News Blog

News Blog


Unknown hackers steal details on U.S. Joint Strike Fighter project

An unknown cyber criminal (or group of them) has broken into computer systems housing information about the U.S. Defense Department's $300 billion Joint Strike Fighter project, the Wall Street Journal reports today, citing a number of "current and former government officials familiar with the attacks."

It's unclear how much damage the attacks have caused to the jet-fighter project, given that the cyber intruders were able to download "sizable amounts of data" related to the aircraft's (also called the F-35 Lightning II) in-flight maintenance diagnostics but weren't able to access the most sensitive information, related to flight controls and sensors (which is stored on computers not hooked up to the Internet), according to the Journal. The Air Force is currently testing prototypes of the aircraft, said to be the most expensive ever commissioned by the Pentagon.

The attackers allegedly access the Joint Strike Fighter information by exploiting vulnerabilities in the networks of two or three contractors helping to build the high-tech fighter jet, the Journal reports, citing "people who have been briefed on the matter." Although none of the contractors have commented publicly on the computer compromise, Lockheed Martin is the lead contractor on the program, while Northrop Grumman Corp. and BAE Systems PLC are also playing important roles in its development. "Computer systems involved with the program appear to have been infiltrated at least as far back as 2007," according to the Journal, which cites unnamed sources who state that the intruders appear to have been interested in data about the design of the plane, its performance statistics and its electronic systems. The guilty party loaded software onto the Pentagon's computers that encrypts the data as it's being stolen, which means investigators don't know exactly what data has been taken.

This latest alleged cyber intrusion comes less than two weeks after the Journal reported that spies from China, Russia and other countries have hacked into the U.S. electricity grid and installed software that could cause mass outages, a story that has been criticized by some computer experts as hype perpetuated by government officials looking for more funding.

It's unlikely that U.S. investigators will be able to ascertain the identities of those behind the attack, unless they can get the cooperation of China and any other countries that might be involved, says Dorothy Denning, a professor of defense analysis at the Naval Postgraduate School in Monterey, Calif. Of course, it's also possible that computers in China were hacked into in order to make it look like China is to blame, she adds.

State-sponsored spies aren't the only ones who've successfully hacked into U.S. government computers though. Scottish computer hacker Gary McKinnon, 42, has for years been fighting extradition to the U.S. for in 2001 and 2002 allegedly breaking into networks owned by NASA, the US Army, Navy, Department of Defense, and the Air Force, causing about $800,000 in damage and ruining 300 computers. McKinnon, who suffers from Asperger's Syndrome and could face life in prison in the U.S. if convicted, says that he hacked into U.S. government systems that had no password or firewall protection to search for information on "UFOs, free energy and anti-gravity technology," Sky News reports.

There's no silver bullet for protecting sensitive information, Denning says. Encrypting data might help, she adds, but an "adversary may be able to fool the system into decrypting the data or plant malicious code on the system that captures keys."

Government computer security is a big problem, but some agencies do better than others, according to Denning, who points to the annual FISMA report (mandated by the Federal Information Security Management Act of 2002). The 2007 report gave five federal agencies (the Social Security Administration, Justice Department, Environmental Protection Agency, Agency for International Development, and National Science Foundation) an "A+" for their security efforts, but the average score was a "C" (and the Defense Department received a "D-").


Image of an F-35 Lightning II Joint Strike Fighter taking off from a Lockheed Martin facility in Fort Worth, Texas, © U.S. Air Force

Tags: Air Force, Joint Strike Fighter, hacker
More News Blog: Next: Robot "Lunacy" competition wraps up in Atlanta Previous: Wireless Bluetooth moves into the fast lane with latest version

13 Comments

Add Comment
View
  1. 1. aln602 06:12 PM 4/21/09

    "UNKNOWN?!?!" C'mon now, everybody knows the Chinese Government is behind most of the Cyber attacks!!!

    Reply | Report Abuse | Link to this
  2. 2. dorobou 12:33 AM 4/22/09

    guilty until proven otherwise??? You are infact, very "Chinese..."

