Latest news

The breach was confirmed for the Washington Free Beacon by unnamed officials from inside the department, and it apparently happened two weeks ago.
The attackers - thought to be working at the behest of a nation state - have managed to penetrate a 14 computer servers and 20 workstations located at the Department's headquarters, and have succeeded in exfiltrating personally identifiable information on several hundred employees and contractors.
According to reports, there are indications that the attackers might have also had other goals in mind - namely to either steal confidential information or to pave the way for future intrusions that would make that possible.
Taking into consideration the target, the speculation that the attackers were classic cyber spies is not that far fetched. Still, investigators have not indicated that Chinese hackers - the "usual suspects" in cases such as these - are to blame.
The individuals whose personal information has been compromised have been notified by email and advised to encrypt all files and emails containing sensitive information, as well as data stored on hard drives and shared on networks. They were also urged not to store or email private and personal information from the Department's computers, and advised to be on the lookout for social engineering attempts using the stolen personal information.
As things stand now, it seems that no confidential information was stolen during the attack.
"The Department’s Cybersecurity Team, the Office of Health, Safety and Security and the Inspector General’s office are working with federal law enforcement to promptly gather detailed information on the nature and scope of the incident and assess the potential impacts to DOE staff and contractors," explained the breach notification.

Follow @zeljkazorz


Spotlight

Is it time to professionalize information security?
Posted on 23 May 2013. | The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





