Attacks/Breaches
2/5/2013
06:12 PM
Connect Directly
RSS
E-Mail
50%
50%

U.S. Energy Department Hack Exposes Employee, Contractor Information

No classified data was compromised, but the attack is believed to have affected several hundred people

Hackers hit the U.S. Department of Energy (DOE) in mid-January and accessed personal information belonging to possibly hundreds of employees and contractors, according to an internal DOE email.

The email circulated Friday and was reported Monday after The Washington Free Beacon broke the story. The revelation came on the heels of reports that several news organizations had been targeted in cyber-attacks as part of an espionage campaign reputed to have originated in China. The Chinese government however has denied any connection to the attacks on the media outlets.

It is important to remember that it is difficult to prove who is behind an Internet attack, as hackers can easily "bounce their attacks between multiple compromised computers" across the globe, Graham Cluley, senior technology consultant at Sophos, notes in a blog post.

"And there is a chance that China could become an all-too-convenient bogeyman, that can easily be blamed for any embarrassing security breach," he adds.

The DOE email does not name any specific culprit, but states that an investigation turned up no evidence that classified information was compromised in the attack.

"We believe several hundred DOE employees’ and contractors’ PII (personally-identifiable information) may have been affected," according to the email. "As individual affected employees are identified, they will be notified and offered assistance on steps they can take to protect themselves from potential identity theft."

The email also urges employees to encrypt all files and emails containing PII and sensitive data, including files stored on hard drives or on the shared networks. In addition, employees were told not to store or email non-government related PII on DOE network computers.

Once the full nature and extent of the attack is known, the email continues, the department will "implement a full remediation plan."

"The Department is also leading an aggressive effort to reduce the likelihood of these events occurring again," according to the email. "These efforts include leveraging the combined expertise and capabilities of the Department’s Joint Cybersecurity Coordination Center to address this incident, increasing monitoring across all of the Department’s networks and deploying specialized defense tools to protect sensitive assets."

A remediation plan would be a good step forward to Richard Towle, head of federal markets at FireMon.

“If not for a troubling history preceding this incident, this report could be seen as an opportunity to improve," Towle says. "If classified information was truly not compromised, the organization could use what was taken to inform themselves about risks in the “reach-ability” of critical assets and associated access vulnerabilities."

"However, based on track record – not just of government, but also the industry at large – the typical response is to simply plug the wounds after they have already bled out, and try and defend similar points of entry," he continues. "We need to break the cycle and make security about understanding and addressing risk, as opposed to trying to get better and faster at reaction."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
DarkReadingTim
50%
50%
DarkReadingTim,
User Rank: Strategist
2/6/2013 | 5:00:26 PM
re: U.S. Energy Department Hack Exposes Employee, Contractor Information
I love the last quote in this story.-á Enterprises and government continue to spend money to plug the holes, and the breaches keep coming.-á Seems like time to rethink security, not just from a technology perspective, but from an architectural perspective.
--Tim Wilson, editor, Dark Reading
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0914
Published: 2014-07-30
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 6.x and 7.x through 7.5.0.6, Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 6.2 through 6.2.8 for Tivoli IT Asset Management f...

CVE-2014-0915
Published: 2014-07-30
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2 through 6.2.8...

CVE-2014-0947
Published: 2014-07-30
Unspecified vulnerability in the server in IBM Rational Software Architect Design Manager 4.0.6 allows remote authenticated users to execute arbitrary code via a crafted update site.

CVE-2014-0948
Published: 2014-07-30
Unspecified vulnerability in IBM Rational Software Architect Design Manager and Rational Rhapsody Design Manager 3.x and 4.x before 4.0.7 allows remote authenticated users to execute arbitrary code via a crafted ZIP archive.

CVE-2014-2356
Published: 2014-07-30
Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain sensitive information via a crafted HTTPS request.

Best of the Web
Dark Reading Radio