News: 1698088506

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

DC elections agency warns entire voting roll may have been stolen

(2023/10/23)


The US Capitol's election agency says a ransomware crew might have stolen its entire voter roll, which includes the personal information of all registered voters in the District of Columbia.

The DC Board of Elections (DCBOE) first became aware of the intrusion on October 5, when a criminal gang called RansomVC claimed to have broken into a server belonging to DataNet Systems, the agency's website hosting provider, and accessed 600,000 items of US voter data including DC voter records.

According to DCBOE, none of its own internal databases or servers were accessed, but important information was on DataNet's servers.

[1]

In a Friday [2]update posted on its website, the voting agency said the break-in now looks worse than it originally thought. During a daily check-in call with DataNet Systems, DCBOE learned - 15 days after the initial attack - that the compromised server "did contain a copy of the DCBOE's voter roll."

[3]

[4]

"DataNet Systems confirmed that bad actors may have had access to the full voter roll which includes personal identifiable information (PII) including partial social security numbers, driver's license numbers, dates of birth, and contact information such as phone numbers and email addresses," the agency added.

It said the service provider couldn't definitely say "if or when" the incident occurred, or "how many, if any, voter records were accessed." The elections agency says it will now contact all registered voters, and it has also hired Mandiant to assist with the incident response.

[5]Now MOVEit maker Progress patches holes in WS_FTP

[6]Casio keyed up after data loss hits customers in 149 countries

[7]Europol knocks RagnarLocker offline in second major ransomware bust this year

[8]Cybercrim claims fresh 23andMe batch takes leaked records to 5 million

"This remains an active and open investigation," the statement said. "DCBOE will release its full findings when they are available." The agency didn't have any further updates as of Monday morning, DCBOE spokesperson, Sarah Winn Graham, told The Register .

DCBOE is also working with law enforcement and federal government agencies including the FBI, the Multi-State Information Sharing and Analysis Center, US Department of Homeland Security, and the Office of the Chief Technology Officer to investigate the breach.

[9]

Upon learning of the incident in early October, the elections agency took down its website and started scanning its database, server and IT networks for vulnerabilities.

While the website remains down, with a message telling visitors it is [10]undergoing maintenance , "voter registration remains open, active, and secure for District of Columbia residents," according to DCBOE.

RansomVC, aka Ransomed.vc, is a new extortion crew that emerged in September and [11]claimed to have breached Sony and Japanese cell carrier NTT Docomo. ®

Get our [12]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZTbtByCqGG57Ui2H97KmwAAAAAw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.dcboe.org/databreach/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZTbtByCqGG57Ui2H97KmwAAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZTbtByCqGG57Ui2H97KmwAAAAAw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2023/10/01/in_brief_infosec/

[6] https://www.theregister.com/2023/10/19/casio_data_theft/

[7] https://www.theregister.com/2023/10/19/europol_knocks_ragnarlocker_offline/

[8] https://www.theregister.com/2023/10/19/latest_23andme_data_leak_takes/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZTbtByCqGG57Ui2H97KmwAAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[10] https://dcboe.org/

[11] https://www.theregister.com/2023/10/01/in_brief_infosec/

[12] https://whitepapers.theregister.com/



A ransomware crew might have stolen its entire voter roll

abend0c4

It's rather less ambitious than attempting to steal an entire election.

Actually, Florida sells this

Gene Cash

They sell CDs with everything except SSN.

It's not exactly the voter role, it's the list of everyone with a driver's license, but that's not much different.

They warn you if you email a state agency, your email address becomes public record, and is available for sale.

I am not joking.

Re: Actually, Florida sells this

elsergiovolador

It's quite pragmatic. They operate under the assumption that data will be stolen and sold regardless, so why not preempt the thieves?

Response

elsergiovolador

The elections agency says it will now contact all registered voters

And do what? Give people new identities, addresses, jobs and whatnot?

I mean, you can't unsteal someone's identity.

*** Knghtbrd is now known as SirKewLDooD
*** Mercury kicked SirKewlDooD from #quakeforge (*WHACK*)