Madam Speaker, pursuant to rule IX, I rise to notify the House of my intention to offer a resolution as a question of the privileges of the House. The form of my resolution is as follows: Directing…
Madam Speaker, pursuant to rule IX, I rise to notify the House of my intention to offer a resolution as a question of the privileges of the House.
The form of my resolution is as follows:
Directing the Chief Administrative Officer and the Sergeant
At Arms of the House of Representatives to take timely action
to ensure that all Members, committees, and offices of the
House are alerted of the dangers of electronic attacks on the
computers and information systems used in carrying out their
official duties and are fully briefed on how to protect
themselves, their official records, and their communications
from electronic security breaches.
Understanding that the Clerk will finish the rest of the resolution, I ask unanimous consent that it be considered as read.
Madam Speaker, I call up the resolution just noticed.
I yield myself such time as I may consume.
(Mr. WOLF asked and was given permission to revise and extend his remarks.)
Madam Speaker, in August 2006, four of the computers in my personal office were compromised by an outside source. This source first hacked into the computer of my Foreign Policy and Human Rights staff person, then the computers of my Chief of Staff, my Legislative Director and my Judiciary Committee staff. On these computers was information about all the case work I've done on behalf of political dissidents and human rights activists around the world. That kind of information, as well, everything else on my computer, e-mails, memos, correspondence and district case work, was open for outside eyes to see.
I'm aware that the computers in the offices of several other Members of the Congress were similarly compromised, as well as a major committee, the Foreign Affairs Committee. That means the computers in the House Foreign Affairs Committee have been compromised. It is logical to assume that critical and sensitive information about U.S. foreign policy and the work of Congress to help people who are suffering around the world, was also open to view from those official computers.
In subsequent meetings with the House Information Resources and the FBI, it was revealed that the outside sources responsible for this attack came from within the People's Republic of China. Just so it's understood, they acknowledged that this attack came from within the People's Republic of China.
The cyber attacks permitted the source to probe our computers to evaluate our systems defenses and to view and copy information. My suspicion is some say that I perhaps was targeted by the Chinese sources because of the history of speaking out about China's abysmal, very abysmal human rights record.
My offices' computers were cleaned and returned to me by House Information Resources, but ever since this happened, I've been deeply concerned that this institution, the institution of the United States Congress, is definitely not adequately aware of or protected from these types of threats.
I've also learned that this threat exists not only here in the Capitol complex, but also when Members travel overseas. I've been told that, particularly in countries in which access to information is tightly controlled by the government, Members are at risk of having their conversations and information recorded or stolen from their cell phones and Blackberry devices. That means, when a Member of the House, the Senate or the administration goes abroad, goes to China, everything, and if they use their cell phone or they use their Blackberry, it's being recorded by the Chinese government. And I don't believe any Member of the Congress has been told of that.
As I've shared my office experience with other Members, it has become clear to me that many Members and committees of other offices in the House do not fully understand the extent of the threat against the security of their offices and how to protect themselves.
I have no information to confirm this, but it would be realistic that the Senate may also be at risk.
The committees in both Chambers on Government Reform, Intelligence, the Judiciary Committee, the Armed Services and the Homeland Security should have hearings on this issue. This is an issue that must have public hearings, as well as closed door and private hearings.
That is why, Madam Speaker, I'm here today on the House floor. I'm speaking out about the threat of cyber attacks from China and other countries on the entire U.S. government, including our military, because of my deep concern about maintaining the security and the integrity of our government.
According to a report from the Congressional Service, and I quote, ``U.S. counterintelligence officials reportedly have stated that about 140 different foreign intelligence organizations regularly attempt to hack into the computer systems of U.S. government agencies and U.S. companies.''
This happens with alarming frequency, according to a recent Business Week article entitled ``The New E-spionage Threat.'' This article states that U.S. Government agencies reported almost 13,000 cyber security incidents in fiscal year 2007, triple the number from just 2 years earlier.
