Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

FBI: “Sloppy” Sony Hacking Pointed to North Korea Servers

National intelligence director says attack gave North Korea “global recognition at a low cost with no consequences.”

FBI Director James Comey said on Wednesday that hackers behind the cyber attack on Sony Pictures Entertainment provided key clues to their identity by sometimes posting material from IP addresses used exclusively by the North Korean government.

The hackers, who called themselves “Guardians of Peace,” sometimes “got sloppy” and failed to use proxy servers that would hide their identity, Comey said at the International Conference on Cyber Security in New York.

“The Guardians of Peace would send emails threatening Sony employees and post online various statements explaining their work. In nearly every case they would use proxy servers in sending those emails and posting those statements,” Comey said.

“But several times they got sloppy. Several times, either because they forgot or they had a technical problem, they connected directly and we could see it,” Comey said.

“We could see that the IP addresses they used … were IPs that were exclusively used by the North Koreans. It was a mistake by them. It was a very clear indication of who was doing this. They would shut it off very quickly once they realized the mistake, but not before we saw them and knew where it was coming from,” he added.

Sony’s network was crippled by hackers in November as the company prepared to release “The Interview,” a comedy about a fictional plot to assassinate North Korean leader Kim Jong-un. The attack was followed by online leaks of unreleased movies and emails that caused embarrassment to executives and Hollywood personalities.

Comey urged the U.S. intelligence community to declassify information that showed the hackers used such servers. Critics of the FBI and spy agencies have accused the government of failing to back up assertions that North Korea was responsible.

Comey said investigators still do not know how hackers got into Sony’s systems. But he said technical analysis of the malware used showed strong similarities to malware developed by North Korea and used last year in attacks on South Korean banks.

He said language used by Guardians of Peace also matches language used in other hack attacks attributed to North Korea.

Comey said the FBI would deploy more cyber security experts to work in the offices of its foreign partners in order to “shrink the world” the way hackers have done.

U.S. officials familiar with investigations into the attack say while U.S. agencies believe North Korea initiated it, they are also looking into whether Pyongyang hired outside help.

One of the officials said investigators believe the North Koreans could either have hired foreign hackers to help with the attack or got help from disgruntled Sony insiders. They do not believe North Korea had help from any other government.

In earlier remarks at the conference, Director of National Intelligence James Clapper called the Sony hack the most serious such attack ever against U.S. interests. The attack offered North Korea “global recognition at a low cost with no consequences,” Clapper said, and that recognition will make the North Koreans more likely to commit similar acts in the future.

Clapper added that over the weekend, he had watched “The Interview,” and “it’s obvious to me that the North Koreans don’t have a sense of humor.”

CNBC and NBC News contributed to this report.

This article originally appeared on Recode.net.

See More:

More in Technology

Podcasts
Anthropic just made AI scarierAnthropic just made AI scarier
Podcast
Podcasts

Why the company’s new AI model is a cybersecurity nightmare.

By Dustin DeSoto and Sean Rameswaram
Politics
The Supreme Court will decide when the police can use your phone to track youThe Supreme Court will decide when the police can use your phone to track you
Politics

Chatrie v. United States asks what limits the Constitution places on the surveillance state in an age of cellphones.

By Ian Millhiser
Future Perfect
The simple question that could change your careerThe simple question that could change your career
Future Perfect

Making a difference in the world doesn’t require changing your job.

By Bryan Walsh
Technology
The case for AI realismThe case for AI realism
Technology

AI isn’t going to be the end of the world — no matter what this documentary sometimes argues.

By Shayna Korol
Politics
OpenAI’s oddly socialist, wildly hypocritical new economic agendaOpenAI’s oddly socialist, wildly hypocritical new economic agenda
Politics

The AI company released a set of highly progressive policy ideas. There’s just one small problem.

By Eric Levitz
Future Perfect
Human bodies aren’t ready to travel to Mars. Space medicine can help.Human bodies aren’t ready to travel to Mars. Space medicine can help.
Future Perfect

Protecting astronauts in space — and maybe even Mars — will help transform health on Earth.

By Shayna Korol