Former NSA Contractor Stole 50,000 Gigabytes of Data

NYT’s/WASHINGTON — Investigators pursuing what they believe to be the largest case of mishandling classified documents in United States history have found that the huge trove of stolen documents in the possession of a National Security Agency contractor included top-secret N.S.A. hacking tools that two months ago were offered for sale on the internet.

The criminal complaint filed September 13, 2016 is here.

They have been hunting for electronic clues that could link those cybertools — computer code posted online for auction by an anonymous group calling itself the Shadow Brokers — to the home computers of the contractor, Harold T. Martin III, who was arrested in late August on charges of theft of government property and mishandling of classified information.

Harold T. Martin III and his wife Deborah Shaw in an undated photo. Credit Deborah Shaw

But so far, the investigators have been frustrated in their attempt to prove that Mr. Martin deliberately leaked or sold the hacking tools to the Shadow Brokers or, alternatively, that someone hacked into his computer or otherwise took them without his knowledge. While they have found some forensic clues that he might be the source, the evidence is not conclusive, according to a dozen officials who have been involved in or have been briefed on the investigation.

All spoke on condition of anonymity because they were not authorized to discuss it publicly.

An anonymous hacker group, calling itself the Shadow Brokers, announced in August a sale of computer codes stolen from the National Security Agency.

Mr. Martin, an enigmatic loner who according to acquaintances frequently expressed his excitement about his role in the growing realm of cyberwarfare, has insisted that he got in the habit of taking material home so he could improve his skills and be better at his job, according to these officials. He has explained how he took the classified material but denied having knowingly passed it to anyone else.

 

“As a contractor, he gets to see a slice of the overall picture,” said one person familiar with the exchanges, summarizing Mr. Martin’s explanation. “He wanted to see the overall picture so that he could be more effective.”

Mr. Martin’s home in Glen Burnie, Md., with car parked outside. Credit Nate Pesce for The New York Times

The material the F.B.I. found in his possession added up to “many terabytes” of information, according to court papers, which would make it by far the largest unauthorized leak of classified material from the classified sector. That volume dwarfs the hundreds of thousands of N.S.A. documents taken by Edward J. Snowden in 2013 and exceeds even the more voluminous Panama Papers, leaked records of offshore companies obtained by a German newspaper in 2015, which totaled 2.6 terabytes. One terabyte of data is equal to the contents of about one million books.

Image result for harold t martin nsa  NBCNews

F.B.I. agents on the case, advised by N.S.A. technical experts, do not believe Mr. Martin is fully cooperating, the officials say. He has spoken mainly through his lawyers, James Wyda and Deborah Boardman of the federal public defender’s office in Baltimore. They declined to comment before a detention hearing set for Friday in federal court.

Investigators discovered the hacking tools, consisting of computer code and instructions on how to use it, in the thousands of pages and dozens of computers and data storage devices that the F.B.I. seized during an Aug. 27 raid on Mr. Martin’s modest house in suburban Glen Burnie, Md. More secret material was found in a shed in his yard and in his car, officials said.

The search came after the Shadow Brokers leak set off a panicked hunt at the N.S.A. Mr. Martin attracted the F.B.I.’s attention by posting something on the internet that was brought to the attention of the N.S.A. Whatever it was — officials are not saying exactly what — it finally set off an alarm.

The release of the N.S.A.’s hacking tools, even though they dated to 2013, is extraordinarily damaging, said Dave Aitel, a former agency employee who now runs Immunity Inc., an information security company.

“The damage from this release is huge, both to our ability to protect ourselves on the internet and our ability to provide intelligence to policy makers and the military,” Mr. Aitel said.

The N.S.A.’s hacking into other countries’ networks can be for defensive purposes: By identifying rivals’ own hacking methods, the agency can recognize and defend against them, he said. And other countries, with some of the N.S.A.’s tools now in hand, can study past hacks and identify the attacker as the N.S.A., learn how to block similar intrusions, or even decide to retaliate, Mr. Aitel said.

Mr. Martin, 51, a Navy veteran who was completing a Ph.D. in information systems at the University of Maryland, Baltimore County, has worked for several of the contracting companies that help staff the nation’s security establishment. After stints at the Computer Sciences Corporation and Tenacity Solutions, where he was assigned to the Office of the Director of National Intelligence, he joined Booz Allen Hamilton in 2009. He worked on that firm’s N.S.A. contract until 2015, when he was moved to a different Pentagon contract in the area of offensive cyberwarfare.

