Attacks/Breaches
2/5/2013
06:12 PM
Connect Directly
RSS
E-Mail
50%
50%

U.S. Energy Department Hack Exposes Employee, Contractor Information

No classified data was compromised, but the attack is believed to have affected several hundred people

Hackers hit the U.S. Department of Energy (DOE) in mid-January and accessed personal information belonging to possibly hundreds of employees and contractors, according to an internal DOE email.

The email circulated Friday and was reported Monday after The Washington Free Beacon broke the story. The revelation came on the heels of reports that several news organizations had been targeted in cyber-attacks as part of an espionage campaign reputed to have originated in China. The Chinese government however has denied any connection to the attacks on the media outlets.

It is important to remember that it is difficult to prove who is behind an Internet attack, as hackers can easily "bounce their attacks between multiple compromised computers" across the globe, Graham Cluley, senior technology consultant at Sophos, notes in a blog post.

"And there is a chance that China could become an all-too-convenient bogeyman, that can easily be blamed for any embarrassing security breach," he adds.

The DOE email does not name any specific culprit, but states that an investigation turned up no evidence that classified information was compromised in the attack.

"We believe several hundred DOE employees’ and contractors’ PII (personally-identifiable information) may have been affected," according to the email. "As individual affected employees are identified, they will be notified and offered assistance on steps they can take to protect themselves from potential identity theft."

The email also urges employees to encrypt all files and emails containing PII and sensitive data, including files stored on hard drives or on the shared networks. In addition, employees were told not to store or email non-government related PII on DOE network computers.

Once the full nature and extent of the attack is known, the email continues, the department will "implement a full remediation plan."

"The Department is also leading an aggressive effort to reduce the likelihood of these events occurring again," according to the email. "These efforts include leveraging the combined expertise and capabilities of the Department’s Joint Cybersecurity Coordination Center to address this incident, increasing monitoring across all of the Department’s networks and deploying specialized defense tools to protect sensitive assets."

A remediation plan would be a good step forward to Richard Towle, head of federal markets at FireMon.

“If not for a troubling history preceding this incident, this report could be seen as an opportunity to improve," Towle says. "If classified information was truly not compromised, the organization could use what was taken to inform themselves about risks in the “reach-ability” of critical assets and associated access vulnerabilities."

"However, based on track record – not just of government, but also the industry at large – the typical response is to simply plug the wounds after they have already bled out, and try and defend similar points of entry," he continues. "We need to break the cycle and make security about understanding and addressing risk, as opposed to trying to get better and faster at reaction."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
DarkReadingTim
50%
50%
DarkReadingTim,
User Rank: Strategist
2/6/2013 | 5:00:26 PM
re: U.S. Energy Department Hack Exposes Employee, Contractor Information
I love the last quote in this story.-á Enterprises and government continue to spend money to plug the holes, and the breaches keep coming.-á Seems like time to rethink security, not just from a technology perspective, but from an architectural perspective.
--Tim Wilson, editor, Dark Reading
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2006-1318
Published: 2014-09-19
Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, which allows remote attackers to execute arbitrary code via a malformed control in an Office document, aka "Microsoft Office Control Vulnerability."

CVE-2012-2588
Published: 2014-09-19
Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, or (3) Subject header or (4) body in an SMTP e-mail message.

CVE-2012-6659
Published: 2014-09-19
Cross-site scripting (XSS) vulnerability in the admin interface in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-1391
Published: 2014-09-19
QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.

CVE-2014-3614
Published: 2014-09-19
Unspecified vulnerability in PowerDNS Recursor (aka pdns_recursor) 3.6.x before 3.6.1 allows remote attackers to cause a denial of service (crash) via an unknown sequence of malformed packets.

Best of the Web
Dark Reading Radio