{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-gru-spearphishing-of-the-clinton-campaign-dnc-and-dccc"},"incident":{"title":"GRU spearphishing of the Clinton campaign, DNC and DCCC","date":"2016","date_precision":"year","victim_org":"Hillary Clinton presidential campaign, Democratic National Committee and Democratic Congressional Campaign Committee","sector":"Government","country":"United States","primary_vector":"Spear Phishing (Email)","secondary_vectors":["Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported in the indictment.","outcomes":["Espionage","Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No monetary loss; the outcome was mass exfiltration and staged public release of emails and documents.","records_affected":null,"threat_actor":"Russian GRU Units 26165 and 74455 (twelve officers indicted)","summary":"A federal grand jury indictment announced on 13 July 2018 charged twelve Russian GRU officers with hacking offences related to the 2016 US election. According to the Department of Justice, officers in Unit 26165 began spearphishing volunteers and employees of the Clinton presidential campaign, including the campaign's chairman, and used the same methods against the DCCC and DNC to obtain usernames and passwords, steal emails and documents, monitor employee activity and implant malicious code.","how_it_worked":"The unit sent targeted emails to campaign staff and party employees that harvested account usernames and passwords. Compromised mailboxes yielded further contact lists and internal context that made subsequent lures more credible, letting the operation spread laterally from volunteers to senior staff. Stolen credentials were then used to access other computers on the committees' networks, where the officers monitored employee activity and installed malware for persistent collection. The exfiltrated correspondence was subsequently staged and released publicly to maximise political effect during the campaign.","lessons":"Hardware security keys for all campaign and party staff, which several campaigns adopted afterwards, defeat credential-harvesting pages regardless of how convincing the lure is.","confidence":"Confirmed","sources":[{"title":"Grand Jury Indicts 12 Russian Intelligence Officers for Hacking Offenses Related to the 2016 Election","url":"https://www.justice.gov/opa/pr/grand-jury-indicts-12-russian-intelligence-officers-hacking-offenses-related-2016-election","publisher":"U.S. Department of Justice"}],"entry_type":"incident","slug":"2016-gru-spearphishing-of-the-clinton-campaign-dnc-and-dccc","year":2016,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-gru-spearphishing-of-the-clinton-campaign-dnc-and-dccc"}}