He has long held a high-level clearance and for a time worked with the N.S.A.’s premier hacking unit, called Tailored Access Operations, which breaks into the computer networks of foreign countries and which developed the hacking tools later obtained by the Shadow Brokers. According to one person briefed on the investigation, Mr. Martin was able to obtain some of the hacking tools by accessing a digital library of such material at the N.S.A.

theshadowbrokers @shadowbrokerss

@cyberwar@guardian@VICE@mashable@wired@kaspersky@symantec Equation Group – Cyber Weapon Auction http://pastebin.com/NDTU5kJQ 

Courtesy of WikiLeaks: Here Comes Obama’s Emails

WikiLeaks Releases First Batch Of Barack Obama’s Emails

WikiLeaks has released a new batch of leaked emails, containing messages sent to and from Barack Obama prior to his inauguration.

The emails were sent from what WikiLeaks claims is a secret address, “[email protected].”

****

Breitbart: The top email in today’s leak contains a message from John Podesta about a potential invitation from President George W. Bush to the “President-Elect.” Podesta sent the email while votes were still being cast on November 4th.

The emails show a transition plan being worked on before the 2008 election had taken place. According to an attached memo in one of the emails, Obama was already discussing his transition to office with members of the Bush Administration, including then-Treasury Secretary Hank Paulson, prior to the election.

As you have observed in your interactions with Secretary Paulson, he is apparently eager to involve you and your transition team extensively in his policy choices following the election.

Another attached memo acknowledges that it was unusual to start the transition process so soon.

We are now at the point of deciding how to staff economic policy during the transition, who should be the point of contact with Treasury and how to blend the transition and campaign economic policy talent.

Normally these decisions could be made after the election, and ideally after the selection of a National Economic Advisor, but, of course, these are not normal times.

One of the emails, from Citigroup executive and later Assistant to the President Michael Froman, shows a proposed “diversity list” for the cabinet. In Froman’s own words, the lists consist of :

A list of African American, Latino and Asian American candidates, divided between Cabinet/Deputy and Under/Assistant/Deputy Assistant Sectetary levels, as well as lists of senior Native Americans, Arab/Muslim Americans and Disabled Americans. We have longer lists, but these are candidates whose names have been recommended by a number of sources for senior level jobs in a potential Administration.

A list of women, similarly divided between candidates for Cabinet/Deputy and other senior level positions.

The lists can be viewed in full at the “attachements” tab here.

Subject: Re: G-20
2008-11-04 22:05 2016-10-19 [email protected] [email protected]
Subject: RE: G-20
2008-11-04 21:59 2016-10-19 [email protected] [email protected]
Subject: G-20
2008-11-04 21:39 2016-10-19 [email protected] [email protected]
Subject: Diversity
2008-10-06 22:38 2016-10-18 [email protected] [email protected]
Subject: Economic Staffing Decisions
2008-10-30 19:17 2016-10-17 [email protected] [email protected]
Subject: Re: Economic Staffing Decisions
2008-10-31 01:47 2016-10-17 [email protected] [email protected]
Subject: Contact Information
2008-10-06 15:41 2016-10-13 [email protected] [email protected]
What is curious however is the domain of Ameritech.com…..seems there may be a connection here…..thoughts?
ameritech

ABOUT US

Our vision takes into account a broad range of solution that improve healthcare by focusing on the physicians. In today’s $1.6 trillion healthcare market, 80% of all healthcare costs are the direct result of physician-driven decision. The best way for healthcare providers to improve their revenue by developing a strong relationship with an information partner whom they can trust… and also can help them to manage their entire information infrastructure.

We provide easy-to use, affordable, intuitive interface, scalability solution. It automates and supports the administrative, billing and business process of the practices, which helps to increase your revenue and reduce your cost by providing comprehensive list of services. Ameritech provide fill comprehensive solutions to all aspects of the healthcare industry.

US Office

Ameritech Inc
1 Rockefeller Plaza
New York
NY10020.

Tel: 917-639 4063
Fax: 917-639 4005

Dubai Office

Ameritech Inc
Dubai Airport Free Zone East Wing 3, 4th Floor, P.O. Box 54620, Dubai, UAE.

