
The Pentagon is informing more than 2 million current and former military members that their personnel records storing sensitive personal information were stolen over a monthslong compromise of one of its networks. The breach is the second one in recent months to expose sensitive government information.
The records, according to one notification letter posted to Reddit, included Social Security numbers, names, addresses, sex, race, and occupational specialty. This last category could be particularly valuable to foreign adversaries because it could help their intelligence agencies in identifying high-value military personnel. Starting last October, hackers gained access to a system operated by the Defense Manpower Data Center, which collates Department of Defense personnel records. The Pentagon says that the breach compromised the records of 2.8 million living individuals.
A potential boon
The incident is the second time a major network breach in recent months has exposed sensitive US government personnel records that criminal groups or foreign adversaries could use. Last month, the ransomware group ShinyHunters claimed it hacked into FBI systems and stole records of thousands of the agency’s current or former employees. Reuters reported the job titles in the records included ones related to investigating China or Russia.
ShinyHunters said that it has no plans to release the information, but the promises of a criminal organization that has hacked and extorted hundreds of organizations mean very little. Additionally, the group’s cyber defenses are likely no match against nation-state intelligence hackers. An FBI official this week called on group members to turn themselves in.
Leave a Reply