US cybersecurity agency ‘warns’ government officials, politicians: “…immediately review and apply…” – ET CISO
https://etimg.etb2bimg.com/thumb/msid-116461509,imgsize-27682,width-1200,height=765,overlay-etciso/cybercrime-fraud/us-cybersecurity-agency-warns-government-officials-politicians-immediately-review-and-apply.jpg
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent recommendation for senior government officials and politicians. It has published a “Mobile Communications Best Practice Guidance”, urging them to immediately switch to end-to-end encrypted messaging apps.
In a written advisory, CISA urged individuals in senior government and political positions to prioritise the use of end-to-end encrypted communications to protect their sensitive information. This encryption method ensures that only the sender and recipient can read the messages, preventing unauthorised access even if the communication channel is compromised.
Why CISA has issued urgent security guideline
This guidance comes in the wake of significant cyberattacks on major US telecom companies attributed to Chinese hackers.
“The Cybersecurity and Infrastructure Security Agency (CISA) has identified cyber espionage activity by People’s Republic of China (PRC) government-affiliated threat actors targeting commercial telecommunications infrastructure. This activity enabled the theft of customer call records and the compromise of private communications for a limited number of highly targeted individuals,” the guaidance said.
CISA’s recommendation highlights the growing concern over the severity of these recent cyberattacks, dubbed “Salt Typhoon.” Last week, Senator Ben Ray Lujan called it “the largest telecommunications hack in our nation’s history.”
“While applicable to all audiences, this guidance specifically addresses “highly targeted” individuals who are in senior government or senior political positions and likely to possess information of interest to these threat actors. CISA is releasing this best practice guidance to promote protections for mobile communications from exploitation by PRC-affiliated and other malicious cyber threat actors,” the guidline added.
It added that these individuals “should assume that all communications between mobile devices—including government and personal devices—and internet services are at risk of interception or manipulation.”
It highlighted that while no single solution eliminates all risks, implementing these best practices significantly enhances protection of sensitive communications against government-affiliated and other malicious cyber actors.