Indian Office

Amerimedtech India Pvt. Ltd.
Tek Towers, Ground Floor,
11, Rajiv Gandhi Salai (OMR),
Okkiyam Thoraipakkam,
Chennai600 097.

Tel: 044-30226600, 044-30439900, 044-30439901, 044-30439902, 044-30439903+ 91-44-64500233

Dirty Production of NHS Drugs Helps Create Superbugs

Drug resistance

Revealed: How dirty production of NHS drugs helps create superbugs

War in Yemen is Actually with Iran

Reuters: A 72-hour truce in Yemen came under pressure on Thursday when missiles fired from Yemen injured civilians in southern Saudi Arabia, according to an Arab coalition which launched air strikes that Iran-allied Houthi fighters said killed three people.

Exclusive: Iran steps up weapons supply to Yemen’s Houthis via Oman – officials

 

Reuters: Iran has stepped up weapons transfers to the Houthis, the militia fighting the Saudi-backed government in Yemen, U.S., Western and Iranian officials tell Reuters, a development that threatens to prolong and intensify the 19-month-old war.

The increased pace of transfers in recent months, which officials said include missiles and small arms, could exacerbate a security headache for the United States, which last week struck Houthi targets with cruise missiles in retaliation for failed missile attacks on a U.S. Navy destroyer.

Much of the recent smuggling activity has been through Oman, which neighbors Yemen, including via overland routes that take advantage of porous borders between the two countries, the officials said.

That raises a further quandary for Washington, which views the tiny Gulf state as a strategic interlocutor and ally in the conflict-ridden region. A senior U.S. administration official said that Washington had informed Oman of its concerns, without specifying when.

“We have been concerned about the recent flow of weapons from Iran into Yemen and have conveyed those concerns to those who maintain relations with the Houthis, including the Omani government,” the official told Reuters.

Oman denies any weapons smuggling across its border, and its officials could not be reached for comment. Yemeni and senior regional officials say the Omanis are not actively involved with the transfers, but rather turning a blind eye and failing to aggressively crack down on the flow.

In an interview with Saudi newspaper Okaz last week, Omani Foreign Minister Yousef bin Alwi said:

“There is no truth to this. No weapons have crossed our border and we are ready to clarify any suspicions if they arise.”

The Iran-allied Houthis gained a trove of weapons when whole divisions allied to former Yemen President Ali Abdullah Saleh sided with them at the start of the war last year. But Saudi Arabia and Yemen’s exiled government say they also receive substantial amounts of weapons and ammunition from Iran. Tehran views the Houthis as the legitimate authority in Yemen, but denies it supplies them with weapons.

Some Western officials have been more skeptical of the view that the Houthis are receiving large-scale support from Iran.

The U.S. and Western officials who spoke to Reuters about the recent trend in arms transfers said it was based on intelligence they had seen but did not elaborate on its nature. They said the frequency of transfers on known overland smuggling routes had increased notably, though the scale of the shipments was unclear.

Even U.S. officials warning of Iran’s support for the Houthis acknowledge intelligence gaps in Yemen, where the U.S. posture has been sharply reduced since the start of the conflict. The sources all declined to be identified because of the sensitivity of the issue.

“We are aware of a recent increased frequency of weapons shipments supplied by Iran, which are reaching the Houthis via the Omani border,” a Western diplomat familiar with the conflict told Reuters.

Three U.S. officials confirmed that assertion.

One of those officials, who is familiar with Yemen, said that in the past few months there had been a noticeable increase in weapons-smuggling activity.

“What they’re bringing in via Oman are anti-ship missiles, explosives…, money and personnel,” the official said.

Another regional security source said the transfers included surface-to-surface short-range missiles and small arms.

A senior Iranian diplomat confirmed there had been a “sharp surge in Iran’s help to the Houthis in Yemen” since May, referring to weapons, training and money.

“The nuclear deal gave Iran an upper hand in its rivalry with Saudi Arabia, but it needs to be preserved,” the diplomat said.

Washington’s Gulf allies have warned that U.S. President Barack Obama’s rapprochement with Tehran through the landmark nuclear deal signed last year will only embolden Iran in conflicts in Syria, Lebanon, Yemen and elsewhere.

U.S. LOOKING INTO MISSILE ORIGIN

The increase in transfers comes as the civil war drags on and threatens to pull the United States deeper into a conflict that has killed 10,000 people and which pits two regional powers, Saudi Arabia and Iran, against each other. A U.N.-brokered 72-hour ceasefire went into effect on Wednesday.

