Lawmaker: US Senate, staff targeted by state-backed hackers

FILE - In this Feb. 4, 2015, file photo, Sen. Mike Enzi, R-Wyo., checks his phone as he arrives for a bipartisan lunch in the Kennedy Caucus Room on Capitol Hill in Washington. Oregon Sen. Ron Wyden is proposing new legislation that would allow the Senate’s Sergeant at Arms to spend taxpayer money protecting senators’ private email accounts and personal devices amid persistent anxieties over the digital security of the American midterm vote. (AP Photo/Susan Walsh, File)
FILE - In this Feb. 4, 2015, file photo, Sen. Mike Enzi, R-Wyo., checks his phone as he arrives for a bipartisan lunch in the Kennedy Caucus Room on Capitol Hill in Washington. Oregon Sen. Ron Wyden is proposing new legislation that would allow the Senate’s Sergeant at Arms to spend taxpayer money protecting senators’ private email accounts and personal devices amid persistent anxieties over the digital security of the American midterm vote. (AP Photo/Susan Walsh, File)

Foreign government hackers continue to target the personal email accounts of U.S. senators and their aides — and the Senate’s security office has refused to defend them, a lawmaker said.

Sen. Ron Wyden, an Oregon Democrat, said in a Wednesday letter to Senate leaders his office discovered “at least one major technology company” has warned an unspecified number of senators and aides that their personal email accounts were “targeted by foreign government hackers.” Similar methods were employed by Russian military agents who leaked the contents of private email inboxes to influence the 2016 elections.

Wyden did not specify the timing of the notifications, but a Senate staffer said they occurred “in the last few weeks or months.” The aide spoke on condition of anonymity because he was not authorized to discuss the issue publicly.

But the senator said the Office of the Sergeant at Arms , which oversees Senate security, informed legislators and staffers it has no authority to help secure personal, rather than official, accounts.

“This must change,” Wyden wrote in the letter. “The November election grows ever closer, Russia continues its attacks on our democracy, and the Senate simply does not have the luxury of further delays.” A spokeswoman for the security office said it would have no comment.

Wyden has proposed legislation that would allow the security office to offer digital protection for personal accounts and devices, the same way it does with official ones. His letter did not provide additional details of the attempts to pry into the lawmakers’ digital lives, including whether lawmakers of both parties are still being targeted.

Google and Microsoft, which offer popular private email accounts, declined to comment.

The Wyden letter cites previous Associated Press reporting on the Russian hacking group known as Fancy Bear and how it targeted the personal accounts of congressional aides between 2015 and 2016. The group’s prolific cyberspying targeted the Gmail accounts of current and former Senate staffers, including Robert Zarate, now national security adviser to Florida Sen. Marco Rubio, and Jason Thielman, chief of staff to Montana Sen. Steve Daines, the AP found.

The same group also spent the second half of 2017 laying digital traps intended to look like portals where Senate officials enter their work email credentials, the Tokyo-based cybersecurity firm TrendMicro has reported.

Microsoft seized some of those traps, and in September 2017 apparently thwarted an attempt to steal login credentials of a policy aide to Missouri Sen. Claire McCaskill, the Daily Beast discovered in July. Last month, Microsoft made news again when it seized several internet domains linked to Fancy Bear , including two apparently aimed at conservative think tanks in Washington.

Upcoming Events