The May 31 cover story of the National Journal, the respected National Journal, says, ``The Chinese Cyber-Invasion,'' and every Member should read it, titled the ``Chinese Cyber-Invasion'' reported, ``Electronic devices by the U.S. Commerce Secretary Carlos Gutierrez and his party during a December 2007 visit to China were invaded using spyware that could steal information.'' Gutierrez was in China with a high-level delegation to discuss trade-related issues.
Now, this Congress said it's concerned about trade-related issues with China, and that's why he was there, such as intellectual property rights, consumer product safety, and market access. The Associated Press also reported on the breach. Why did we learn about this in the press instead of from our own government officials? Did our government do anything about this attack? Did they get information from Secretary Gutierrez that could be used against American business in negotiation of trade agreements?
China, in particular, is actively engaged in espionage against the United States. I recently had the opportunity to read, and I hope every Member of the Congress has read, the U.S.-China Economic Security Review Commission's classified report--it is in the House Intel Committee--to the Congress and found the report's conclusions to be very alarming. The report addresses China's activities in the areas of espionage, cyber warfare, and arms proliferation. I strongly urge all Members of the House to read this report as it gives a clear picture of the threat that China poses, the threat, and in their words, that China poses to our national security.
In fact, the Pentagon's 2008 annual report to Congress stated that ``in the past year, numerous computer networks around the world, including those owned by the U.S. Government, were subject to intrusions that appear to have originated within the People's Republic of China.''
According to the Business Week article in 2007, the U.S. Government launched a classified operation called Byzantine Foothold to combat sophisticated new attacks that were compromising sensitive information at the State Department and a defense contractor, such as Boeing, the source of which U.S. officials allege is China.
The Business Week article states that computer attacks have targeted sensitive information on the Internet works of at least several Federal agencies: the Defense Department, the State Department, the Energy Department, the Commerce Department, the Health and Human Services Department, and the Agriculture Department, and the Treasury Department. Defense contractors Boeing, Lockheed Martin, General Electric, Raytheon, and General Dynamics have also been targeted.
Despite everything we read in the press, our intelligence and law enforcement, national security, and diplomatic corps remain hesitant to speak out on the problem. Perhaps they are afraid that talking about the problem will reveal our vulnerability. In fact, I have been urged not to speak out about this threat. But our adversaries already know we are vulnerable. Pretending that we are not vulnerable is a mistake.
As a Nation, we must decide when we are going to start considering this type of activity a threat to our national security and the men and women who serve in the Armed Forces, a threat that we must confront and which we must protect ourselves.
Madam Speaker, the apparent lack of national urgency to address this problem only gives those who wish us harm an extra advantage.
The Government Accounting Office reported in 2007 that no comprehensive strategy exists yet to coordinate improvements of computer security across the Federal Government in the private sector.
I strongly believe that the appropriate officials, including those of the Department of Homeland Security and the FBI, should brief all Members of Congress in a closed session regarding threats from China and other countries against security of House technology including our computers, BlackBerry devices, and phones. There must be a session where any Member who is interested has the opportunity to get briefed by the FBI and the Department of Homeland Security and others.
The potential for massive and coordinated cyber attacks against the United States is no longer a futuristic problem. We must prepare ourselves now and develop procedures for responding to this threat. Members need to know how best to protect themselves, their staff, and their official business from these threats. I have experienced this threat firsthand, as have others in the Congress, and are deeply worried that this institution, the United States Congress, is not adequately protected.
Congress should take the lead in protecting our government and indeed our country from the threat posed by cyber espionage activities.
James Lewis, the director of the Technology and Public Policy Program at the Center for Strategic and International Studies remarked last year in testimony before the House committee on Homeland Security that ``If gangs of foreigners broke into the State or Commerce Department and carried off dozens of file cabinets, there would be a crisis. When the same thing happens in cyberspace, we shrug it off as another of those annoying computer glitches we must live with.''
The apparent complacency in both the private and public sectors toward this threat is astonishing. We must know about the threat. We must speak out about how to protect ourselves and form a comprehensive strategy with which to respond.
Stephen Spoonamore, a CEO of a cyber security firm called Cybrinth, put the matter succinctly in the National Journal article. He said, ``By not talking openly about this, they are making truly a dangerous national security problem worse . . . Secrecy in this matter benefits no one. Our Nation's intellectual capital, industrial secrets, economic security are under daily and withering attack. The oceans that surround us are no protection from sophisticated hackers, working at the speed of light on behalf of nation-states and mafias.''
