Emails show how Hillary Clinton campaign chair was apparently hacked

New evidence appears to show how hackers earlier this year stole more than 50,000 emails of Hillary Clinton's campaign chairman, an audacious electronic attack blamed on Russia's government and one that

News 12 Staff

Oct 29, 2016, 5:50 AM

Updated 2,730 days ago

Share:

Emails show how Hillary Clinton campaign chair was apparently hacked
New evidence appears to show how hackers earlier this year stole more than 50,000 emails of Hillary Clinton's campaign chairman, an audacious electronic attack blamed on Russia's government and one that has resulted in embarrassing political disclosures about Democrats in the final weeks before the U.S. presidential election.
The hackers sent John Podesta an official-looking email on Saturday, March 19, that appeared to come from Google. It warned that someone in Ukraine had obtained Podesta's personal Gmail password and tried unsuccessfully to log in, and it directed him to a website where he should "change your password immediately."
Podesta's chief of staff, Sara Latham, forwarded the email to the operations help desk of Clinton's campaign, where staffer Charles Delavan in Brooklyn, New York, wrote back 25 minutes later, "This is a legitimate email. John needs to change his password immediately."
But the email was not authentic.
The link to the website where Podesta was encouraged to change his Gmail password actually directed him instead to a computer in the Netherlands with a web address associated with Tokelau, a territory of New Zealand located in the South Pacific. The hackers carefully disguised the link using a service that shortens lengthy online addresses. But even for anyone checking more diligently, the address -- "google.com-securitysettingpage" -- was crafted to appear genuine.
In the email, the hackers even provided an Internet address of the purported Ukrainian hacker that actually traced to a mobile communications provider in Ukraine. It was also notable that the hackers struck Podesta on a weekend morning, when organizations typically have fewer resources to investigate and respond to reports of such problems. Delavan, the campaign help-desk staffer, did not respond immediately to the AP's questions about his actions that day.
It is not immediately clear how Podesta responded to the threat, but five months later hackers successfully downloaded tens of thousands of emails from Podesta's accounts that have now been posted online. The Clinton campaign declined to discuss the incident. Podesta has previously confirmed his emails were hacked and said the FBI was investigating.
The suspicious email was among more than 1,400 messages published by WikiLeaks on Friday that had been hacked from Podesta's account.
It was not known whether the hackers deliberately left behind the evidence of their attempted break-in for WikiLeaks to reveal, but the tools they were using seven months ago still indicate they were personally targeting Podesta: Late Friday, the computer in the Netherlands that had been used in the hacking attempt featured a copy of Podesta's biographical page from Wikipedia.
The U.S. Office of the Director of National Intelligence and the Homeland Security Department have formally accused Russian state-sponsored hackers for the recent string of cyberattacks intended to influence the presidential election.
The help-desk staffer, Delevan, emailed to Podesta's chief of staff a separate, authentic link to reset Podesta's Gmail password and encouraged Podesta to turn on two-factor authentication. That feature protects an account by requiring a second code that is separately sent to a cell phone or alternate email address before a user can log in. "It is absolutely imperative that this is done ASAP," Delevan said.
Tod Beardsley, a security research manager at the Boston-based cybersecurity firm Rapid7, said the fact that an IT person deemed the suspicious email to be legitimate "pretty much guarantees the user who is not an IT person is going to click on it."
Other emails previously released by WikiLeaks have included messages containing the password for Podesta's iPhone and iPad accounts.
___
Associated Press writer Matthew Lee contributed to this reporting.
___
Follow Tami Abdollah on Twitter at https://twitter.com/latams and Michael Biesecker at https://twitter.com/mbieseck.


More from News 12
0:28
Man who set himself on fire outside Trump trial dies of injuries, police say

Man who set himself on fire outside Trump trial dies of injuries, police say

1:37
Scattered rain showers overnight; sunshine returns Saturday afternoon

Scattered rain showers overnight; sunshine returns Saturday afternoon

0:15
Authorities: Berkley Township man sentenced to 20 years in prison for fatal stabbing of Seaside Heights man

Authorities: Berkley Township man sentenced to 20 years in prison for fatal stabbing of Seaside Heights man

1:42
Police: Marlboro teacher accused of inappropriately touching student faces charges

Police: Marlboro teacher accused of inappropriately touching student faces charges

0:32
Man who lit himself on fire outside Trump trial has ties to New Jersey

Man who lit himself on fire outside Trump trial has ties to New Jersey

0:56
Graffiti of former Palestinian militant Leila Khaled found spray-painted at Rutgers University

Graffiti of former Palestinian militant Leila Khaled found spray-painted at Rutgers University

0:09
Police: 2 men critically injured in Newark shooting

Police: 2 men critically injured in Newark shooting

2:16
Public warned to keep their dogs away from seals at the Jersey Shore

Public warned to keep their dogs away from seals at the Jersey Shore

0:59
Jersey Proud: 3 men running the length of New Jersey for ‘Dylan’s Wings of Change’ charity

Jersey Proud: 3 men running the length of New Jersey for ‘Dylan’s Wings of Change’ charity

0:35
Tesla recalling nearly 4,000 Cybertrucks because accelerator pedal can get stuck

Tesla recalling nearly 4,000 Cybertrucks because accelerator pedal can get stuck

1:01
New Jersey water companies make plans to adapt federal ‘forever chemical’ guidelines

New Jersey water companies make plans to adapt federal ‘forever chemical’ guidelines

1:54
Authorities: 2 children at Port Reading school become sickened after ingesting marijuana gummies

Authorities: 2 children at Port Reading school become sickened after ingesting marijuana gummies

2:45
Business owners say they are losing business due to Route 71 bridge being stuck in up position

Business owners say they are losing business due to Route 71 bridge being stuck in up position

1:42
Prosecutor: Remains found at Wall construction site were of ‘advanced age’

Prosecutor: Remains found at Wall construction site were of ‘advanced age’

0:27
Prosecutors: Atlantic City’s Central Pier bursts into flames; 1 man dead

Prosecutors: Atlantic City’s Central Pier bursts into flames; 1 man dead

0:25
Boil water advisory issued for parts of Monmouth County

Boil water advisory issued for parts of Monmouth County

0:48
Ridgewood mayor shares photos showcasing renovation of former Warner Theater

Ridgewood mayor shares photos showcasing renovation of former Warner Theater

1:37
Officials: Some Marlboro schools, Trenton Board of Ed receive bomb threat 2nd day in a row

Officials: Some Marlboro schools, Trenton Board of Ed receive bomb threat 2nd day in a row

0:31
Start of Sen. Bob Menendez's bribery trial is delayed a week to mid-May

Start of Sen. Bob Menendez's bribery trial is delayed a week to mid-May

Show off your team spirit! Share your photos with News 12

Show off your team spirit! Share your photos with News 12