Special Report: State Department's computer crime investigations go global

 

Connecting state and local government leaders

In 2003, in a former Soviet republic, several people were tried and convicted of terrorism, and two of them received the death penalty.

In 2003, in a former Soviet republic, several people were tried and convicted of terrorism, and two of them received the death penalty.For national security reasons, many details of the case are not available. But what is known is that the State Department assisted in gaining the convictions, thanks to the work of its computer crimes unit.'There was an attempted terrorist attack and the target was U.S. interests,' said David Trosch, branch chief for the Computer Investigations and Forensics (CIF) unit in the Diplomatic Security Service, a division of the department.The country caught a man with a bomb and learned from him the location of the terrorist safe house, he said.'As they were going through the door, [a] co-conspirator smashed the computer on the floor,' Trosch said. 'Their security service tried to work it over,' but it was too damaged for their expertise and the country asked the U.S. embassy for assistance.Analysts from Trosch's unit went there and tried to duplicate the contents of the hard drive, but could not because it was so damaged.The case was urgent, so the embassy arranged to divert a military airplane to the country, so the CIF agents could bring the drive back to the U.S. and use a 'clean room' to dismantle the drive.'We never were able to mirror the drive, but we replaced the damaged head and mechanically manipulated the drive to recover about 75 percent of the data,' Trosch said. 'Based on that re- covery, the foreign government convicted several people.'Much of the work that CIF carries out is not as urgent as that example, but the unit is on track to handle more than 200 cases this year.Trosch estimated that a quarter of those cases involve counterintelligence, another quarter are criminal cases investigating passport and visa fraud, and a quarter are miscellaneous investigations.The remaining 25 percent are related to internal affairs matters'Diplomatic Service employees using government computers for illegal or unethical activities, he said.When a State Department employee turns on his or her computer, the first thing they see on the screen is a warning that the machine is the property of the U.S. government and everything on it is subject to search at any time.But people forget that all the time, said Anthony Adkison, the former branch chief for CIF, who recently moved on to another assignment in the department.'It's not that they use computers to do something they wouldn't otherwise do,' he said. 'It's that the computer is a new venue for them to indulge habits they already have,' whether it's gambling over the Internet or conducting personal business.[IMGCAP(2)]Over the past three years, CIF has grown from three people to 25 full-time staff members. Ten of them are State Department employees; the other 15 are contractors, Trosch said.That mix is necessary in part because of the expense of finding trained analysts, but in part because the Diplomatic Service rotates staff to new posts, overseas and stateside, every two years. Adkison stayed in his post for three years to help the unit take shape, but he had to request a one-year extension to do so.Trosch has been brought in to head the team from the Defense Department. As a civil-service employee, he's not subject to the rotation rule.'I'll be here for a while,' he said. 'It's becoming more high profile. ... They [department chiefs] have made significant investments, in both money and manpower.'CIF is broken down into two lines of work, Trosch said. Several agents provide support services for search and seizures, going on-scene to handle the securing of computers and other digital devices, while the remainder provide the forensic analysis to support cases.As the terrorism example shows, the unit provides its services to many outside interests, including other governments and other U.S. agencies. CIF also handles the computer forensics examinations for schemes against the State Department's computer networks, such as phishing, where the department itself is the victim, he said.In passport and visa fraud cases, CIF is not the lead investigating unit. Overseas, personnel in the embassies and consulates conduct the investigations, and in the United States, field offices handle the investigations. But CIF can provide appropriate language for search warrants, log in the evidence and handle media analysis.CIF creates a CD or DVD with hyperlinks that is turned over to the case agent, Trosch said.The department is making a significant new investment in its computer forensics capabilities. CIF is scheduled by the end of the year to move into much larger offices, with dedicated lab space for analysts' workstations, juiced-up cooling capabilities to deal with the heat generated by all the equipment, and even 'safe' access to the Internet, so connections can't be traced back to the State Department, he said.'It's several million dollars' of investment, Trosch said. 'I'm in the process now of trying to project lifecycle replacement costs' for the unit's very high-end computers.At the same time, he has to look ahead to new technology challenges.'There are several areas we're going to have to pay attention to,' such as RFID. The department has mandated that passports'both American and those of other countries'will have to include microchips to facilitate checking individuals' credentials.Fortunately, 'there's always a bit of lead time when new technology comes out,' Trosch said.

Over the past three years, the Computer Investigations and Forensics unit has grown from three people to 25 full-time staff members. Ten of them are State department employees; the other 15 are contractors.

Susan Afoosi

Forensics is 'becoming more high profile. ... They [department chiefs] have made significant investments, in both money and manpower.'

'CIF Branch Chief David Trosch

Susan Afoosi















Recovery led to convictions

























Network protection
















X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.