Greg Weston: Anti-hacking agency slow to learn about Chinese cyberattack
'We cannot be the soft underbelly of North America,' retired CSIS boss says
By Greg Weston, CBC News
Posted: Feb 22, 2013 6:09 AM ET
Last Updated: Feb 22, 2013 10:58 PM ET
Confidential documents obtained by CBC News show that when Chinese military spies hacked into the control systems of Canadian pipelines and power grids last fall, this country’s official cyber-response agency sprang into action – exactly 10 days later.
On Sept. 10, 2012, Calgary-based Telvent advised its customers that hackers had managed to penetrate its computers and access some customer files. The company says it has no evidence the hackers gained access to the customers' computer systems.
"Telvent is aware of a security breach of its corporate network that has affected some customer files. Customers have been informed and are taking recommended actions, with the support of Telvent teams. Telvent is actively working with law enforcement, security specialists and its affected customers to ensure the breach has been contained," Telvent said in a later statement to CBC News.
But no one, apparently, told the Canadian Cyber Incident Response Centre, the federal agency set up to respond to cyberattacks on critical infrastructure.
Documents indicate the first the agency even heard about the attack was a news report 10 days later, saying a "Canadian energy company" had been hacked.
Even then, it took the organization more than 24 hours to determine the Canadian company hit was Telvent.
The 2012 cyberattack successfully breached a Calgary-based supplier of control systems for electrical power grids, municipal water systems, public transit operations, and most of Canada’s major oil and gas pipelines. (Canadian Press)Part of the problem was the federal response centre wasn't open to respond to anything on weekends. In fact, it was only staffed during banker’s hours – eight hours a day, five days a week.
Whatever the cause, the Telvent embarrassment was hardly an anomaly.
Hundreds of pages of the agency’s internal emails and cyber “incident reports” paint an organization unable to deal with an almost constant hail of cyberattacks on government and industry.
The documents show the government was consistently slow to respond to what would become Canada’s worst cyberattack in the fall of 2010.
China-based hackers broke into the computer systems of at least three federal departments, seven Bay Street law firms, and two multinational corporations – all involved in the ultimately unsuccessful corporate takeover of Saskatchewan’s Potash Corporation.
Documents show warning signs of a cyberattack throughout the fall of 2010, but no evidence of a co-ordinated response to it.
In mid-January 2011, all hell began to break loose with attack alerts pouring in daily.
Emails on Jan. 31 indicated the Finance Department and Treasury Board were both being slammed with severe cyberattacks, including significant volumes of sensitive government data being stolen by computers in China.
U.S. offers help after massive cyberattack
But it wasn’t until three days later – and many meetings and a mountain of emails – that all of the computers at Finance, Treasury Board and Defence Research, also hit, were finally disconnected from the internet to prevent further loss of data.
Two weeks later, the first media reports about the massive cyberattack prompted the U.S. cyber response agency to offer “help and resources,” to its Canadian counterpart, and to inquire if there were ways to mitigate the damage.
In an extraordinary exchange of emails, top officials at the Canadian cyber agency spent an entire day debating whether to share information with the Americans offering to help.
Meanwhile, the attacks were far from over.
Documents show six weeks after the three departments were unplugged from the internet, another federal agency was “severely impacted by a cyber incident.”
On May 1, five more were hit, including the Privy Council, the prime minister’s department.
Documents show the attacks continued on an almost daily basis through the rest of 2011 and all of 2012.
Experts say most of the attacks on the federal government over the past two years were likely the work of hundreds of different hackers from various countries with a variety of reasons for causing mayhem.
For its part, the Cyber Response Centre issued an unusual report to government a year ago, all but pleading for help.
While the Harper government has long boasted about its “cyber strategy,” the report suggests those who had to implement it were not impressed.
The agency complained of “ambiguity of roles in an emergency,” and how it is “difficult to prioritize clients and services without clearly defined mission and mandate.”
It complained about an “aging” laboratory, and the high turnover of staff at the agency.
Last fall, Auditor General Michael Ferguson hammered the government for its much-touted cyber strategy.
Among many pages of scathing commentary, the federal spending watchdog found that over the past decade, successive governments have promised a lot more in cyber security than they have delivered.
Auditor general critical of federal cyber strategy
Most of the time, he said, the government did not seem to know how much money was available for cyber security, nor what it was being spent on.
The Cyber Response Centre, he concluded, was underfunded and otherwise ill-equipped to do its job.
All of which clearly frustrates security experts such as Canada’s former head of intelligence and counter-terrorism , Ray Boisvert.
In an interview with CBC, the recently retired CSIS boss says the growing cyber threats are “as important if not more important than terrorism now.”
He says the Cyber Response Centre is “a good start,” but the federal government will “have to do far more than that.”
“This government has invested some time and some money in this issue of late and I think it’s all very helpful.
“But we cannot be the soft underbelly of North America.”
Rafal Rohozinski of the SecDev Group is one of Canada’s leading cyber experts.
'I think frankly that it requires co-ordination at the upper levels of political authority.'—Rafal Rohozinski of the SecDev Group
He says Canada is lagging behind its allies in making cyber security a co-ordinated effort among all government agencies and the private sector.
