MIAMI ā The cyberattack crested just as finance officials from across Latin America were descending on Washington to commemorate the 60th anniversary of the Inter-American Development Bank.
On Sept. 24, 2019, requests from more than 15,000 internet addresses throughout China flooded the bankās website, knocking part of it intermittently offline. To unclog the network, the bank took the drastic step of blocking all traffic from China.
Recommended Videos
But the attackers persisted, and as officials gathered for a day of conferences with athletes, academics and celebrity chefs the bombardment intensified.
Details of the attack, which has not been previously reported, are contained in an IDB internal document reviewed by The Associated Press.
News of the attack is surfacing just as the bankās new president, Mauricio Claver-Carone, seeks to leverage his hawkish views on China from his time in the Trump administration to outmaneuver those in Washington and beyond still fuming over his politically charged election last year.
Claver-Carone, the former National Security Councilās senior director for Western Hemisphere affairs, chaired last week in Colombia his first annual meeting of the IDB since he was elected last fall over the objections of Democrats and some regional governments who complained he was breaking the longstanding tradition of a Latin American being at the helm.
A geopolitical ideologue, Claver-Carone seems in no rush to abandon his disdain for Beijingās growing influence in Washingtonās backyard. In sharp contrast to his predecessor, Luis Alberto Moreno of Colombia, who eagerly promoted Chinese investment in the region, Claver-Carone recently floated the possibility of inviting Taiwan, the island democracy claimed by the communist Beijing government as part of its territory.
In curtailing Chinaās influence, Claver-Carone is looking to curry favor with Democrats who question his leadership but share his mistrust of Beijing. If he succeeds, they can help him deliver on what was the main pledge of his unorthodox candidacy: U.S. support for a capital increase so the bank can help the region dig out from a pandemic-induced recession thatās the worst in more than a century.
There are early signs he may be making some headway. This month, a bipartisan group of five lawmakers led by Sen. Bob Menendez, head of the Senate Foreign Relations Committee, proposed legislation authorizing an $80 billion capital increase that would boost lending at the Washington-based bank by 60%.
āPeople need to accept that he won,ā said Dan Runde, a former official with the U.S. Agency for International Development in the George W. Bush administration and an expert on multilateral institutions at the Center for Strategic and International Studies. āThose who are not happy havenāt gone through the five stages of grief yet. Theyāre stuck somewhere between denial and anger.ā
But Sen. Patrick Leahy, the powerful chairman of the Senate Appropriations Committee, has yet to sign on after warning last year that the choice of Claver-Carone, a āpolarizing American,ā to lead the IDB would hurt ā not help ā the case for a funding boost. Thereās also an expectation that some in the region who supported Claver-Carone when Trump was in office ā such as Brazil and Colombia ā might switch allegiances to appeal to the new sheriff in town: President Joe Biden.
āThe argument that an underfunded bank is an opportunity for China is very compelling,ā said Dan Restrepo, who served in the same National Security Council role as Claver-Carone during the Obama administration. āBut it doesnāt answer how you adequately fund the bank and with what leadership.ā
As far as cyber-disruptions go, the attack against the IDB was too small to generate concern beyond the bank. Last year, more than 10 million similar distributed denial of service (DDoS) attacks were observed throughout the world, according to digital security firm NETSCOUT.
But occurring amid the IDBās gala celebration it was fraught with symbolism.
The bash in Washington was hastily organized after the Trump administration six months earlier rallied allies to force the cancellation of the IDB gathering in the Chinese city of Chengdu, which was to be something of a breaking out party for China a decade after it joined the bank.
While the U.S. had been trying to derail the meeting for months, Chinaās denial of a visa to a representative of Venezuelan opposition leader Juan GuaidĆ³ gave it the opportunity to act decisively. While the IDB and the bulk of nations in Latin America recognize GuaidĆ³ as Venezuelaās legitimate leader, China is a staunch ally of President NicolĆ”s Maduro
Claver-Carone was the U.S. official driving the diplomatic standoff with China at the IDB. As the top White House official for Latin America, he was also the architect of āAmerica Crece,ā (America Rising), a program that sought to curb the inroads being made by China in Latin America, where it has displaced the U.S. as the top trading partner in countries such as Argentina, Brazil, and Chile.