    Reply | Report Abuse | Link to this
  3. 3. nolm69 02:26 AM 4/22/09

    To blame China for all computer break-ins ignores the fact that there are at least Nations, including Russia, N. Korea, Afghanistan (say, Al Queda and the Taliban), Iran, Israel who has it's share of hackers and lump in Venezuela, Cuba, Somalia, the Balkans, Romania(sorry guys), maybe Ireland [IRA] or some snot in England and of course China! If you just average it out among them all, you'd realize that they all have very, very sharp kids in school and college and university and clandestine training and , OOPS, don't forget Syria and souther Saudi Arabia and Yemen and ...I think the picture is a bit more cloudy than any of us except CIA and NIA, FBI, CSI, NCSI, sheesh! they can all help point the finger, can't they. Damn it all, everybody's looking for a piece of us, because! we've got all the good stuff..! and-they-want it!!, etc ad nauseum, Add to this the knowledge that China has hacked the power grid in this country and we've got a recipe for Real Disaster..Hope that Obama suceeds in reducing the BUSH Hegemony into Iraq and all that grew with it! Democrat PJB

    Reply | Report Abuse | Link to this
  4. 4. Happy Phil 03:01 AM 4/22/09

    Wasting $300 Billion on another airplane is the real crime here.

    Reply | Report Abuse | Link to this
  5. 5. Gage 03:05 AM 4/22/09

    "(which is stored on computers not hooked up to the Internet)" It's good to know they actually employ this very easy security for sensitive information. It's always bewildered me why they don't, and why they say hackers cause so much damage. How does a hacker cause damage?

    Reply | Report Abuse | Link to this
  6. 6. ggross 07:04 AM 4/22/09

    This is another great example of not learning from your mistakes. They admit that hackers have broken into thier computers since 2007. Why the hell are these computers still connected to the internet? Sensitive information needs to be shared between individual contractors, but NOT over the internet. Break the connections!!!

    Reply | Report Abuse | Link to this
  7. 7. ErnestPayne 03:57 PM 4/22/09

    Happy is exactly correct. This boondoggle has nothing to do with the types of wars the US can expect to fight in the future and everything to do with socialism for the defense industry.

    Reply | Report Abuse | Link to this
  8. 8. Mithremakor 10:25 AM 4/23/09

    Frankly, I think it would be a good thing if more of our government's computer systems were hacked into but the info retrieved should be made public. Governmental secrecy passed all bounds of reason many years ago and we the people shouldn't put up with it any more. Government secrets should be restricted by law to details about pending and ongoing military operations. Weapons system secrecy only leads to international arms races and escalating hostility between nations.

    Reply | Report Abuse | Link to this
  9. 9. Paradox in reply to aln602 01:06 PM 4/23/09

    Think about whos the closest behind us in superior aircraft? Russia; they have some of the best hackers on the job and they cant get enough of this. This is very disappointing.... info like this should not be able to be taken as easily and sercretivly and to not even identify the person or persons resposible..

    Reply | Report Abuse | Link to this
  10. 10. johnwnorton 04:43 PM 4/24/09

    Imagine this: You know that you have information that is valuable and prime hackers are surely going to try to get it. Would it not make sense to create a challenging but false target for the hackers, let them break in--but make it hard so they come away convinced that they have accomplished something--and then publicize the break-in to make the hackers think they got prize information, when in fact you fed them persuasive garbage. A convoluted description, but do you get my drift?

    Reply | Report Abuse | Link to this
  11. 11. Happy Phil in reply to johnwnorton 07:45 PM 4/24/09

    Great 7,000 year old trick from Homers' epic poems. The old misinformation ploy fools them every time.

    $300 billion dollars for an airplane is still the more impressive scheme.

    Reply | Report Abuse | Link to this
  12. 12. SarahA 11:37 AM 4/29/09

    If this article on hackers interests you and you are currently researching new ideas to respond to the mounting challenges in cyber security you should take a look at the Global Security Challenge website: www.globalsecuritychallenge.com.

    We have launched a new award (�9,000 GBP cash grant, mentorship from a top VC and invaluable publicity) for researchers and small companies developing new technologies in cyber security. The judging for this award will focus mainly on the disruptive potential of the technology and less on the idea's maturity. Entry is free and the closing date is 15 May 2009.

