In recent days, especially following the order from Barack Obama, the President of the United States, to expel 35 diplomats and staff from Russian agencies in the U.S. and impose certain sanctions against Russia, the discussion of cybersecurity and the defensive capabilities of governments has returned to the forefront of media coverage. This article begins with a brief discussion of the generalities of cyber attack systems, illustrating how cyber attackers utilize various methods to achieve their objectives. It then addresses the application of diplomacy in the specific case of Russian cyber attacks on the U.S. and the political deadlock this issue has created between the leaders of Russia and the U.S. The most common cyber crimes, according to a study conducted by Verizon on types of cyber crimes, include phishing—where the goal is to deceive individuals to install malware on their computers and gain control over them for a large-scale cyber attack. For instance, an email is sent to you that appears to be from your bank, asking you to click a link to change or confirm something. After clicking, a page opens that looks very similar to your bank's website, but in that brief moment, malware is installed on your computer, turning it into a pawn in the hackers' malware chain. A Verizon study shows that 23% of people are easily deceived by phishing emails. Identity theft is another common method in cyberspace. In the first quarter of 2015 in the U.S., the number of identity theft victims increased by 31% compared to the same period the previous year, reaching 32,058 individuals. The primary goal of identity theft is financial and economic, stealing information related to access to individuals' bank and credit accounts. Hacking—Verizon's study indicates that within three months, 285 million individuals' information was made available to hackers (an average of 9 cases per second). Nearly one in four of these incidents is perpetrated by individuals within the system (insider employees). In fact, current or former employees of a company or database may attempt to steal information from the customers of that institution. Hacking and national security—another action hackers can undertake, which has more national security implications, is infiltrating service systems such as medical, energy, or any similar system that relies on computer systems to operate and provide services. On Friday, December 30, an event in Vermont triggered a state of readiness for cyber defense. In this incident, one of the operations attributed to Russian hackers, codenamed Grizzly Steppe, attempted to hack one of the computers in the state's power supply system. Although this code was not used extensively enough to disrupt the system, and only a small trace of it was observed, it raised concerns about how hacking such systems could potentially halt power supply systems and subsequently disable computer systems like medical and emergency services that depend on a full energy supply, creating a national disaster. In this particular case in Vermont, the issue ended with the discovery of malware on a computer that did not play an active role in the power supply network, but the situation could have been much more extensive and was therefore considered very alarming. The tracking of this malware shortly after the announcement of the expulsion of diplomats and sanctions against Russia has once again directed attention towards Russia. According to sources that are no longer classified, U.S. anti-espionage systems have access to the computer infrastructures of over 60 countries that have previously been hacked by various hackers, studying how they were hacked, tracking patterns and methods of hacking, and can gather important clues about the perpetrators. What is the content of the cyber system? The content of cyber systems is a vast array of diverse information, including personal, credit, banking, commercial, industrial, medical, technological, political, decision-making, military, and security information. The smallest piece of personal information pertains to an individual's identity. Identity information can be stolen, allowing another person to assert their existence elsewhere in the country or world. Any actions taken by that fraudulent individual in any legally actionable context will legally fall on the individual whose information was stolen, and until they can prove they have not committed any wrongdoing, they are responsible before the law. In some cases, individuals exploit this information for blackmail and extortion. Stolen information from hundreds of thousands of customers of a retail store is sold on the internet by the same hackers or returned to the store after receiving a ransom. Information from credit card companies and banks, as well as individuals' medical information, is similarly misused and traded. To effectively counter such levels of cyber threats, the most effective solution is to have software capable of timely detecting and neutralizing suspicious activities. Thus, two types of expertise are needed: hardware expertise and software expertise. Perhaps this is why cybersecurity is compared to the construction and protection of a bridge in some respects, as both result from advanced engineering operations and precise calculations. In peacetime, no one attacks bridges; criminals and gangs may graffiti or vandalize the bridge walls, while cyber terrorists write slogans on websites aligned with their political existence or promote their terrorist group's goals after cyber attacks. Such events in the computer and internet realm are performed for self-display, power demonstration, and assertion of existence. For example, when a newspaper's website is attacked by hackers and even revolutionary slogans are written on it, it is merely a display of power and a declaration of opposition. Shortly after, the situation returns to normal, and the newspaper's website is back under the control of its owner. Young hackers pursue a form of personal and personality gratification in their work. This is where the work of hackers diverges from bridge construction, as no one seeks adventure in building a bridge. Unlike bridges, which rarely have network connections, the cyber world is interconnected and linked. Cyber attacks cannot be precisely traced and tracked. Every virus comes from a path. An unsuccessful attack by a virus may have no connection to another attack coming from a different direction, but the environment and operation of it, as well as the hidden mindset behind it, indicate a similar and continuous thought process. The attack of worms and viruses on internet networks and personal computers began in the 1980s. In the first quarter of 2015, the rate of malware attacks and computer infections worldwide was about 36%. Norway had the lowest at 20%, while China had the highest at 48% in terms of malware infection. Now these figures have undergone fundamental changes. The problem arises when governments and diplomatic entities are involved, especially when hackers attack from