“I think frankly that it requires co-ordination at the upper levels of political authority. There has to be a decision made by the Prime Minister's Office that cyber security matters.
“There has to be a national security advisory team that deals with this just like they deal with any other aspect of national security.”
Rohozinski says the Chinese attack on Telvent and its big utility customers is another wakeup call for Canada, and a reminder of what’s at stake in securing cyberspace.
“It certainly puts us in the position of military potential vulnerability if some of our core assets are penetrated … by a foreign power or entity that can sidestep the securities that we have built within them.”
Since the auditor general’s scathing report last year, the Harper government has increased funding for the Cyber Response Centre, at least enough to operate 15 hours a day, seven days a week.”
This week, Prime Minister Stephen Harper seemed to say all’s well in cyberspace.
Asked for his reaction to this week’s report fingering the Chinese for the cyberattack on Telvent, the PM said: “We are certainly aware of these kinds of security threats and risks that exist.
“We have professionals who constantly evaluate them and work with partners on addressing them.”
Corrections and Clarifications
- An earlier version of this story said Telvent had told its customers that hackers had also penetrated their computer systems. In fact, the company says it has no evidence hackers accessed its clients' systems. March 27, 2012 | 10:43 AM ET
Share Tools
Tories to invoke closure on 'superclosure' motion to curb debate, extend sitting hours by Kady O'Malley May. 22, 2013 9:18 AM Move to cut off debate could spark opposition to mount procedure-based protest against proposal to keep the House fires burning until midnight until June
Top News Headlines
- Video forensics: How easy would it be to fake a Rob Ford video?
- Two media outlets reported last week that they had seen a cellphone video of Mayor Rob Ford allegedly smoking crack, a claim that has gone global. If a video does surface, how easy would it be to determine its authenticity? CBC News asked video forensic analyst David McKay.
more »
- Tim Bosma memorial today in hall that hosted his wedding reception
- The widow of Tim Bosma, the Hamilton man killed after taking two strangers on a test drive in a truck he had listed for sale online, will say goodbye to her husband at a public memorial today in the same hall where they celebrated their marriage just three years ago. CBCNews.ca will livestream the event starting at 11 a.m. ET. more »
- Oklahoma residents begin to return home after deadly tornado
- Rescue workers raced to complete the search for survivors and the dead in the Oklahoma City suburb where a mammoth tornado destroyed countless homes, cleared lots down to bare red earth and claimed 24 lives, including those of nine children. more »
- Jimmy Kimmel cracks jokes about Toronto Mayor Rob Ford
- Toronto Mayor Rob Ford's woes over crack cocaine allegations are providing plenty of late-night TV fodder for Jimmy Kimmel, Jon Stewart and other comedians south of the border. more »
- How the weather info that storm chasers use can keep you safe
- Radar imagery and a stream of weather information are readily available to the public when severe weather bears down. more »
Must Watch
Latest Politics News Headlines
- Senate sends Duffy expense audit for 2nd internal review
- The Senate decided to send Senator Mike Duffy's audit report back to its internal committee for a second review, despite objections from the Liberal Senate leader, who argued the RCMP should be tasked with the job. New travel rules for senators will be announced today.
more »
- Harper in Peru for trade talks amid Senate expense scandal
- Prime Minister Stephen Harper will meet with business leaders and Peruvian politicians this morning as part of a four-day trip to South America that will focus on trade and bilateral relations, but is expected to be asked about the growing Senate expense scandal. more »
- Stockwell Day: Abolish the Senate? Build it up instead
- Not only is abolishing the Senate next to impossible, it's also a bad idea. An Upper Chamber filled with provincially-elected representatives would be far better and address a major flaw in Canada's parliamentary system. more »
- Tom Mulcair contacted by police about suspected bribe by ex-Laval mayor
- Federal NDP Leader Tom Mulcair says he was contacted by the provincial police anti-corruption squad in Quebec to discuss a suspected 17-year-old bribe offered to him. more »
- 'Very upset' Harper wants fast Senate spending reform
- Prime Minister Stephen Harper told the Conservative caucus this morning that he's "very upset" about the recent conduct of some senators and his own office, and he wants Senate spending rules tightened quickly. more »
The National
The House
- Questions mount for Harper and chief of staff Nigel Wright in Senate scandal May. 18, 2013 1:15 PM This week on The House, with Senators Wallin and Duffy now out of the Conservative caucus, we get reaction from NDP Ethics critic Charlie Angus. We also hear directly from Senator Patrick Brazeau who says the Conservatives have thrown him under the bus. Plus we speak with B.C. Premier Christy Clark after her stunning victory.
- Video forensics: How easy would it be to fake a Rob Ford video?
- Jodi Arias asks for 'second chance' during jail interview
- Tim Bosma memorial today in hall that hosted his wedding reception
- Oklahoma residents begin to return home after deadly tornado
- Children's mouths allegedly taped shut at N.S. school
- Microsoft unveils Xbox One
- Only 1 set of human remains found at Millard farm, police say
- Judge scolds 'flabby, sad generation' for skipping jury duty
- Yukon couple hold record for longest marriage in country