    Reply | Report Abuse | Link to this
  13. 13. SarahA 11:38 AM 4/29/09

    If this article about hackers interests you and you are currently researching new ideas to respond to the mounting challenges in cyber security you should take a look at the Global Security Challenge website: www.globalsecuritychallenge.com.

    We have launched a new award (£9,000 GBP cash grant, mentorship from a top VC and invaluable publicity) for researchers and small companies developing new technologies in cyber security. The judging for this award will focus mainly on the disruptive potential of the technology and less on the idea's maturity. Entry is free and the closing date is 15 May 2009.

    Reply | Report Abuse | Link to this
Leave this field empty

Add a Comment

You must sign in or register as a ScientificAmerican.com member to submit a comment.
Click one of the buttons below to register using an existing Social Account.

More from Scientific American

See what we're tweeting about

Scientific American Editors

More »

Free Newsletters


Get the best from Scientific American in your inbox

Solve Innovation Challenges

Powered By: Innocentive

  SA Digital
  SA Digital

Science Jobs of the Week

Email this Article

Unknown hackers steal details on U.S. Joint Strike Fighter project: Scientific American Blog

X
Scientific American Magazine

Subscribe Today

Save 66% off the cover price and get a free gift!

Learn More >>

X

Please Log In

Forgot: Password

X

Account Linking

Welcome, . Do you have an existing ScientificAmerican.com account?

Yes, please link my existing account with for quick, secure access.



Forgot Password?

No, I would like to create a new account with my profile information.

Create Account
X

Report Abuse

Are you sure?

X

Institutional Access

It has been identified that the institution you are trying to access this article from has institutional site license access to Scientific American on nature.com. To access this article in its entirety through site license access, click below.

Site license access
X

Error

X

Share this Article

X

About the Bering in Mind Blog

In this column presented by Scientific American Mind magazine, research psychologist Jesse Bering of Queen's University Belfast ponders some of the more obscure aspects of everyday human behavior. Ever wonder why yawning is contagious, why we point with our index fingers instead of our thumbs or whether being breastfed as an infant influences your sexual preferences as an adult? Get a closer look at the latest data as "Bering in Mind" tackles these and other quirky questions about human nature. Sign up for the RSS feed or friend Dr. Bering on Facebook and never miss an installment again.

X

About the Cross-check Blog

Every week, John Horgan takes a puckish, provocative look at breaking science. A former staff writer at Scientific American, he is the author of several books—most notably, The End of Science: Facing the Limits of Knowledge in the Twilight of the Scientific Age. He currently directs the Center for Science Writings at Stevens Institute of Technology. He lives in New York State's Hudson Highlands, where he plays ice hockey each winter to hone his cross-checking skills.

X

Expeditions Blog

Ever wonder what it's really like to be working in Antarctica or collecting core samples from the middle of the Pacific Ocean? Get a first-hand feel for scientific exploration by following the blog posts of researchers out in the field.

X

About the Extinction Countdown Blog

Several times a week, John Platt shines a light on endangered species from all over the globe, exploring not just why they are dying out but also what's being done to rescue them from oblivion. From unusual or little-known organisms like the giant spitting earthworm and the stinking hawk's-beard to popular favorites like cheetahs and koalas, Platt, a journalist specializing in environmental issues and technology, does his part to slow the countdown.

X

About the Guest Blog

The editors of Scientific American regularly encounter perspectives on science and technology that we believe our readers would find thought-provoking, fascinating, debatable and challenging. The guest blog is a forum for such opinions. The views expressed belong to the author and are not necessarily shared by Scientific American.

X

About the Solar at Home Blog

Follow Scientific American editor George Musser as he installs--or tries to install--solar photovoltaic panels on the roof of his suburban New Jersey home. You'll learn the literal nuts and bolts of going green with the sun and get energy-saving tips even if you aren't putting up panels.

Write to us with tips or comments at blog@sciam.com and follow us on Twitter: http://twitter.com/sciam.

X