Since the beginning of the war, the Houthis have used short-range Scud missiles, and the United Nations says they have also used surface-to-air missiles, improvised to operate as surface-to-surface rockets against Saudi Arabia.

But a suspected Houthi missile attack against a United Arab Emirates vessel in a strategic Red Sea shipping lane this month, as well as the attempted strikes against the U.S. warship, raise worries about the rebels’ capability to launch bolder attacks.

The Houthis have denied attacking the USS Mason.

BBC: The Saudi-led military coalition backing the government in the war in Yemen has accused Houthi rebels of repeatedly violating a ceasefire.

A statement said the rebels had breached it more than 40 times along the border with Saudi Arabia.

The UN-brokered truce, meant to last three days, began on Wednesday just before midnight.

Rebels, meanwhile, said an air strike on their territory had killed three civilians.

The UN had hoped that the truce might be extended and lead to renewed peace talks.

Rockets were fired by Houthi rebels at Jazan and Najran in Saudi Arabia, the coalition said in a statement.

“Forty-three violations were committed along the border… in which snipers and various weapons were used, including missiles,” it said.

The Houthis said a coalition air strike on Thursday killed three civilians in northern Saada province. They also said they had launched attacks across the border on Saudi military camps over the past two days.

The war has killed nearly 7,000 people, mostly civilians, the UN says.

The coalition, which backs Yemen’s exiled president, has been fighting the rebels and their allies since March 2015, when a Saudi-led air campaign began.

Map of control of Yemen (10 October 2016)

Five previous ceasefires have broken down within a short time.

The announcement of the ceasefire followed an international outcry over the deaths of 140 people in a Saudi air strike that hit a funeral gathering in Sanaa.

Saudi officials said they had targeted the wrong site by mistake due to “bad information”.

The conflict and a blockade imposed by the Saudi-led coalition have triggered a humanitarian disaster, leaving millions of people homeless and hungry and 80% of the population in need of aid.

Mediterranean Sea is Getting Crowded with Russian Navy

Russia possibly mapping underwater internet cables in Mediterranean

WT: Approximately one year ago, the Russian navy caused quite a stir by hanging around internet cables in the Atlantic for some period of time.

Steffan Watkins, an open-source intelligence analyst who monitors Russian ship movements, said the Russian navy sends vessels such as Yantar to the region to check on existing U.S. underwater sensors or cables that have been detected previously. The ships also search for new equipment on the sea floor that would reveal U.S. operations.

Steffan Watkins, an open-source intelligence analyst who monitors Russian ship movements, said the Russian navy sends vessels such as Yantar to the region to check on existing U.S. underwater sensors or cables that have been detected previously. The ships also search for new equipment on the sea floor that would reveal U.S. operations.

The accusation was the Russians were mapping the cables in order to be able to sever them in times of conflict.

The Russian fleet in the Mediterranean seems to be doing the same thing this week over cables off the Syrian coast.

News.com.au writes, “Author and military analyst H.I. Sutton is one of several observers who have noted the unusual activity of a suspected Russian survey ship, the Yantar, in waters between Cyprus, Syria, Lebanon and Turkey in recent weeks.

It’s reported positions have been coinciding with the tracks of three major undersea fibre-optic cables. Mr Sutton’s blog suggests the extremely slow speed and frequent stopping of the ship suggest it could be deploying a submersible to the sea floor.”

If internet cables were severed that were supporting Western information flow, this could cause great economic disruption and take a very long time to repair, especially in time of war.

It seems likely that Russia wants this capability to inflict great damage on the European and American economies if need be.

Another possibility is that the Russian navy could be deploying devices to monitor information through the cables for espionage reasons.

(Bloomberg) — U.K. warships are monitoring a Russian aircraft-carrier group sailing past Britain’s eastern coast to the Mediterranean Sea to supplement President Vladimir Putin’s forces in the region, as international condemnation mounts of Russia’s military campaign in Syria.

