National Security Agency employee indicted for 'leaking top secret info'
- Reference: 1648791213
- News link: https://www.theregister.co.uk/2022/04/01/nsa_employee_secret_data_leak/
- Source link:
According to a DoJ [1]announcement and the [2]indictment , an NSA staffer named Mark Unkenholz "held a TOP SECRET/Sensitive Compartmented Information (SCI) clearance and had lawful access to classified information relating to the national defense."
The indictment alleges that on 13 occasions between 2018 and 2020, Unkenholz shared some of that information with a woman identified only as "RF" who was not entitled to see it. Unkenholz did so despite allegedly having "reason to believe [the info] could be used to the injury of the United States or to the advantage of any foreign nation."
[3]
The DoJ claims that RF had a TOP SECRET/SCI clearance from April 2016 until approximately June 2019 when she worked for an entity the indictment calls "Company 1". Her clearance lapsed when, in June 2019, she went to work at "Company 2".
[4]
[5]
The indictment's timeline claims that Unkenholz sent material to RF when she was at Company 1 and at Company 2 – so it seems RF's clearance was not sufficient to read some of the info she was sent while working at Company 1.
[6]NSA spies ample opportunities to harden Kubernetes
[7]China thrilled it captured already-leaked NSA cyber-weapon
[8]Russia 'stole US defense data' from IT systems
The indictment and announcement allege Unkenholz used his personal email address to send material to RF.
The documents are silent on how he was able to do so – yet that could be the most interesting aspect of this case. The NSA is by its very nature supposed to be very good at securing data and preventing it from reaching the wrong hands. Knowing what went wrong may be as important to the USA as the leaks.
Unkenholz sent information with his personal email 13 times, it is claimed. Each instance could see him spend ten years inside – as could 13 more charges for retaining that information in his personal email account.
[9]
That sound you hear? Every nation-state-connected snooper in the world mashing their keyboard in a fast and furious effort to figure out if they ever had access to that inbox in one way or another.
Unkenholz made a brief appearance in a Maryland federal district court on Thursday, and was released on conditions including providing a DNA sample, surrendering his passport, and residing at an approved address.
No date has been set for the next hearing. Whenever it happens, can someone in the room ask about how Unkehnolz was able to sneak the NSA info out the door? ®
Get our [10]Tech Resources
[1] https://www.justice.gov/usao-md/pr/national-security-agency-employee-facing-federal-indictment-willful-transmission-and
[2] https://regmedia.co.uk/2022/04/01/unkenholz_indictment.pdf
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YkbNVr8gfeCbgfFH9yO-kAAAAFY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YkbNVr8gfeCbgfFH9yO-kAAAAFY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YkbNVr8gfeCbgfFH9yO-kAAAAFY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2022/03/16/hardening_kubernetes_the_nsa_way/
[7] https://www.theregister.com/2022/03/14/china_nsa_nopen/
[8] https://www.theregister.com/2022/02/17/cisa_russian_attacks/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YkbNVr8gfeCbgfFH9yO-kAAAAFY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://whitepapers.theregister.com/
Re: "The NSA is [..] supposed to be very good at securing data"
Keyword: supposed.
C.
Re: "The NSA is [..] supposed to be very good at securing data"
We've seen it a number of times, haven't we? Those whose business is snooping on others can be quite lax about keeping their own stuff secure.
Asymmetry, anyone?
Ah....I see.....the NSA can hoard as much data as it likes about me.........
........you know, telephone records, email, FB, WhatsApp, hacked Proton, hacked Telegram, hacked CCTV......
........but God help anyone who tries to hoard ANY of their hoard!!!!
Your taxpayer dollar at work!!! Building the STASI one dollar at a time!!!
Meanwhile UK Government Ministers ...
... continue to use Private self-destructing Emails to conduct their business.
Re: Meanwhile UK Government Ministers ...
Not quite the same. UK public sector (MPs, civil servants, etc) use private email in an attempt to avoid Freedom of Information.
Re: Meanwhile UK Government Ministers ...
Ironically while the government itself sends FOIs to health trusts/boards to get data from their e-mails.
Rules don't seem to apply to certain government departments it seems.
Re: Meanwhile UK Government Ministers ...
BoJo's SOP.
Thing about the NSA
If you are vigorous young computer security-type person, what do you do? You could work for NSA: big government, bureaucracy, perhaps well-paid but you do not get shares, can never say what you do, lots of academic types who will sneer at you. Or you could go to work for a new thrusting young future-googlebook unicorn-type company. You get to do thrusting-young unicorn-type things, you get very well paid, you do really cool eork, and you get stock options. When company fails you find a new one, rinse and repeat until one succeeds, your options vest and you are now minor plutocrat, perhaps start own thrusting young rocket company.
The NSA get two sorts of IT people: the ones who could not get jobs at the unicornoids because they are not very good, and the ones with a James Bond spy obsession who perhaps own too much things which are camouflaged. Not surprising they leak stuff, really.
(This is different than the academic types: they probably are good, probably do work for NSA but their skills are in theory and sneering, not actual IT security.)
More info please
So, the suspect was busy sending classified info to this lady when she was at Company A which may/may not have been ok, but wasn't ok when she was at Company 2?
I think a little more info is needed here. Was it actually ok for him to send her the info while at Company A or not, while she was cleared? If not, that was a Bad Thing. If so, that was fine. So then she moves to Company B and her clearance lapses. So if it had been ok to send her the info previously, then maybe he had just assumed she was still cleared at Company B?
Re: More info please
The Reg linked a copy of the indictment. "PERSONAL EMAIL ADDRESS, COMPANY 1 EMAIL ADDRESS, COMPANY 2 EMAIL ADDRESS were not authorized locations for the storage of classified information..." and apparently he wasn't authorized to send from his email or she to receive this info at either address.
The first 6 counts are of sending to company 1's email.
Re: More info please
Without actual details, however, I do wonder if the NSA had tied itself up in its own bureaucracy to the extent that this sort of thing was the only way to get the work done.
How did he get it out?
Perhaps he has a photographic memory and then he just typed it on his home computer and then sent it?
You did ask.
"The NSA is [..] supposed to be very good at securing data"
Yeah, except when it isn't.
Having your crown jewels [1]hacked and stolen makes for some very sloppy internal procedures when you are indeed "supposed" to be secure at all levels.
[1] https://en.wikipedia.org/wiki/The_Shadow_Brokers