According to the IDB document, on Sept. 19, 2019, traffic to the IDB website surged to more than four times normal levels, forcing the main website and publications page offline. At first, the bank defended itself by blocking individual IP addresses.
But then āthe attackers switched tactics and started to throw requests from more than 15,000 IP addresses spread throughout China,ā according to the internal document. āBy Tuesday 24th evening all income traffic from China was blocked, a decision the allowed us to come back online.ā
Unthwarted, the attackers pivoted again, this time relying on 180,000 IP addresses from countries including Singapore and Japan. In all, the attack lasted for months but was effectively contained after three weeks when the bank turned to Amazon to build a more robust firewall.
While there is no indication the site was breached, āthe downtime affected our digital presence and had a negative impact in different communication endeavors,ā the document says. āIt also made our vulnerabilities explicit for third parties, which could potentially make us the target of new attacks and impact the reputation of the IDB brand.ā
Still, itās impossible to know who was behind the attack.
While China has some of the worldās most skilled hackers, security experts say that doesnāt necessarily mean it is behind the attacks. Poorly protected computers can be hijacked and marshaled from anywhere in the world and turned into botnets for unleashing DDoS attacks.
āA targeted attack this long has an obvious financial or political motive ā you donāt troll for three weeks,ā said Tord Lundstrom, a digital security expert at Qurium, a Swedish non-profit organization. āBut determining whether China was behind it, or someone is just trying to make it look like it was, is very hard to determine without additional digital forensic information.ā
Chinaās foreign ministry didnāt respond directly to questions about whether the government knew about the incident at the IDB or was involved but said in a statement that it strongly opposes cyber attacks
āLinking cyber attacks directly to a government is a highly sensitive political issue,ā the ministry statement said. āAll parties should jointly resolve the hacking issue through dialogue and cooperation and avoid politicizing the issue.ā
Claver-Carone declined to be interviewed while the IDB said it does not comment on internal cybersecurity issues. Nonetheless, three people at the bank told the AP they recall China being openly blamed for the attack in briefings back in 2019 to discuss the fallout. The people spoke to the AP on the condition of anonymity to discuss internal deliberations.
On paper, China has a minuscule 0.004% of the IDBās voting shares, the smallest stake of any of the bankās 48 members. But membership has been a cheap way for China to expand its reach in Latin America. Chinese companies are able to bid on IDB-financed projects, rub shoulders with political leaders and pick up valuable economic intelligence that would be harder to acquire on its own.
China is also the second-largest non-borrowing shareholder in IDB Invest, the bankās private lending arm, with nearly 6% of shares, thanks to a reorganization in 2015 when the Obama administration refused to pony up additional resources and saw the U.S.ā stake diluted to 13%.
The IDB also manages a $2 billion fund made up entirely of contributions from China. Over the years the IDB also hosted more than a dozen business summits connecting Latin American entrepreneurs with Chinese investors.
āFor too long the IDB was too friendly with the Chinese Communist Party,ā said Runde. āThe Bank and its shareholders did not hold China accountable when it ruined the 60th Anniversary for the IDB. This too cozy relationship has to change.ā
China has made no secret of its tense relationship with Claver-Carone. In a symbolic rebuke, Yi Gang, the head of Chinaās central bank, refrained from voting in the special meeting last year when Claver-Carone was elected, according to a person who attended the meeting on the condition of anonymity to discuss the closed-door discussion.
Rebecca Ray, a Boston University economist who tracks Chinaās investment in the region, said the touchy politics around China can be a double-edged sword. While Claver-Caroneās attempts to isolate Beijing may play well in the U.S. Congress and help him secure additional funding it could ultimately end up undermining the IDBās mission at a time of great need for financing to build infrastructure, improve health care and reduce poverty in the region.
She noted that as the IDB has lagged other multilateral institutions in securing more funding, three Latin American countries ā Brazil, Ecuador, and Uruguay ā have joined the Asian Infrastructure Investment Bank, Chinaās answer to the World Bank and one which the U.S. opposes.
āSidelining China may end up limiting Chinaās willingness to keep playing an active role, which would not be popular in the region,ā said Ray. āAs long as the need for financing remains high, countries will keep turning to China because thatās where the money is.ā
___
Associated Press writer Joe McDonald in Beijing contributed to this report.
__
Joshua Goodman on Twitter: @APJoshGoodman
___
Contact APās global investigative team at Investigative@ap.org