We must cease, Madam Speaker, this Congress must cease, the administration must cease denying the scope and scale and risk of the issue. And he goes on to say a growing number of his peers ``believe that our Nation is in grave and growing danger.''
Mr. Spoonamore is right. We are making this dangerous national security problem worse by not discussing it openly. I believe this institution, as my resolution states, should get the facts, and armed with these facts, should take the necessary action to protect the safety and integrity of the House.
In 1789, Madam Speaker, British Parliament member William Wilberforce, speaking to his colleagues about the slave trade, said, ``having heard all of this, you may choose to look the other way, but you can never again say you do not know.''
This Congress on both sides of the aisle and people in the administration can never again, can never again say you do not know; and the American people should ask their Members of Congress, Do you know and what are you going to do about it.
We cannot afford to look the other way when foreign sources are threatening to compromise our government institutions, our economy, our very way of life through cyber espionage. We cannot sit by and watch. I urge the adoption of the resolution.
I reserve the balance of my time.
Before I yield the gentleman 5 minutes, I would say this is bigger than just the House, though. The computers of the House have been violated and when Members go abroad, but also, it deals with people in the administration.
And so I think there need to be public hearings by the Armed Services Committee and by the Judiciary Committee. This Congress is never reluctant to hold a hearing on different things. This is a major issue so it must be broader than just the House Administration Committee.
I yield 5 minutes to the gentleman from New Jersey.
I recognize the gentleman from Illinois (Mr. Kirk), a member of the Appropriations Committee whose computer was also stripped from someone in China, for 1\1/2\ minutes.
Madam Speaker, I recognize the gentleman from Virginia (Mr. Forbes) for 2 minutes.
Madam Speaker, may I inquire as to how much time I have remaining?
Madam Speaker, I yield 4 minutes to the gentleman from Michigan, the ranking member on the Intelligence Committee, Mr. Hoekstra.
Madam Speaker, I recognize the gentleman from Michigan (Mr. Ehlers) for 2 minutes.
How much time do I have left, Mr. Speaker?
I thank the gentlelady for her agreement. I think we have to, one, read the National Journal. This is a very respected magazine. And this is a serious problem. Up until now, it has been neglected by many in the administration and many in Congress.
Secondly, I think the American people are ahead of this Congress. And quite frankly on this issue with China, I think they are ahead of the administration. They are ahead of the administration on human rights, religious freedom, persecution and bad goods coming in from China. This Congress and this administration ought to wake up.
Thirdly, people are not anxious to talk about this in the Congress, nor are they anxious to talk about it in the administration. They are not anxious to talk about it. There was an effort to have me not go ahead with this using different techniques and different ideas. And we complied. We worked with the majority every way we can.
I want to say this. I will not let this issue rest. I may not be the fastest person in this institution. But I am as dogged as anyone. And I expect the leadership, I expect the leadership to deal with this not just by the House Administration Committee, I expect the leadership to deal with this on the Armed Services Committee. I expect the leadership to deal with this with regard to the House Intelligence Committee. I expect the Government Operations, has the Government Operations Committee ever been reluctant to hold a hearing on anything? And the answer is ``no.'' They must deal with this issue. And I tell the gentlelady, who has been very good, and I thank her for that, that if this is not resolved, I will be down here on the floor. I will rework this resolution. It will be a privileged resolution. And the next time there will be a vote on this. And then the American people, the American people can see how aggressive this administration and this Congress will be on a major national security issue and the issues of religious freedom and persecution. Keep in mind that 35 Catholic
bishops are in jail in China. Two hundred Protestant pastors are in jail in China. They have plundered the Tibetans, and they're persecuting the Uighurs. This is not a government that is very friendly. And also they are the leading supporter of genocide in Darfur.
With that, knowing this will be dealt with, I reserve the balance of my time.
Mr. Speaker, I yield back the balance of my time.
Motion to Refer Offered by Ms. Zoe Lofgren of California