NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / World

Iranians tried to hack US presidential campaign in effort that targeted hundreds, Microsoft says

By Jay Greene, Tony Romm and Ellen Nakashima
Washington Post·
5 Oct, 2019 04:43 AM7 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Trump calls for China to investigate Bidens; former Ukraine envoy testifies on Capitol Hill. Video / NBC News

An effort believed to be tied to the Iranian government attempted to identify, attack and breach email accounts belonging to a U.S. presidential campaign, government officials and journalists, according to new data unveiled by Microsoft, highlighting the continued global security threats that loom over the fast-approaching 2020 election.

The intrusion observed by Microsoft, spearheaded by an outfit it calls Phosphorus, made more than 2,700 attempts to identify personal email addresses that belonged to the company's customers over a 30-day period between August and September, 241 of which were then attacked. Four were compromised, but they do not belong to the presidential campaign or government officials, according to the tech giant.

Reuters and other news media outlets reported the hackers targeted President Donald Trump's campaign.

Microsoft said it notified the customers attacked and has worked with those whose accounts were compromised to secure them. It declined to disclose the names of the account holders, including the presidential campaign that had been targeted. Microsoft declined to comment beyond a blog post disclosing the news Friday.

Tim Murtaugh, a spokesman for President Trump's 2020 campaign, said he has "no indication that any of our campaign infrastructure was targeted." Asked to clarify whether Microsoft had contacted the campaign about Iranian targeting of either the campaign or campaign personnel's personal email accounts, Murtaugh said: "We have no further comment."

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

The news is the latest reminder that the US is likely still vulnerable to security threats when it comes to the 2020 presidential election. Tech giants like Facebook and Twitter, as well as politicians and security officials have all made the next presidential election a priority as they race to combat hackers - some of whom are working for foreign governments.

Still, recent technology developments like increasingly realistic "deepfake" or otherwise manipulated videos have many cybersecurity experts concerned about how hackers might be able to manipulate public perception in the way the Russians did in 2016.

During the last presidential election, U.S. officials uncovered a sprawling effort backed by the Kremlin to trigger social and political unrest on major social media sites. Russian hackers also targeted Democratic candidate Hillary Clinton by hacking the emails of one of her top lieutenants, the contents of which were later dumped on Wikileaks.

Advertisement
Advertise with NZME.

Since then, other countries have come to adopt more of Russia's playbook, including Iran, which for years has targeted US officials through "large-scale intrusion attempts," said John Hultquist, the director of intelligence analysis at the cybersecurity firm FireEye. But Iran only has become more aggressive recently in response to President Trump, he said, who has imposed massive sanctions and pulled out of an international deal over the country's nuclear program.

"The Iranians are very aggressive, and they could leverage whatever access they get for an upper hand in any kind of negotiations," Hultquist added. "They could cause a lot of mayhem."

Other tech companies also have been warning about the rising Iranian threat, largely out of concern that malicious actors originating in the country were spreading disinformation online. In May, for example, Facebook and Twitter said they had removed a sprawling Iranian-based propaganda operation, including accounts that mimicked Republican congressional candidates and appeared to try to push pro-Iranian political messages on social media. Some of those accounts similarly took aim at U.S. policymakers and journalists, researchers said at the time.

Private-sector analysts have documented a gradual increase in cyber activity by Iran and its proxies targeting US industry since 2014, and especially in the last year. It has often come in the form of targeted phishing attempts seeking access to computer systems in the energy sector.

Discover more

World

Trump calls for China to investigate Bidens

03 Oct 04:33 PM
World

Trump says the Democratic-led House has the votes to impeach him

04 Oct 11:04 PM
World

Comment | All in: Donald Trump's colossal gamble

05 Oct 01:49 AM
World

Trump's order will deny visas to immigrants who lack health-care coverage

05 Oct 05:35 AM

Christopher Krebs, director of DHS' Cybersecurity and Infrastructure Security Agency, said in a statement that the agency is working with Microsoft "to assess and mitigate impacts.

"While much of this activity can likely be attributed to run-of-the-mill foreign intelligence service work, Microsoft's claims that a presidential campaign was targeted is yet more evidence that our adversaries are looking to undermine our democratic institutions," he said in the statement. He urged Americans to be on their guard.