outside a country and their traces can be pursued. In such cases, the issue becomes transnational and international, bringing in Interpol and even intelligence and counterintelligence organizations. The structure of attack and defense—To attack a bridge, a form of physical presence or mass demonstration, bombing, or airstrike is necessary; however, in cyberspace, the attack occurs remotely, and in many cases, the address that appears to have conducted the attack may not be the actual attacker. Everything is controlled from a center and remotely, while we only witness the results of the attack without the attack designer's computer identity being easily identifiable to non-specialists. The capability of chain connectivity in computer science enables the use of several hacked computers without their owners' knowledge in a cyber attack network. This connection is also referred to as a botnet or zombie army, and it often sends spam messages using the name and email of the hacked computer's owner. The chain connectivity of computers allows for distributed denial-of-service attacks against hypothetical targets. In late 2012 and early 2013, an Iranian group was able to block access to several banking websites for a period as a protest through distributed denial-of-service attacks that reached a volume of 120 gigabytes. A command and control center oversees this chain for cyber attacks, and therefore, if the command center can be disabled, the attacking system will cease to function. There are software tools to detect how a computer has been utilized in such a chain without the owner's knowledge, but using and analyzing the reports generated is not simple for someone lacking sufficient technological knowledge and programming language skills. Defense at the state level—When the capacity for cyber attacks targets larger objectives than one or several personal computers, and in other words, when the target is 'strategic,' a cyber army will be needed, similar to real warfare between nations. This war requires a group of specialists ranging from operators to designers, programmers, and producers of software and hardware. In fact, hardware equates to military weapons, and computer knowledge is akin to operational command knowledge. Naturally, the production of suitable hardware and software for cyber defense is classified as security and defense intelligence. Most buyers of personal computers and laptops sign a document upon purchase, committing not to export that computer to other countries after buying it in an advanced industrial country. Aside from export and import issues, there may also be a security concern. Some of these computers can be used in military, missile, and even nuclear industries or manipulated through software and hardware for such purposes. Naturally, the power to produce such sensitive devices is limited to nations at very advanced technological levels. However, in the free world, universities are open to students and researchers, and consequently, outstanding students from countries classified under hardware export bans study in such universities, enriching the scientific resources of research and development centers in return. Many of these graduates come from countries like China, Japan, Israel, India, Russia, Iran, and some Eastern European countries and have a significant following in the international scientific market. Major cyber defense centers require these specialties and strive to retain such expertise for themselves. This topic bears a strong resemblance to weapon production in armies, which can have both military-defensive and commercial aspects. The application of diplomacy and political leverage in cybersecurity—During the U.S. presidential elections, Russia was accused of hacking the documents of both the Democratic and Republican parties and then only providing the Democratic Party's documents to WikiLeaks to influence the election process against the Democratic candidate. Voter opinions were also influenced by 200 newly created news sources that spread false news, ultimately affecting the election outcome. President Obama promised to address this issue and take action before the end of his presidency. In the last days of 2016, President Obama took a new step in response to Russian cyber threats by ordering the expulsion of 35 Russian diplomats and officials from the United States and imposing new sanctions against Russia. According to this punitive package, 35 Russians suspected of espionage were expelled, and sanctions were imposed on major Russian security and intelligence entities; two Russian compounds in Maryland and New York were closed due to their involvement in espionage activities. Additionally, several Russian hackers are wanted by the FBI, including Yevgeny Mikhailovich Bogachev, 33, and Alexey Alexeyevich Bilan, 29, who are on the list of the most wanted cybercriminals. One is accused of hacking American institutions and stealing personal information, while the other is accused of infecting computers in over a hundred countries worldwide. The FBI has offered a reward of $100,000 for any information leading to their arrest. President Obama's action—As previously mentioned, Barack Obama issued an order to expel diplomats and close several Russian institutions in the U.S. Following this order, a Russian government plane on January 1 flew the accused diplomats out of the United States; however, President Obama's punitive package, in addition to what has been publicly announced, contains undisclosed and classified sections that have not been revealed to avoid compromising U.S. security intelligence sources. Obama's action, with less than twenty days remaining in his presidency, faced both supportive and opposing reactions. Although Congress generally welcomed it, many senators supported it and promised to intensify it during Donald Trump's presidency. Some media outlets took a more scrutinizing stance and even questioned the core story. For instance, Rolling Stone expressed doubt about the essence of the matter, likening it to the dubious information regarding Iraq's weapons of mass destruction that led to the Iraq War.
Cyber Threats and Diplomatic Limitations
Following President Obama's order to expel Russian diplomats and impose sanctions due to cyber threats, discussions on cybersecurity have intensified. The article outlines common cyber crimes, the implications of Russian hacking, and the political deadlock between the U.S. and Russia. This situation highlights the growing importance of cybersecurity in international relations.
👥 Key Players
⚡ Actions
📰 What Happened
U.S. expels Russian diplomats amid rising cybersecurity threats linked to Russian hackers.
- United States expel Russian diplomats
- United States impose Russia
- Russian hackers hack U.S. power supply system
💡 Why It Matters
📚 Background
U.S. actions against Russia highlight ongoing cybersecurity threats.
📝 Key Evidence
🏷️ Entities Mentioned
Translated from the original and edited for English readers. View original source →
Translation confidence: 85%