Nearly every American’s social security number and other sensitive information is believed to have been leaked and sold on the dark web in what has been described as the largest data breach in today’s digital age. Bloomberg Law first reported on the data breach after a proposed class action lawsuit... Read More »
DOJ & Federal Courts Report Email and Court Files Hacks Via SolarWinds Breach
The US Department of Justice (DOJ) and US federal courts announced on January 6 they were both hacked by a prior, similar government breach into SolarWinds, a network security management firm that worked inside the systems of multiple US government agencies. The breach also includes a suspected hacking into the federal courts’ filing systems.
The new breach into the DOJ and Federal courts’ emails follows the recent explosive news that numerous government agencies and businesses were also hacked for about four months without authorities noticing.
Leading up to these new hacking reports, government authorities on December 24 announced that hackers had broken into various systems of Solar Winds during automatic updates occurring on the SolarWinds systems. The US Cybersecurity and Infrastructure Security Agency (CISA) then reported the computer intrusion “poses a grave risk” to US federal, state, local agencies, US companies, and organizations since SolarWinds operates in so many sensitive government areas.
Fast forward two weeks later, and two new agencies have now reported being impacted by the former SolarWinds breach.
The DOJ released a statement that about three percent of its emails have been most likely “accessed” by the SolarWinds cyber attacks as well.
The DOJ noted, “After learning of the malicious activity, the OCIO eliminated the identified method by which the actor was accessing the O365 email environment. At this point, the number of potentially accessed O365 mailboxes appears limited to around 3-percent and we have no indication that any classified systems were impacted.”
The DOJ said this breach is considered a “major incident” under the Federal Information Security Modernization Act (FISMA).
Launched in 2014, FISMA was created as an update into US government cybersecurity practices. Among numerous updates, FISMA codified the Department of Homeland Security (DHS) “authority to administer the implementation of information security policies for non-national security Federal Executive Branch systems, including providing technical assistance and deploying technologies to such systems.”
In a tersely worded statement on Wednesday, the CISA said, “The Cybersecurity and Infrastructure Security Agency (CISA) is aware of compromises of US government agencies, critical infrastructure entities, and private sector organizations by an advanced persistent threat (APT) actor beginning in at least March 2020. This APT actor has demonstrated patience, operational security, and complex tradecraft in these intrusions. CISA expects that removing this threat actor from compromised environments will be highly complex and challenging for organizations.”
The second new breach under investigation was discovered inside the systems of the Federal courts. A statement by the United States Courts said, “After the recent disclosure of widespread cybersecurity breaches of both private sector and government computer systems, federal courts are immediately adding new security procedures to protect highly sensitive confidential documents filed with the courts.”
New procedures were immediately put into effect for federal courts on January 6, including that they “accept highly sensitive documents only in paper form or on a secure electronic device, such as a thumb drive, according to new procedures announced Wednesday. Such documents should be stored in a secured stand-alone computer system and should not be uploaded to the Case Management/Electronic Case Files system, known as CM/ECF.”
In total, the SolarWinds breach has impacted about 250 federal agencies and US businesses.
Related Articles
Cybercriminals forced the East Coast Colonial Pipeline to go offline Friday, impacting 2.25 million barrels of the coast's supply of diesel, petrol, and jet fuel. The breach is considered the most significant energy breach in history. This cyber-attack impacted about 45 percent of the entire East Coast's fuel and reinforced... Read More »
SolarWinds, a network-management software maker, has had one of the worst hacker breaches in U.S. history. The attack was sophisticated, broad in scope, and marred the trust placed in tech providers. SolarWinds’ new chief executive is still trying to determine how his company became the hacker’s main avenue of attack.... Read More »
Cyber hackers working on behalf of a foreign government that is widely believed to be Russia broke into numerous government agencies and networks, including the Commerce, Treasury Departments, and several national security agencies. The cyber hackers breached the protected email systems in a sophisticated attack that has left the feds... Read More »