Hackers and cybersecurityprofessionals may have noticed an open Wi-Fi network called “#Rewardsnotransoms” while last week in Las Vegas for the renowned cyber session Black Hat. It’s not the kind of place where a network would normally be left unprotected, but that was the point in this case.
Attendees were directed to a page for the State Department’s new resourcefulness offering up to $10 million to informers with state-backed hackersinformation by logging in or scanning the QR code on T-shirts and flyers distributed on the convention floor.
For the first time in the nearly four decades of the Reward for Justice programme, informants could elect to receive payments in cryptocurrency and reach out to the US government with sensitive information through a secure portal on the Dark Web.The announcement came after the State Department made it quietly last month, amid a flurry of other steps taken by the Biden administration to strengthen the country’s cybersecurity.
“There’s a lot of enthusiasm within our programme because we’re really pushing the envelope every chance we get to try and reach audiences, sources, and people who might have information that helps improve our national security,” a State Department official said in the first interview since the announcement.”It may have been nerve-wracking for some government agencies, but we’re going to keep pushing forward in a variety of ways.”
The Biden administration has accused Russian and Chinese hackers of breaching multiple US government agencies and departments in recent months.The goal of RFJ’s new reward is to elicit useful information from hackers who may know people involved in such operations. RFJ is targeting state-sponsored attackers who use to target protected computers such as those used by the US government, financial services, and a variety of infrastructure sectors.
“Something on the Dark Web that allows total anonymity and an initial level of security is probably more appropriate for those folks,” said a second State Department official, who declined to speak on the record about the officials’ comments.”So I think the name of the game for Rewards for Justice is just finding out people where they use to be and reaching them with the technology which they are most comfortable with.”
Up to $10 million can be paid for the identification or location of a state-supported hacker attacking US government structures and serious infrastructure like power, water, or transportation, according to a new cryptocurrency reward offer from a programme typically associated with terrorist rewards.(The maximum reward offered by RFJ is $25 million for Al Qaeda’s leader, Ayman al-Zawahiri, who may or may not be alive.)
According to the State Department, the new cryptocurrency reward was not motivated by recent cyberattacks or the Biden administration’s vocal response to them.Instead, RFJ benefited from the administration’s increased focus on the country’s cybersecurity.
“We’ve been working on this for a long time,” said the first official, who is from the Diplomatic Security Service, which oversees RFJ. “We were able to get this rolled out at a very good time as serious infrastructure and ransomwarehappened to be at the top of the news cycle, so to speak, and a major concern for the US government,” he added.
Dark Web tips
Tor, the most popular browser for the Dark Web, which is a hidden part of the internet that regular search engines don’t see, can be used to access the RFJ channel. Tor allows users to access the Dark Web anonymously. Officials said that tips regarding malicious cyber thespians have already land in the weeks since the channel opened.Because of the sensitivity of the information and sources, they declined to say how many or describe them, adding that it’s too early to say whether they’ll lead to anything.
“This isn’t going to be a quick process.” We’re getting some suggestions. We’re weighing in on some suggestions. We’ll pass along those suggestions to our interagency partners.They must then take that information and contact the appropriate people to begin their investigation,” one official explained. “This is going to take a while.”
With information obtained from the Dark Web, the US government has already had success.The CIA launched its own onion site in 2019, recognising that sites on the Tor network are known for both recruiting and receiving tips, and that it needed to be present in places where people felt safe reaching out.
According to a US official, the CIA has received a wide variety of tips in the two years since the site was launched, including about terrorism plots.
“Among other things, the CIA has establishedauthenticated information about attack planning and terrorist networks, intelligence problems, cyber and technology issues, and crime,” the official said.
The information obtained can then be cross-referenced with existing intelligence data or used to confirm previously obtained intelligence.
The State Department is now vying to become a centralised clearinghouse for information seeking to reach the US government. The global visibility of RFJ around the world and on the ground, in dozens of diverse languages, assists cement its position as “an interlocutor to get information to our national security partners,” according to State Department officials.
“I’d like to believe that in the coming months and years, we’ll have developed such a reliable and efficient process that our National Security Council partners will regard us as one of the most effective and reliable sources of information on the national security threats they’re attempting to counter. Without a doubt, “said the other official.
In 2017, Congress granted RFJ the authority to award rewards for cybercrime, and they have since advertised two specific rewards relating to North Korean cybercrime and foreign cyber election interference. The new reward is only for state-backed actors, not for the criminal hackers who have shut down gas pipelines and food processing plants in recent major attacks.
Payments made in cryptocurrency reflect the changing times and are one of many different types of payments that can be made.