In June, Krebs told The Washington Post that "Iranian hackers and their proxies "are not just garden-variety run-of-the-mill data thieves," he said. "These are the guys that come in and they burn the house down." He urged companies and organisations to take computer security seriously.

Microsoft software is present in far more computers around the world than U.S. law enforcement and intelligence agencies, giving the company a broader window into the threat than government authorities.

The Democratic National Committee warned campaigns about the Phosphorus attacks, noting that the group has been targeting personal and professional email accounts. The DNC recommended that members review logs for connection attempts in August and September.

"They create believable spear phishing emails and fake LinkedIn profiles as primary tactics," according to the email from the DNC obtained by The Post. Microsoft also owns the LinkedIn professional social network.

Advertisement
Advertise with NZME.

Spokespeople for Democratic candidates including Elizabeth Warren and Cory Booker did not immediately respond to requests for comment. Spokespeople for former vice president Joe Biden and Sen. Bernie Sanders declined to comment. Ian Sams, a spokesman for Kamala Harris said he had "no indication that our campaign is the one Microsoft referenced or that we have been targeted by this attack."

To target political and government officials' emails, Phosphorus hackers tried to figure out how to reset passwords or otherwise trigger account recovery features to take over accounts, Microsoft said. In some instances, Microsoft found that the group gathered phone numbers belonging to its targets to try to authenticate password resets.

The attacks were not "technically sophisticated," Microsoft's vice president of customer security and trust, Tom Burt, wrote in the blog post. But he noted that they used significant amounts of the targets' personal information, suggesting that Phosphorus was willing to invest "significant time and resources engaging in research and other means of information gathering."

This isn't Microsoft's first brush with Phosphorus. The company, which names hacking groups after elements on the periodic table, seized 99 websites in March it said were used by the group to launch cyberattacks against government agencies, businesses and users in Washington. Microsoft said it had been tracking the group for six years. Other researchers have tagged the group Ajax Security Team, APT 35 and Charming Kitten.

At the time, Microsoft said Phosphorus had targeted activists and journalists, "especially those involved in advocacy and reporting on issues related to the Middle East."

Phosphorus used the websites Microsoft seized this spring to trick visitors into downloading malicious software that appeared authentic. But that was only one of the group's tactics. In Phosphorus's latest attempts, the group tried to trick users into give up codes that are used for two-factor authentication.

Advertisement
Advertise with NZME.
Donald Trump answers journalists' questions. Photo / Getty Images
Donald Trump answers journalists' questions. Photo / Getty Images

The fact that these attacks rely on social engineering, rather than technical skill, makes them particularly difficult to thwart. Tech giants can often detect digital anomalies intended to undermine email and server software. But it's much harder to use algorithms to detect phishing attempts aimed at tricking users. In May, Microsoft offered software to federal campaigns and national political committees to help prevent such breaches.

Allison Wikoff, a researcher with Atlanta-based Secureworks who has conducted previous analysis on Phosphorus, said Microsoft's report marked the first public disclosure of attempted intrusion on a 2020 presidential campaign. It is possible, however, that similar activities have unfolded but gone unobserved, she noted.

The level of research that went into identifying targets, as social media and other tools become more and more central to the tactics of the suspected hackers, was particularly noteworthy, Wikoff said.

"This group and other Iranian groups are very focused on the credentials of particular people of interest, whether they be US government officials or people working for other types of companies that may be of strategic interest to the Iranian government," Wikoff said.

Save

    Share this article

Latest from Technology

Premium
Business

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM
World

What you need to know about Trump Mobile's ambitious phone plans

17 Jun 02:04 AM
Premium
Business|companies

Mighty Ape boss fronts over glitch that saw some users logged into other users’ accounts

15 Jun 11:27 PM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Technology

Premium
Fringe Benefit Tax: Should you be paying it if your business owns a ute?

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM

The IRD says changes should be revenue-neutral – but many have never paid FBT.

What you need to know about Trump Mobile's ambitious phone plans

What you need to know about Trump Mobile's ambitious phone plans

17 Jun 02:04 AM
Premium
Mighty Ape boss fronts over glitch that saw some users logged into other users’ accounts

Mighty Ape boss fronts over glitch that saw some users logged into other users’ accounts

15 Jun 11:27 PM
One NZ expands Starlink partnership to Internet of Things

One NZ expands Starlink partnership to Internet of Things

15 Jun 09:34 PM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP