top of page
  • Writer's picturekhareem sudlow

Malware Arrest Exposes Security Gaps at Trump’s Mar-a-Lago Club

http://bit.ly/2uzmcXA Malware Arrest Exposes Security Gaps at Trump’s Mar-a-Lago Club




WASHINGTON — The arrest of a Chinese woman who carried a malware-laced device into Mar-a-Lago, President Trump’s Florida resort, has exposed porous security at the private club and escalating tensions between Secret Service agents and the resort’s staff members, who vet guest lists and allow people onto the sprawling grounds.

At times neither side has had full clarity on who was entering Mar-a-Lago. Secret Service agents must rely on club receptionists and other employees to crosscheck visitors, former officials said.

Communication breakdowns allow for security breaches — like the one that happened on Saturday, with Mr. Trump in residence, when the woman, Yujing Zhang, 32, was arrested with four cellphones, a hard drive, a laptop and a malware-infected thumb drive. She said she was there to attend a “United Nations Friendship Event” that had never been scheduled at the resort.

Her arrest revealed gaps in Mr. Trump’s security and also the challenge of protecting a president who spends less time at the remote, fortified Camp David and more time at his busy resort with sometimes hundreds of guests. The normally tight-lipped Secret Service was so disturbed by the breach that it issued an unusual statement that effectively blamed the Mar-a-Lago staff for not tightly tracking the comings and goings of guests at the club.



“The Secret Service does not determine who is invited or welcome at Mar-a-Lago; this is the responsibility of the host entity,” the agency said in a statement late Tuesday. “The Mar-a-Lago club management determines which members and guests are granted access to the property.”

The arrest of Ms. Zhang came against a backdrop of increasing interest in Mar-a-Lago in China, where advertisements on the internet and on social media sell invitations to the club, which also functions as a for-profit enterprise that rents itself out. The advertisements promise the prospect of rubbing elbows with the president and his associates at banquets, fund-raisers and other events. Access to Mar-a-Lago is highly prized in China, bestowing respect, influence and the allure of potential business opportunities.

On Wednesday Mr. Trump praised the Secret Service and his staff at Mar-a-Lago for helping to catch the woman. “The person at the front desk did a very good job, to be honest with you,” Mr. Trump said.

When Ms. Zhang was confronted at the resort on Saturday, she at first said she was headed to the pool. She later produced a copy of a Chinese-language invitation for the event that was promoted by Cindy Yang, who had previously owned a string of massage parlors where the police shut down a prostitution ring in February. Authorities said the patrons included Robert Kraft, a friend of the president’s and the owner of the New England Patriots.

Federal officials said they were still investigating Ms. Zhang and what kind of malware was on her thumb drive. It was not yet clear whether she was just a striver seeking selfies at the president’s resort or whether she had links to Chinese intelligence. Ms. Zhang’s lawyer did not respond to a request for comment.



Hotels owned by the Trump administration have come under cyberattack before; in 2015, credit card information was stolen from a number of Trump hotel properties. But that appeared to be criminal action, rather than the act of a state.

The promoters of events at Mar-a-Lago are organizations that, in some cases, flaunt their connections to China’s ruling Communist Party and the department that promotes its foreign policy abroad, the United Front Work Department.

One flier on WeChat, a prominent Chinese social messaging platform, declared it to be “the first party at Mar-a-Lago where the protagonists are Chinese.”

When the president is in Palm Beach, agents must construct a government security system on top of what is essentially a private residence. Questions about the process arose just a month after Mr. Trump assumed office in 2017, when resort guests took plain-sight photos of Mr. Trump and the Japanese prime minister discussing a North Korean missile launch. Several Democratic lawmakers called for an investigation into how the club was vetting its visitors.

“The Secret Service relies on the club’s security who has the guest list to tell them who belongs and who doesn’t,” said Don Mihalek, executive vice president of the Federal Law Enforcement Officers Association, which represents the Secret Service.

“The Secret Service is not the club membership business and does not have visibility on who these members are or what they’re entitled to,” said Mr. Mihalek, a former Secret Service agent who was assigned to Trump Tower during the 2016 campaign and presidential details from 2007 to 2011. “That’s the standard for any protected site outside of the White House.”




