FBI Advises the Use a Disposable Phone During Beijing Olympics

In a new Private Industry Notification, the US Federal Bureau of Investigation has released advice and guidelines for attendees of the 2022 winter Olympics to be held in Beijing this month. The notification includes different security guidelines and advice, including the recommendation to use a disposable or "burner" phone during the event and while in Beijing.

The warning issued by the FBI doesn't name any specific threats or threat actors that might be involved. However, the notification explains in broad strokes that "a broad range of cyber activities" may be afoot. The warning does concern only athletes and their entourage, it is also aimed at anyone who visits the events.

The FBI provided data from the 2020 Summer Olympics held in Tokyo. During this event, a staggering 450 million attempts to carry out cybercrimes and hacks were recorded. However, due to the outstanding security measures taken by the organizers in Japan, none of those attempts were successful.

Brace for Impact – FBI Expects Torrent of Cyberattacks

The FBI expects all sorts of cyberattacks and payloads during the Beijing Olympics, from data theft and phishing to ransomware and other malware. When it comes to advice concerning using a disposable phone, the FBI doesn't mince words. The guidelines spell things out quite plainly: "The download and use of applications, including those required to participate or stay in the country, could increase the opportunity for cyber actors to steal personal information or install tracking tools, malicious code, or malware."

The fact that the FBI doesn't hesitate to call out even "official" applications required for participation in the Olympic events probably stems from the recent disclosure made by Canadian Citizen Labs, concerning the official application of the event called MY2022. Citizen Labs discovered a gaping security vulnerability in the app that everyone participating in the Olympics will be required to have on their phone.

Major Issues with Official Olympics App

The encryption used for data transfer in MY2022 can be "trivially sidestepped" according to the security researchers. We previously covered Citizen Labs' examination of the app and their subsequent disclosure to the app's developer. Citizen Labs never received a formal response and the bug they discovered was still present in later versions of the application, so it's safe to say it has not been addressed.

The FBI is also warning to leave other Internet-enabled communication devices at home, in addition to using a disposable phone. Using MFA on all applications that would allow it and being very wary of phishing attempts are two other recommendations for anyone who is going to visit the Chinese capital for the Olympics.

February 2, 2022
Loading...

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.