News: 1712254814

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Feds probe massive alleged classified US govt data theft and leak

(2024/04/04)


Updated Uncle Sam is investigating claims that some miscreant stole and leaked classified information from the Pentagon and other national security agencies.

The US Department of State "is aware of claims that a cyber incident has occurred and is currently investigating," a spokesperson told The Register .

"The department takes seriously its responsibility to safeguard its information and continuously takes steps to improve the department's cybersecurity posture. For security reasons, we will not provide details on the nature and scope of the claim."

[1]

A netizen who goes by IntelBroker took credit for the cyber-heist, and on Tuesday appeared to dump at least a sample of the alleged stolen data on the dark web.

[2]

[3]

The leak, [4]spotted by Dark Web Informer, allegedly consists of a treasure trove of contact info for government and military officials – including names, email addresses, and office and personal cell phone numbers belonging to Pentagon and government employees – plus classified and confidential communications and documents shared between the Five Eyes' intelligence agencies and other US allies.

IntelBroker bragged about the leak on Twitter, sorry, X, before being [5]booted from the social network — and said they obtained the records after breaking into the IT environment of Acuity, a Virginia-based consulting firm that works with the US government and national security organizations.

[6]

Acuity did not respond to The Register 's request for comment. We will update this story if and when we receive a response.

The intrusion [7]may have happened last month: At the time, the same miscreant claimed to have stolen sensitive information, via Acuity, belonging to US Immigration and Customs Enforcement (aka ICE) and US Citizenship and Immigration Services, including personal details about 100,000 folks plus email addresses and plain-text passwords.

[8]Ivanti commits to secure-by-design overhaul after vulnerability nightmare

[9]Microsoft slammed for lax security that led to China's cyber-raid on Exchange Online

[10]Ransomware gang did steal residents' confidential data, UK city council admits

[11]Feds finally decide to do something about years-old SS7 spy holes in phone networks

IntelBroker bragged they used a zero-day bug in GitHub to access Acuity's tokens and snatch the government data.

This follows an earlier theft of State Department data also involving Microsoft, which owns GitHub.

In that case, in June 2023, Chinese government snoops, known as Storm-0558, compromised Microsoft keys and breached the IT giant's Exchange Online hosted email service to [12]steal some 60,000 emails from the department, plus a list of all its employees' email addresses. ®

Updated to add

"Acuity recently identified a cybersecurity incident related to GitHub repositories that housed dated and non-sensitive information. Immediately upon becoming aware of this zero-day vulnerability, Acuity applied the vendor's security updates and performed mitigating actions in accordance with the vendor's guidance," Acuity CEO Rui Garcia told The Register after publication.

"After conducting our own analysis and following a third-party cybersecurity expert investigation, Acuity has seen no evidence of impact on any of our clients' sensitive data. In addition to cooperating with law enforcement, Acuity takes the security of its customers' data seriously and is implementing appropriate measures to secure its operations further."

Get our [13]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zg8i@6JmZXS48Gx63GWS1AAAABM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zg8i@6JmZXS48Gx63GWS1AAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zg8i@6JmZXS48Gx63GWS1AAAABM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://twitter.com/DarkWebInformer/status/1775295354910466200

[5] https://twitter.com/DarkWebInformer/status/1775690327271067654

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zg8i@6JmZXS48Gx63GWS1AAAABM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.hackread.com/hacker-breach-federal-contractor-acuity-ice-uscis-data/

[8] https://www.theregister.com/2024/04/04/ivanti_secure_by_design/

[9] https://www.theregister.com/2024/04/03/cisa_microsoft_exchange_online_china_report/

[10] https://www.theregister.com/2024/04/04/ransomware_gang_did_in_fact/

[11] https://www.theregister.com/2024/04/02/fcc_ss7_security/

[12] https://www.theregister.com/2023/09/28/chinese_hackers_stole_60000_state/

[13] https://whitepapers.theregister.com/



Enquiring minds want to know.

nematoad

Uncle Sam is investigating claims that a criminal stole and leaked classified information from the Pentagon and other national security agencies.

Would his name be Trump by any chance?

Criminal?

Anonymous Coward

I guess that 'The Donald' has more docs in his possession than those found at Mar-A-Lardo.

They'll be his exit stage left to Putin plan the moment that the jury in NYC goes out to deliberate.

The like of Fox News/NewsMax/RSBN and the rest will try their best to make out that it is all the fault of the 'Biden Crime Family'.

It is a Mad, Mad, Mad World.

Five Eyes And..................

Anonymous Coward

.............Incontinence!!!!!

Biter Bit???

Stable Door ... Horse Long Gone????

White Hats A Bit Dirty????

....and so on......

The more bragging you do, the sooner they catch you and the more time you serve.

Tron

The contact info used to be openly accessible on mil sites. But in those days we still had telephone directories and people were happy to share contact information so the world could function more easily.

The five eyes stuff might be more fun. I'm a big fan of transparency in government. Unfortunately, state accountability only seems to come from hacks like Wikileaks and the Paradise Papers. It's almost like they are up to something and are trying to hide it! Surely not.

I need to program a function key to type 'you should keep private stuff on a system that never connects to the public internet' as these hacks are almost daily now.

Moderation is a fatal thing. Nothing succeeds like excess.
-- Oscar Wilde