A photo taken from a Norwegian surveillance aircraft shows a group of Russian navy ships in international waters off the coast of Northern Norway on October 17, 2016. 333 Squadron, Norwegian Royal Airforce/NTB Scanpix/Handout via Reuters ATTENTION EDITORS - THIS IMAGE WAS PROVIDED BY A THIRD PARTY. FOR EDITORIAL USE ONLY. NORWAY OUT.A photo taken from a Norwegian surveillance aircraft shows a group of Russian navy ships in international waters off the coast of Northern Norway on October 17, 2016. 333 Squadron, Norwegian Royal Airforce/NTB Scanpix/Handout via Reuters

The deployment signals Putin’s determination to assert Russian interests as U.S. and European leaders accuse him of war crimes and dangle the threat of sanctions in response to the bombing of Aleppo by Russian warplanes.

Putin floated a possible extension of a cease-fire for the besieged Syrian city during a late-night meeting in Berlin on Wednesday with French President Francois Hollande and German Chancellor Angela Merkel that she portrayed as testy. Merkel and Hollande will meet again in Brussels on Thursday for a two-day summit of the EU’s 28 leaders that will consider a common response to Russia’s actions in support of Syrian President Bashar Al-Assad.

“We must show a robust and united European stance in the face of Russian aggression,” U.K. Prime Minister Theresa May told reporters as she arrived for her first summit. While Britain is leaving the EU, until it does “it’s vital that we work together to continue to put pressure on Russia to stop its appalling atrocities, its sickening atrocities in Syria,” she said.

May’s comments hint at the growing outrage over the bombing by Russian and Syrian forces of Aleppo, where some 275,000 inhabitants remain trapped. Syria’s government opened two crossings for fighters who want to leave the rebel-held eastern part of the contested city, a day after announcing a three-day humanitarian pause to its offensive.

Northern Fleet

Russia’s Northern Fleet, based at Severomorsk near the Finnish border, said last week that a naval group had set out for the northeast Atlantic en route to the Mediterranean “to ensure naval presence in the important areas” of the seas, according to the TASS news agency. The ships include the Admiral Kuznetsov, Russia’s only aircraft carrier.

“When these ships near our waters we will man-mark them every step of the way,” U.K. Defense Secretary Michael Fallon said in an e-mailed statement on Thursday. “We will be watching as part of our steadfast commitment to keep Britain safe.”

Russia said last month that its permanent naval group already stationed in the Mediterranean numbers about 10 warships and support vessels. Igor Konashenkov, a Defense Ministry spokesman in Moscow, declined to comment on the additional deployment.

Russian Responsibility

Speaking after the Berlin talks that stretched into early Thursday, Putin said Russia would halt its bombing of Aleppo as long as “terrorist forces” aren’t active. At a separate news conference alongside Merkel, Hollande said Putin didn’t specify how long such a cease-fire might last. “We hope it’s as long as possible” to allow for humanitarian aid to reach all parts of the city, he said.

European foreign ministers will work on getting aid to the area, which would “at least be a first step that we haven’t seen in a long time,” Merkel said. “It was right to use this blunt language” in the talks with Putin because “Russia bears a clear responsibility in Syria, including exerting influence over” Assad, the German leader said.

Merkel and Hollande kept the threat of sanctions against Russia on the table, while saying the focus had to be on helping civilians in Aleppo.

Hollande said that at best the European Union could target individuals, while Merkel limited herself to saying that “you can’t deny yourself the option.” Either way, any sanctions would require the approval of all 28 member states and the most ardent support for such an approach came from the U.K, which has voted to leave the bloc. Russia already is under EU and U.S. sanctions for its encroachment on Ukraine.

“The conclusion in the European Union is that we don’t believe in new sanctions at this phase because we already have sanctions and these run until the end of January,” Finnish Prime Minister Juha Sipila said in an interview in Helsinki on Wednesday. “In December or January we will have a discussion about the future of sanctions.’’

Minsk Accord

The Syria talks followed a discussion on Ukraine that was also attended by Ukrainian President Petro Poroshenko. Merkel and Poroshenko said the four leaders agreed to work on a “road map” of measures to advance last year’s Minsk accords for ending the conflict in eastern Ukraine between government forces and Russian-backed separatists.

In Brussels, Estonian Prime Minister Taavi Roivas, whose country borders Russia, said EU leaders must deliver “a very clear message to both the Syrian regime and its allies, mainly Russia.” He compared Aleppo with the Chechen capital, Grozny, that was reduced to rubble by Russian aerial bombing in the 1990s. “This is absolutely unacceptable,” Roivas said.