• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCyber Saturday

SEC Breached, Billionaires Bash Bitcoin, Facebook Shares Russia Ads

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
September 23, 2017, 12:09 PM ET
Grand Sumo Championship
LAS VEGAS, NV - OCTOBER 7: A detail of brooms sweeping loose clay off the ring during the Grand Sumo Championship on October 7, 2005 at Mandalay Bay Events Center in Las Vegas, Nevada. This is the first time in 20 years that the Grand Sumo has come to the U.S. (Photo by Donald Miralle/Getty Images)Donald Miralle—Getty Images

An insidious attack trend has been catching my eye lately. It’s called the software supply chain attack.

The scheme goes like this: Hackers compromise a trusted software vendor, subvert its products with their own malicious versions, and then use the tainted formulation to infect customers — thereby bypassing internal security controls and easily spreading malware far and wide. Customers, careful to keep their software up to date, don’t think twice about downloading the latest iterations. That’s good digital hygiene, after all.

At least that’s what we’ve been trained to think. Cisco researchers exposed one of these sneaky incursions earlier this week. The hacking operation sabotaged CCleaner, a popular piece of computer cleaning software distributed by Avast, a Czech antivirus firm. (Morphisec, an Israeli cybersecurity startup, had discovered the compromise too.)

Here’s what happened: In August, some unknown hacking group inserted a backdoor into the CCleaner software, which was then dutifully installed on more than 700,000 machines. With that foothold, the attackers then attempted to drill down deeper into the networks of at least 18 big tech company targets, including Google, Intel, Microsoft, Samsung, HTC, and Cisco. Presumably, the intruders sought trade secrets.

This is only the most recent example of such an attack. Earlier this year hackers compromised MeDoc, a piece of accounting software developed by a Ukrainian tech firm, in order to spread a destructive strain of ransomware, dubbed NotPetya, through its update mechanism. The attack crippled operations at big companies, ranging from Danish shipping giant Maersk to U.S. pharma company Merck. Similarly, Kaspersky Labs, the lately besieged Russian cybersecurity firm, found a backdoor in server management software from the U.S. and South Korean tech firm NetSarang that infected hundreds of banks and other companies over the summer.

These supply-chain attacks fly in the face of commonly accepted principles of computer security — i.e., patch your systems early and often — and they undermine everyone’s trust in the software ecosystem. As the Cisco researchers note in their analysis, a product from an established vendor “rarely receives the same level of scrutiny” as one from an untrusted source. And as they warn in a follow-up post, these types of attacks now “seem to be increasing in velocity and complexity.”

The proliferation is cause for alarm. It’s hard to see how the situation will improve until everyone — even small-fry software vendors — takes responsibility and ups their digital defenses.

Robert Hackett

@rhhackett

robert.hackett@fortune.com

Welcome to the Cyber Saturday edition of Data Sheet, Fortune’sdaily tech newsletter. Fortune reporter Robert Hackett here. You may reach me via Twitter, Cryptocat, Jabber (see OTR fingerprint on my about.me), PGP encrypted email (see public key on my Keybase.io), Wickr, Signal, or however you (securely) prefer. Feedback welcome.

THREATS

SEC hacked. The top market regulator in the U.S. just disclosed a 2016 data breach that may have allowed hackers to obtain and trade on inside information. The SEC's financial filing database, called Edgar, had a vulnerability that the agency said it fixed "promptly," but not before attackers used it to gain access to sensitive corporate information. The breach has officials worried about the security of other government computer systems.

Equifax's ongoing fallout. The state of Massachusetts is suing the big-three credit bureau for failing to safeguard more than 140 million people's personal information. Officials expect the Consumer Financial Protection Bureau, a federal watchdog agency created in the wake of the 2008 financial crisis, also to punish the company. (By the way, Equifax's customer support team has been sending prospective victims to a fake phishing website.)

Facebook to clean up act. Facebook said it would share more than 3,000 Russia-linked political ads with congressional committees that are investigating Moscow's interference in the 2016 presidential election. CEO Mark Zuckerberg promised to improve the platform to prevent its technology from being abused in the future. Marc Rotenburg, president of the Electronic Privacy Information Center, argues in an op-ed for Fortune that Facebook should operate under the same laws that govern other media companies that sell political ads.

Nest flies the nest. Alphabet's connected home unit Nest debuted the Cam IQ Camera Outdoor, a rugged security camera that can recognize visitors' faces. The product, which costs $350, joins Nest's indoor camera as another sentinel to keep watch over customers' living quarters. Nest also introduced a connected doorbell that comes with a mini app-linked video camera.

Microsoft to add hack recovery. Microsoft is beefing up Windows 10 for businesses with tech that will automate certain tasks involved in recovering from security breaches. The addition should give companies a leg up in responding to digital intrusions, freeing security teams to focus on higher level strategy. Rob Lefferts, head of security for Windows, previewed the news exclusively with Fortune this week.

