Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data
It has been a bad month for federal government cybersecurity.
The Pentagon has notified over two million current and former military personnel that their personnel records containing sensitive personal information have been compromised due to a prolonged network compromise. This breach, the second of its kind in recent months, exposed records containing Social Security numbers, names, addresses, sex, race, and occupational specialties.
The latter category could prove particularly valuable to foreign adversaries, enabling them to identify high-value military personnel. Since October last year, hackers infiltrated a system operated by the Defense Manpower Data Center, which aggregates Department of Defense personnel records. The Pentagon estimates that the breach affected the records of 2.8 million living individuals.
This incident highlights the potential boon for criminal groups or foreign adversaries who could exploit such sensitive US government personnel records. Last month, the ransomware group ShinyHunters admitted to hacking into FBI systems and stealing records of thousands of the agency’s current or former employees, which included job titles related to investigating China or Russia.
Written by urgent.news from Ars Technica's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.