Traffic with the noted IP address has been found elsewhere in the United States, indicating that the Burlington discovery wasn't a sign of a targeted attack, and is not always linked with malicious activity. The Post also reports that officials found a suite of malware on the laptop, a more standard criminal package known as "Neutrino," which is not believed to be connected to any Russian hacking operations.
More from The Verge:
Behind the scenes at Faraday Future, an electric carmaker on the brink of collapse
The best apps you didn't know you needed for your new Android phone
Samsung's new four-in-one washer/dryer takes laundry to the extreme
The Post originally reported that Russian hackers had breached the US electrical grid with the apparent attack, but according to the Burlington Electric Department itself, the laptop in question was not connected to the utilities system. "The grid is not in danger," Vermont Public Service Commissioner Christopher Recchia said at the time, specifying that monitoring utilities "flagged it, saw it, notified appropriate parties and isolated that one laptop with that malware on it."
In a bid to inform companies about the risk of cyberattacks coming from abroad, the FBI and the Department of Homeland Security released a report last week that contained a list of suspicious IP addresses — a list that presumably included the address discovered by Burlington Electric Company employees. The report gave advice on how to proceed if such indicators were discovered, but warned against assuming every IP it mentioned was a stone-cold indicator of a hacking operation, with a note saying that "upon reviewing the traffic from these IPs, some traffic may correspond to malicious activity, and some may correspond to legitimate activity."
The report was still criticized, however, for featuring too broad a swathe of IPs, with 30 percent of the addresses being benign proxies or servers used by companies like Amazon and Yahoo. Experts warned that the report may cause people to jump to early conclusions — as apparently happened in Vermont — but a Department of Homeland Security official said the document was ""precisely the type of information DHS should be sharing, particularly since we know that cybersecurity capabilities differ among companies and organizations."