REvil has demanded $70 million in Bitcoin to unlock the victims’ computers, according to cybersecurity experts who reviewed an announcement on the group’s website.

Kaseya said in a statement that fewer than 60 customers were compromised by the ransomware attack, all of whom used its VSA on-premises product. “While many of these customers provide IT services to multiple other companies, we understand the total impact thus far has been to fewer than 1,500 downstream businesses,” Kaseya said.

Charles Carmakal, a senior vice president at Mandiant, part of the cybersecurity company FireEye Inc., said his firm has observed the Russian government hackers carrying out breaches in recent days, though he declined to identify the victims. Carmakal said he had no first-hand knowledge of the RNC breach.

“No question, the Russian government is absolutely benefiting from security companies and intelligence organizations being so focused on ransomware right now,” Carmakal said. “But the question is, is the Russian government providing tacit approval for ransomware operators or are they providing instructions? I don’t know.

“Is it just coincidental timing for the Russian government to do some of the other things they’re doing right now?” Carmakal said. “Is this coordinated and planned? I have no idea. I know that both things are happening, that’s a fact, I just don’t know why.”

Subscribe to Coins2Day Daily to get essential business stories straight to your inbox each morning.

About the Authors
By William Turton
See full bioRight Arrow Button Icon
By Jennifer Jacobs
See full bioRight Arrow Button Icon
By Bloomberg
See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.