Image

The president’s frequent visits to Mar-a-Lago make the resort a visible target for supporters, protesters and, officials fear, others who might try to breach security layers meant to protect Mr. Trump.CreditT.J. Kirkpatrick for The New York Times




A former employee who worked at Mar-a-Lago from 2016 to 2018 said that the arrest of Ms. Zhang was not surprising; people have been caught on the property previously. In one notable example, a woman gained access to the Mar-a-Lago computer system and changed the automatic screen saver to the name of the president, preceded by an expletive, according to the employee, who spoke on the condition of anonymity out of fear of legal retribution.



The former employee said security at the estate was not particularly strong, particularly when Mr. Trump was not there — a fact that was well known among the staff.

Joe Kirschbaum, who helped write a Government Accountability Office report on Mar-a-Lago security, said congressional inspectors were given little help from the White House or the Trump Organization. He warned that it was not the responsibility of the Mar-a-Lago staff to keep Mr. Trump safe, and that the limited amount of information allowed to the Secret Service could create future problems.

In a letter on Wednesday, several Democratic senators asked Christopher A. Wray, the F.B.I. director, to assess the security conditions at Mar-a-Lago.

“The latest incident raises very serious questions regarding security vulnerabilities at Mar-a-Lago, which foreign intelligence services have reportedly targeted,” wrote Senators Chuck Schumer of New York, Dianne Feinstein of California and Mark Warner of Virginia.

Mr. Trump often has a hand in straining the security capacity at his resort. The president has personally instructed members to pack fund-raisers beyond the ticket limit at Mar-a-Lago, according to one event organizer who spoke on the condition of anonymity to share private conversations with Mr. Trump.

The fund-raisers, which occur most weekends during the height of the winter season — usually held in hopes that the president or his family members may drop in — are staged in a large ballroom adjacent to the main patio where Mr. Trump eats his dinner.



Mr. Trump encouraged one organizer to pack the ballroom for a February event beyond the 700-person limit, advising that person to tell his staff at Mar-a-Lago that he said he would allow the increase. That organizer was told that the Mar-a-Lago security team had no final say over crowd numbers, but the event still grew to around 730 guests.

In the end, Mr. Trump did not attend, and it was screened by Mar-a-Lago officials and a private security firm hired by the event’s organizers.

When the president is not at his club, the security bubble becomes easier to break.

Members and guests must still present identification and check in with the club’s security team, but several layers of Secret Service protection are not in place. Laurence Leamer, a Palm Beach resident who wrote a book about Mar-a-Lago, said in an interview that the scene could be freewheeling, “like having dinner at the Outback Steakhouse,” adding that the security “seems to me to be incredibly lax.”

Mr. Trump was at his nearby golf club four miles away when Ms. Zhang showed up at the resort on Saturday, and the process that the Secret Service uses to check visitors when he is in town was in place, officials said. Ms. Zhang was screened by agents before reaching the club’s reception area, but confusion over her name and a potential communication barrier led to her entering.

On Wednesday, the Secret Service was reviewing the Saturday incident with security at Mar-a-Lago. John Cohen, a former Department of Homeland Security acting under secretary who worked closely with the Secret Service on protection details, said the president’s “predictable” travel to the resort had made the location vulnerable.

“That’s a nightmare for the Secret Service,” he said. “A privately owned ranch where the president and his people use the location is much easier than protecting the president when he chooses to go to a private club that’s open to members that provides services to those people in exchange for a fee.”

When people approach a checkpoint at Mar-a-Lago, the Secret Service is focused on screening them for weapons or explosives, Mr. Mihalek said.



The agency will also screen for people it calls “gate callers,” those who have exhibited suspicious behavior — such as waiting for the president at the gate of the White House. From there, an agent will rely on security guards or staff members at the location to verify whether someone is a member or guest of the club.

“If I’m an intelligence service I’m going to pay the membership fee, get someone with a clean background and have them become a member of the community,” Mr. Cohen said. “I’m going to have them bring in guests on a regular basis and that’s going to be my strategy. I now have close proximity to the president’s staff and maybe even the president himself.”




































BarberShop Feed

via NYT > Home Page

http://bit.ly/2uzmcXA April 3, 2019 at 08:51PM BruceDayne, ZOLAN KANNO-YOUNGS, KATIE ROGERS and ALEXANDRA STEVENSON April 3, 2019 at 09:39PM

3 views0 comments
bottom of page