On January 3rd, the Department of Homeland Security (DHS) announced that they had a data breach of 257,167 former and current employees. The breach was discovered on May 10, 2017, and it affected employees who were working in 2014. The exposed data included names, social security numbers, birth dates, positions, grades, and duty stations. Also, the exposure affected people who were part of the DHS Office of Inspector General’s investigations from 2002 to 2014. DHS states the data breach was not an external attack and the personal information was not the primary target (Kaplan, 2018). The cause of the exposure was a former employee of the DHS who accessed unauthorized information. In December, the DHS notified employees who might have been affected. They waited about seven months for notification because there was a criminal investigation that was going on during that period.
This incident was unusual because it was not an external actor that caused the data breach, but a former employee who did not have authorized access. Still, a dangerous case because the former employee could have sold the information to a third party. Also, these are employees of DHS who protect the security of the citizens of the United States. Some of the personnel could be targets of social engineering to obtain privileged information, or important cases could be put at risk because identities were exposed.
I’m glad to hear that DHS is taking extra steps to secure the employee data, and that access will be restricted to select individuals. Also, unusual behavior patterns by authorized users will be monitored (Kaplan, 2018). DHS is offering credit monitoring to those that are affected by the data breach. For those who were part of the OIG’s investigations between 2002 to 2014, they can contact AllClear ID for free credit monitoring at 855-260-2767.
This incident was unusual because it was not an external actor that caused the data breach, but a former employee who did not have authorized access. Still, a dangerous case because the former employee could have sold the information to a third party. Also, these are employees of DHS who protect the security of the citizens of the United States. Some of the personnel could be targets of social engineering to obtain privileged information, or important cases could be put at risk because identities were exposed.
I’m glad to hear that DHS is taking extra steps to secure the employee data, and that access will be restricted to select individuals. Also, unusual behavior patterns by authorized users will be monitored (Kaplan, 2018). DHS is offering credit monitoring to those that are affected by the data breach. For those who were part of the OIG’s investigations between 2002 to 2014, they can contact AllClear ID for free credit monitoring at 855-260-2767.
References
Arghire, I. (2018, Jan 4). 247,000 DHS Employees Affected by Data Breach. Retrieved from http://www.securityweek.com/247000-dhs-employees-affected-data-breach
Cameron, D. (2018, Jan 3). Homeland Security Data Breach Affects 240,000 Federal Employees, Plus Witnesses and Interviewees. Retrieved from https://gizmodo.com/homeland-security-data-breach-affects-240-000-federal-e-1821755817
Kaplan, P. (2018, Jan 3). Privacy Incident Involving DHS Office of Inspector General Case Management System. Retrieved from https://www.dhs.gov/news/2018/01/03/privacy-incident-involving-dhs-oig-case-management-system
No comments:
Post a Comment