RNC servers reportedly hacked by Russia-linked group
The Russian hacking group behind last year’s massive SolarWinds data breach recently targeted the Republican National Committee, a report said on Tuesday.
The RNC said that none of its data was accessed in the hack on its third-party provider, Synnex. Bloomberg News reported the breach earlier Tuesday, citing two people familiar with the matter.
“Over the weekend, we were informed that Synnex, a third party provider, had been breached. We immediately blocked all access from Synnex accounts to our cloud environment,” RNC Chief of Staff Richard Walters said in a statement.
“Our team worked with Microsoft to conduct a review of our systems and after a thorough investigation, no RNC data was accessed. We will continue to work with Microsoft, as well as federal law enforcement officials on this matter.”
According to Bloomberg, Russian government hackers breached the RNC’s computer systems last week. The report said it was unclear what if any data may have been seen or stolen.
The hackers are part of a group known as APT 29 or Cozy Bear, which has been linked to Russia’s foreign intelligence service, the report said.
The gang was previously accused of hacking the Democratic National Committee in 2016, and of carrying out the December 2020 SolarWinds intrusion, in which several US government agencies were infiltrated.
An RNC spokesman denied that its systems were breached, telling the outlet on Tuesday, “There is no indication the RNC was hacked or any RNC information was stolen.”
“We are investigating the matter and have informed DHS and the FBI,” the statement said.
According to Bloomberg, the hackers breached RNC servers via the California-based IT corporation Synnex.
In a press release, Synnex said “it is aware of a few instances where outside actors have attempted to gain access, through Synnex, to customer applications within the Microsoft cloud environment.”
“As our review continues, we are unable to provide any specific details,” the company said in a statement to Bloomberg. “As with any security issue, a full review of all companies, systems, third-party applications and related IT solutions must be completed before final determinations can be made.”
The reported RNC hack happened around the same time as Friday’s massive ransomware attack that targeted hundreds of US companies, which has also been tied to a Russia-linked cybercriminal gang called REvil.
It’s not clear if the reported hack on the RNC is connected in any way to the ransomware attacks.