Tag / 13 entries / page 1 of 2 / feed available

Government

13 of the 76 analyses in Data Breaches carry this tag. All 13 are scored against the four invariants; the matrix below is that evidence.

How this tag scores against the four invariants

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

073

Conduent Business Services Data Breach (January 2025)

Contained by: EGR

Conduent Business Services discovered unauthorized access to a limited portion of its environment on January 13, 2025, after access that began on October 21, 2024. The actor exfiltrated client-associated files containing personal, medical, health-insurance, claims, and Social Security information; SafePay claimed responsibility and alleged theft of 8.5 terabytes, but the role and volume were not independently confirmed. Publicly reported impact reached at least 25 million people, while later HHS OCR figures and state reports remained inconsistent and unresolved.

071

U.S. Department of the Treasury BeyondTrust Breach December 2024

A China state-sponsored APT (later attributed to Silk Typhoon) compromised a stolen BeyondTrust Remote Support SaaS API key, using it to reset local application account passwords and remotely access U.S. Treasury Department workstations and unclassified documents. The intrusion, detected by BeyondTrust on December 2, 2024 and disclosed to Congress on December 30, 2024 as a major cybersecurity incident, reached the Office of Foreign Assets Control, the Committee on Foreign Investment in the United States, the Office of Financial Research, and reportedly the Office of the Treasury Secretary. The attack exploited a critical unauthenticated command/argument-injection flaw (CVE-2024-12356, CVSS 9.8) and a second lower-severity flaw (CVE-2024-12686); OFAC later sanctioned contractor Yin Kecheng for his role in the compromise.

067

Army National Guard Salt Typhoon Network Compromise (March–December 2024)

Prevented by: EGR · Contained by: HSF

A PRC-associated Salt Typhoon actor extensively compromised the Army National Guard network of an unidentified U.S. state from March through December 2024. The actor reportedly accessed or exfiltrated administrator credentials, network configurations and diagrams, a geographic map, and service-member personally identifiable information, while collecting configuration and traffic involving Guard networks in every other state and at least four territories. NJCCIC reported entry through a weakly configured remote-access service, followed by lateral spread and control of several privileged accounts, although the complete attack chain was not publicly established.

059

Indian Council of Medical Research Data Breach 2023

Prevented by: HSF, EGR

In October 2023, the Indian Council of Medical Research experienced a major data breach that led to the exposure of 815 million records, including Aadhaar IDs, passport details, names, phone numbers, and addresses. The data was compromised by a hacker identified as pwn0001, who made the information available for sale on the dark web. The breach involved significant security vulnerabilities, particularly in access controls and encryption practices, indicating a need for improved data protection measures.

054

Microsoft Email Accounts Security Breach

In May 2023, Microsoft suffered a data breach conducted by China-based hackers, Storm-0558, who used forged authentication tokens to access customer email accounts. This breach impacted governmental entities, resulting in the unauthorized access and potential exfiltration of approximately 60,000 unclassified emails, emphasizing the breach’s serious national security implications.

048

Consumer Financial Protection Bureau Data Breach

The Consumer Financial Protection Bureau experienced a data breach in February 2023 caused by an employee transferring sensitive records to a personal email account, exposing the personally identifiable information of approximately 256,000 individuals. This breach involved data exfiltration from government systems, highlighting severe insider threat risks and deficiencies in internal data protection protocols. The compromised data originated from several financial institutions, posing potential privacy risks, although no misuse has been confirmed.

031

SolarWinds Supply Chain Attack

Prevented by: PEC, EGR

The SolarWinds Supply Chain Attack involved the compromise of SolarWinds Orion software, leading to malicious updates that were installed by over 18,000 customers. This allowed the attackers, attributed to state-sponsored groups, to steal data and spy on organizations including U.S. government departments. The attack exploited software development vulnerabilities to insert SUNBURST malware, affecting multiple sectors globally.

024

Aadhaar Data Breach

The Aadhaar breach in January 2018 resulted in the unauthorized exposure of personal and biometric data of 1.1 billion Indian citizens. This was due to system vulnerabilities like unsecured API endpoints, allowing attackers access to sensitive data including bank account information. While specific threat actors remain unconfirmed, the large-scale data compromise highlights significant security lapses within the government’s database management.

021

Deep Root Analytics Data Breach

In 2017, a misconfigured Amazon Web Services (AWS) S3 bucket at Deep Root Analytics exposed sensitive data of nearly 200 million U.S. voters. The breach involved personal information such as names, addresses, birth dates, and political affiliations. This incident was primarily due to cloud storage misconfiguration without any evidence of external hacking, highlighting vulnerabilities in data handling practices by third-party vendors.

018

Office of Personnel Management Data Breach 2015

Prevented by: HSF, EGR

In 2015, the Office of Personnel Management (OPM) suffered a major data breach that exposed personal information, including Social Security Numbers and biometric data of approximately 21.5 million individuals. The breach involved sophisticated data exfiltration methods believed to be executed by state-sponsored actors, specifically linked to Chinese hackers. Vulnerabilities in OPM’s legacy systems, coupled with compromised contractor credentials, allowed attackers unauthorized access to sensitive data.

RSS feed for this tag →

Now playing Bandcamp