Hacked European Cables Reveal a World of Anxiety About Trump, Russia and Iran
By David E. Sanger and Steven Erlanger, NY Times, Dec. 18, 2018
WASHINGTON--Hackers infiltrated the European Union’s diplomatic communications network for years, downloading thousands of cables that reveal concerns about an unpredictable Trump administration and struggles to deal with Russia and China and the risk that Iran would revive its nuclear program.
In one cable, European diplomats described a meeting between President Trump and President Vladimir V. Putin of Russia in Helsinki, Finland, as “successful (at least for Putin).”
Another cable, written after a July 16 meeting, relayed a detailed report and analysis of a discussion between European officials and President Xi Jinping of China, who was quoted comparing Mr. Trump’s “bullying” of Beijing to a “no-rules freestyle boxing match.”
The techniques that the hackers deployed over a three-year period resembled those long used by an elite unit of China’s People’s Liberation Army. The cables were copied from the secure network and posted to an open internet site that the hackers set up in the course of their attack, according to Area 1, the firm that discovered the breach.
Area 1 made more than 1,100 of the hacked European Union cables available to The New York Times. The White House National Security Council did not have an immediate comment on Tuesday.
The compromised material provides insight into Europe’s struggle to understand the political turmoil engulfing three continents. It includes memorandums of conversations with leaders in Saudi Arabia, Israel and other countries that were shared across the European Union.
The cyberintruders also infiltrated the networks of the United Nations, the A.F.L.-C.I.O., and ministries of foreign affairs and finance worldwide. The hack of the A.F.L.-C.I.O. focused on issues surrounding the negotiations over the Trans-Pacific Partnership, a trade deal that excluded Beijing.
Part of the United Nations material focuses on months in 2016, when North Korea was actively launching missiles, and appears to include references to private meetings of the world body’s secretary-general and his deputies with Asian leaders.
Some of the more than 100 organizations and institutions were targeted years ago. But many were not aware of the breach until a few days ago, when some were alerted by Area 1, a firm founded by three former officials of the National Security Agency.
The cables include extensive reports by European diplomats of Russia’s moves to undermine Ukraine, including a warning on Feb. 8 that Crimea, which Moscow annexed four years ago, had been turned into a “hot zone where nuclear warheads might have already been deployed.” American officials say they have not seen evidence of nuclear warheads in Crimea.
The European diplomats’ account of their private meeting in July with Mr. Xi quoted the Chinese president vowing that his country “would not submit to bullying” from the United States, “even if a trade war hurt everybody.”
“China was not a backward country anymore,” the European note taker described Mr. Xi as saying.
In their conversations with American officials after the Helsinki meeting in July, European diplomats described efforts by the White House to engage in damage control after Mr. Trump had gone off-script during a joint news conference with Mr. Putin.
Mr. Trump appeared to agree to allow Russians to question former American diplomats in exchange for the American interrogation of Russians who had been indicted by Robert S. Mueller III, the special counsel. According to a July 20 document describing their private exchanges, White House officials assured the Europeans that Mr. Trump’s agreement would be “nipped down” to prevent the questioning of Americans.
A March 7 cable summarized the difficulties in relations between the United States and the European Union that had developed during the Trump administration. In it, a senior European official in Washington spoke of “messaging efforts” to deal “with the negative attitude to the E.U. in the beginning, which had created a lot of insecurity.”
The official, Caroline Vicini, deputy head of the European Union mission in Washington, recommended that diplomats from the 28 member nations describe the United States as “our most important partner” even as it stood up to Mr. Trump “in areas where we disagreed with the U.S. (e.g., on climate, trade, Iran nuclear deal).”
The cable also recommended working around Mr. Trump by dealing directly with Congress, and urged European diplomats in Washington to emphasize member state interest when pushing on a host of issues, including trade, renewable energy and Brexit.
In a statement on Tuesday night, the European Union’s secretariat said it “is aware of allegations regarding a potential leak of sensitive information and is actively investigating the issue.”
But it seemed to avoid the issues raised by the disclosure, saying it “does not comment on allegations nor on matters relating to operational security.”
The trove of European cables is reminiscent of the WikiLeaks publication of 250,000 State Department cables in 2010. But they are not as extensive and consist of low-level classified documents that were labeled limited and restricted.
The more secretive communications--including a level known as “tres secret”--were kept on a separate system that is being upgraded and replaced, according to European officials. And cables that focused on decisions about world powers’ 2015 nuclear deal with Iran--from which Mr. Trump withdrew the United States in May--are walled off from the internet in an entirely different system.
In this case, the cables were exposed after a run-of-the-mill phishing campaign aimed at diplomats in Cyprus pierced the island nation’s systems, said Oren Falkowitz, the chief executive of Area 1.
“People talk about sophisticated hackers, but there was nothing really sophisticated about this,” Mr. Falkowitz said. After getting into the Cyprus system, the hackers had access to passwords that were needed to connect to the European Union’s entire database of exchanges.
After burrowing into the European network, called COREU (or Courtesy), the hackers had the run of communications linking the European Union’s 28 countries, on topics ranging from trade and tariffs to terrorism to summaries of summit meetings, from the vital to the insignificant.