{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-john-podesta-and-dnc-staff-phished-by-fake-google-security-alerts-in-201"},"incident":{"title":"John Podesta and DNC staff phished by fake Google security alerts in 2016","date":"2016-03-19","date_precision":"day","victim_org":"Hillary for America campaign and the Democratic National Committee","sector":"Government","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Data Breach","Espionage","Credential Theft"],"loss_usd":null,"loss_note":"No direct monetary loss reported; harm was reputational and political.","records_affected":null,"threat_actor":"Fancy Bear / APT28, identified in the July 2018 US indictment as GRU Unit 26165","summary":"On 19 March 2016 Hillary Clinton campaign chairman John Podesta received an email styled as a Google security alert warning that someone had his password and urging him to change it. The Bitly-shortened link led to a credential harvesting page controlled by Russian military intelligence. More than 50,000 of Podesta's emails were later published by WikiLeaks; similar spear phishing was used against DNC staff.","how_it_worked":"The message imitated Google's 'Someone has your password' notification and carried a Bitly link masking an attacker-controlled domain that rendered a pixel-perfect Google account login page. A campaign IT aide replied that the mail was legitimate, later saying he had meant to write 'illegitimate,' and the link was clicked and the password entered. With mailbox access the operators archived the account's contents. The same infrastructure was used across hundreds of targets; because Bitly statistics were public, researchers were later able to reconstruct the target list and confirm the operator's identity.","lessons":"Hardware security keys on campaign and executive Google accounts make a harvested password worthless, and a defined out-of-band process for verifying security alerts avoids relying on a hurried email reply.","confidence":"Confirmed","sources":[{"title":"Is this the email that hacked John Podesta's account?","url":"https://www.cnn.com/2016/10/28/politics/phishing-email-hack-john-podesta-hillary-clinton-wikileaks/index.html","publisher":"CNN"},{"title":"How hackers broke into John Podesta, DNC Gmail accounts","url":"https://news.sophos.com/en-us/2016/10/25/how-hackers-broke-into-john-podesta-dnc-gmail-accounts/","publisher":"Sophos Naked Security"},{"title":"How John Podesta's Emails Were Hacked And How To Prevent It From Happening To You","url":"https://www.forbes.com/sites/kevinmurnane/2016/10/21/how-john-podestas-emails-were-hacked-and-how-to-prevent-it-from-happening-to-you/","publisher":"Forbes"}],"entry_type":"incident","slug":"2016-john-podesta-and-dnc-staff-phished-by-fake-google-security-alerts-in-201","year":2016,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2016-john-podesta-and-dnc-staff-phished-by-fake-google-security-alerts-in-201"}}