Bitcoin battered by billionaires. Ray Dalio, the world's most successful hedge funder (whose new book Fortune recently excerpted in the magazine), voiced his skepticism about so-called digital gold, calling the mania for it a "bubble." JPMorgan Chase CEO Jamie Dimon echoed this view, reiterating his longtimedistrust in a Friday interview in which he said the craze for cryptocurrencies will "end badly" (customer orders notwithstanding). In the face of the trash talk, Bitcoin's price briefly shot above $4,000, but has since fallen by about $500 (as it has many times before).

North Korean dictator Kim Jong-un may have an impressive vocabulary (he recently called President Donald Trump a "dotard"), but his regime's record of paying off parking tickets leaves much to be desired.

Share today's Data Sheet with a friend:

http://fortune.com/newsletter/datasheet/

Looking for previous Data Sheets? Click here.

ACCESS GRANTED

The toymaker wasn’t recording or saving Dreamhouse owners’ voice commands — much less combining them into a system that could learn and evolve, otherwise known as natural language processing. "You want to know, how many times did she [the owner] talk to it, what questions does she ask that you don’t answer?" says [Mattel CEO Margo] Georgiadis. For an executive schooled at Google, whose parent company Alphabet makes $90 billion a year primarily by pumping data into algorithms and using it to serve up ads, this lapse was unfathomable.

—An excerpt from Fortune senior writer Michal Lev-Ram's latest feature detailing the digital transformation of toymaker Mattel under the reign of ex-Googler Margo Georgiadis. The new chief is interested in collecting more voice data from its playthings, raising privacy and security concerns.

FORTUNE RECON

Mark Zuckerberg Outlines Facebook's Plan to Fight Russian Election Hacking, by John Patrick Pullen

Is the New Apple iPhone Designed for Cyber-Safety?, by The Conversation's Arun Vishwanath

Inside RT, Russia's Kremlin-Controlled Propaganda Network, by David Z. Morris

California Planned on Strengthening Internet Privacy. It Didn't., by Chris Morris

OkCupid and SparkNotes Founders Take on Slack With Encrypted Chat, by Robert Hackett

Cryptocurrencies May Be a Dream Come True for Cyber Extortionists, by The Conversation's Nir Kshetri

Whoops: ISIS Backers Reveal Location on Instagram, by Jeff John Roberts

ONE MORE THING

How to write about the future. When crafting a narrative about centuries to come, perhaps the best place to start is not with what will change, but what remains the same. That was sci-fi author Annalee Newitz's approach in laying out her new novel Autonomous, set in 2144. By looking into the past, Newitz gleaned human universals. "We’re still arguing over evolution; we still ride in trains and take photographs; we still have radical youth rebellions focused on free love, weird technology, and vegetarianism," she says. Her vision of the future has differences, of course. In it, nation states have fallen and AI has risen up, for instance.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Investingspace
Alphabet poised for another paper gain as SpaceX valuation jumps
By Edward Ludlow and BloombergDecember 14, 2025
3 hours ago
Chess master and co-founder of Chess.com, Danny Rensch
SuccessEntrepreneurs
Chess.com cofounder says it took a pinch of delusion to bring the traditional game online—and it’s a ‘requirement for every successful entrepreneur’
By Emma BurleighDecember 14, 2025
9 hours ago
JPMorganChase CEO Jamie Dimon says AI will eliminate jobs—and that soft skills will be more important than ever.
Future of WorkTech
Jamie Dimon says soft skills like emotional intelligence and communication are vital as AI eliminates roles
By Nino PaoliDecember 14, 2025
11 hours ago
AIchief executive officer (CEO)
Microsoft AI boss Suleyman opens up about his peers and calls Elon Musk a ‘bulldozer’ with ‘superhuman capabilities to bend reality to his will’
By Jason MaDecember 13, 2025
21 hours ago
InvestingStock
There have been head fakes before, but this time may be different as the latest stock rotation out of AI is just getting started, analysts say
By Jason MaDecember 13, 2025
1 day ago
Politicsdavid sacks
Can there be competency without conflict in Washington?
By Alyson ShontellDecember 13, 2025
1 day ago

Most Popular

placeholder alt text
Economy
Tariffs are taxes and they were used to finance the federal government until the 1913 income tax. A top economist breaks it down
By Kent JonesDecember 12, 2025
2 days ago
placeholder alt text
Success
Apple cofounder Ronald Wayne sold his 10% stake for $800 in 1976—today it’d be worth up to $400 billion
By Preston ForeDecember 12, 2025
2 days ago
placeholder alt text
Success
40% of Stanford undergrads receive disability accommodations—but it’s become a college-wide phenomenon as Gen Z try to succeed in the current climate
By Preston ForeDecember 12, 2025
2 days ago
placeholder alt text
Uncategorized
Transforming customer support through intelligent AI operations
By Lauren ChomiukNovember 26, 2025
18 days ago
placeholder alt text
Economy
The Fed just ‘Trump-proofed’ itself with a unanimous move to preempt a potential leadership shake-up
By Jason MaDecember 12, 2025
2 days ago
placeholder alt text
Success
Apple CEO Tim Cook out-earns the average American’s salary in just 7 hours—to put that into context, he could buy a new $439,000 home in just 2 days
By Emma BurleighDecember 12, 2025
2 days ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.