Regulation

Pentagon and FBI breaches expose millions of government personnel records to potential adversaries

A monthslong compromise of Defense Department systems has compromised the records of 2.8 million military members and former service members, marking the second major breach of sensitive U.S. government data in recent months.

3 min read
Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data

The Department of Defense is notifying more than 2 million active and former military personnel that their confidential personnel files were accessed during an extended breach of one of its networks. This marks the second significant compromise of classified government information to occur in the past several months.

According to a notification letter shared on Reddit, the stolen files contained Social Security numbers, full names, home addresses, gender, race, and military occupational specialty. The last element holds particular significance for hostile intelligence services, as it could facilitate the identification of key military targets. Beginning in October of last year, unauthorized actors penetrated systems managed by the Defense Manpower Data Center, the entity responsible for aggregating personnel information across the Department of Defense. The Pentagon has stated that 2.8 million living individuals were affected by the breach.

A potential boon

This breach represents the second instance in recent months in which a significant government network compromise has made accessible sensitive personnel information belonging to U.S. government workers that could be leveraged by criminal enterprises or state-sponsored actors. In the previous month, the ransomware operation ShinyHunters announced it had penetrated FBI infrastructure and obtained personnel files belonging to current and former bureau employees. According to reporting by Reuters, the stolen records contained job titles connected to investigations focused on China and Russia.

ShinyHunters has stated it does not intend to distribute the data, but assurances from a criminal organization responsible for breaching and extorting hundreds of companies carry minimal credibility. Furthermore, the group's defensive infrastructure likely cannot withstand the capabilities of state-level intelligence operations. An FBI representative issued a public statement this week urging the group's members to surrender.

The longer you stay in this, the more we learn about you. You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.

FBI Cyber Division Assistant Director Brett Leatherman

Leatherman delivered this message following the apprehension of a ShinyHunters operative by authorities in the Netherlands.

Collectively, these recent compromises constitute among the most significant potential intelligence collection operations since the 2015 breach targeting the U.S. Office of Personnel Management. In that incident, Chinese state-sponsored hackers obtained 22.1 million records pertaining to government workers and individuals who had undergone security clearance investigations. The compromised information encompassed a comprehensive range of personal data, including fingerprint records from millions of people.

The Defense Manpower Data Center maintains custody of more than 60 million Department of Defense "person records," encompassing military personnel, civilian employees, contractors, retirees, veterans, and their dependents. The Pentagon has not disclosed the method through which attackers circumvented its security infrastructure, whether department leadership has engaged with the responsible parties, or if ransom requests were made. Pentagon leadership has asserted that the compromised information has not been subject to misuse, though officials have not clarified the basis for this determination.

Source: Ars Technica · Reporting supplemented by The Silicon Ledger staff.