Medals for Safety? Surviving the Winter Olympics Cyberthreat
The hack on the 2018 Winter Olympics' IT systems underscores just how difficult it is to protect oneself in such an exposed cyber environment.
February 15, 2018 at 10:00 AM
4 minute read
As soon as the 2018 Winter Olympics in Pyeongchang, South Korea, began, they were compromised.
Officials at the International Olympic Committee (IOC) disclosed that the official Winter Olympics website, as well as unspecified systems connected to internet and television services, were compromised by a cyberattack that occurred shortly after the game's opening ceremonies.
Though officials did not name those behind the attack, there have been reports that link the incident to Russian cybercriminals connected to the Russian government, though the government has denied any association with the attack.
But no matter who the perpetrators were, the successful infiltration of the IOC's IT systems underscores the almost unavoidable cyberthreat high-profile events pose for the organizations, athletes and spectators who attend. For all parties involved in such events, the only way to protect against the cyberthreats is to take cautionary preventive measures, and prepare for what many see as inevitable.
Adam Levin, chairman and founder of identity and data protection company IDT911, noted that the Winter Olympics are a coveted target for many cybercriminals given the attention the event garners.
“Obviously, whenever you have something of this stature, when it is a stage for the entire world, there are those who would attack because they wish to make a statement,” he said.
And not only is it an attractive event to attack, but given the nature of the games, one of the most vulnerable and potentially easy to infiltrate. Within the events themselves, “there are just hundreds of thousands of internet-of-things (IoT) devices, monitors, cameras, HVAC systems, and all sorts of communication systems” that are all potential openings to hackers, Levin said.
“Think about all the different IoT devices that are present in any venue,” he added. “Now multiply that by a factor of 100 considering all the types of venues that are in play … and you see there are all sorts of points vulnerabilities hackers can take advantage of.”
Marcus Christian, partner at Mayer Brown, agreed, noting that as mobile devices and more consumer technology come into play, “we have an expanding number of ways in which cyberattackers can actually target an Olympic game.”
But with all these entry points for cybercriminals, how does one protect themselves at an event like the Olympics?
The best defense, Levin said, is to not have any sensitive or confidential data on hand when attending events like the Olympics or traveling to foreign countries. “Obviously carrying a burner device is probably the best avenue.”
But if there is a need to carry “devices you normally use, make sure to get as much of your personally identifiable information (PII) out of it,” Levin added. “Use VPNs, don't not hook into public Wi-Fi, and try to make sure whatever system you are in is a secure system, though depending on the country you're in, their definition of a secure system could be radically different than our definition.”
In addition, Levin also emphasized the need to have “long and strong passwords and two-factor authentication,” to shred “anything that has PII on it after you are done using it,” and not to send “anything that is sensitive by way of email, especially when you're in a foreign country.”
Levin's advice echoed that of the United States Computer Emergency Readiness Team (US-CERT), which put out a notice before the Winter Olympic events reminding “travelers to be aware of cybersecurity risks” at the games.
To be sure, most of the cybersecurity protections organizations, athletes and travelers can implement for the games are preventive. There is little that can be done, after all, once an organization or person's data is compromised.
Christian, for instance, noted that there isn't a “tool kit of legal tools that companies and individuals have after the fact to go after a hacker.”
“When you look at the U.S. athletes who had their medical information stolen in 2016, for example, for them once the information is out, there is not a whole lot they could do,” he added.
So for the now, the best strategy is to take all necessary precautions, and assume the worst.
“You have to make sure that when you return, you are monitoring properly your credit scores, your credit report, and your accounts and scanning for your PPI on the dark web,” Levin said.
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllTrending Stories
- 1Goodwin Procter Relocates to Renewable-Powered Office in San Francisco’s Financial District
- 2'Didn't Notice Patient Wasn't Breathing': $13.7M Verdict Against Anesthesiologists
- 3'Astronomical' Interest Rates: $1B Settlement to Resolve Allegations of 'Predatory' Lending Cancels $534M in Small-Business Debts
- 4Senator Plans to Reintroduce Bill to Split 9th Circuit
- 5Law Firms Converge to Defend HIPAA Regulation
Who Got The Work
J. Brugh Lower of Gibbons has entered an appearance for industrial equipment supplier Devco Corporation in a pending trademark infringement lawsuit. The suit, accusing the defendant of selling knock-off Graco products, was filed Dec. 18 in New Jersey District Court by Rivkin Radler on behalf of Graco Inc. and Graco Minnesota. The case, assigned to U.S. District Judge Zahid N. Quraishi, is 3:24-cv-11294, Graco Inc. et al v. Devco Corporation.
Who Got The Work
Rebecca Maller-Stein and Kent A. Yalowitz of Arnold & Porter Kaye Scholer have entered their appearances for Hanaco Venture Capital and its executives, Lior Prosor and David Frankel, in a pending securities lawsuit. The action, filed on Dec. 24 in New York Southern District Court by Zell, Aron & Co. on behalf of Goldeneye Advisors, accuses the defendants of negligently and fraudulently managing the plaintiff's $1 million investment. The case, assigned to U.S. District Judge Vernon S. Broderick, is 1:24-cv-09918, Goldeneye Advisors, LLC v. Hanaco Venture Capital, Ltd. et al.
Who Got The Work
Attorneys from A&O Shearman has stepped in as defense counsel for Toronto-Dominion Bank and other defendants in a pending securities class action. The suit, filed Dec. 11 in New York Southern District Court by Bleichmar Fonti & Auld, accuses the defendants of concealing the bank's 'pervasive' deficiencies in regards to its compliance with the Bank Secrecy Act and the quality of its anti-money laundering controls. The case, assigned to U.S. District Judge Arun Subramanian, is 1:24-cv-09445, Gonzalez v. The Toronto-Dominion Bank et al.
Who Got The Work
Crown Castle International, a Pennsylvania company providing shared communications infrastructure, has turned to Luke D. Wolf of Gordon Rees Scully Mansukhani to fend off a pending breach-of-contract lawsuit. The court action, filed Nov. 25 in Michigan Eastern District Court by Hooper Hathaway PC on behalf of The Town Residences LLC, accuses Crown Castle of failing to transfer approximately $30,000 in utility payments from T-Mobile in breach of a roof-top lease and assignment agreement. The case, assigned to U.S. District Judge Susan K. Declercq, is 2:24-cv-13131, The Town Residences LLC v. T-Mobile US, Inc. et al.
Who Got The Work
Wilfred P. Coronato and Daniel M. Schwartz of McCarter & English have stepped in as defense counsel to Electrolux Home Products Inc. in a pending product liability lawsuit. The court action, filed Nov. 26 in New York Eastern District Court by Poulos Lopiccolo PC and Nagel Rice LLP on behalf of David Stern, alleges that the defendant's refrigerators’ drawers and shelving repeatedly break and fall apart within months after purchase. The case, assigned to U.S. District Judge Joan M. Azrack, is 2:24-cv-08204, Stern v. Electrolux Home Products, Inc.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250