Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data

Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data

一个月内两家联邦机构遭黑客攻击,海量敏感数据外泄

The Pentagon is informing more than 2 million current and former military members that their personnel records storing sensitive personal information were stolen over a monthslong compromise of one of its networks. The breach is the second one in recent months to expose sensitive government information.

五角大楼正在通知超过 200 万名现役和退役军人,称其网络在长达数月的入侵事件中遭到破坏,存储敏感个人信息的人事档案已被窃取。这是近几个月来第二次发生导致敏感政府信息外泄的入侵事件。

The records, according to one notification letter posted to Reddit, included Social Security numbers, names, addresses, sex, race, and occupational specialty. This last category could be particularly valuable to foreign adversaries because it could help their intelligence agencies in identifying high-value military personnel.

根据 Reddit 上发布的一封通知信显示,这些记录包括社会安全号码、姓名、地址、性别、种族和职业专长。最后一项信息对外国敌对势力而言尤为重要,因为这有助于其情报机构识别高价值军事人员。

Starting last October, hackers gained access to a system operated by the Defense Manpower Data Center, which collates Department of Defense personnel records. The Pentagon says that the breach compromised the records of 2.8 million living individuals.

从去年 10 月开始,黑客入侵了由国防人力数据中心(Defense Manpower Data Center)运营的一个系统,该中心负责整理国防部的人事记录。五角大楼表示,此次入侵导致 280 万名在世人员的记录遭到泄露。

A potential boon

潜在的“大礼包”

The incident is the second time a major network breach in recent months has exposed sensitive US government personnel records that criminal groups or foreign adversaries could use. Last month, the ransomware group ShinyHunters claimed it hacked into FBI systems and stole records of thousands of the agency’s current or former employees.

这是近几个月来第二次发生重大网络入侵事件,导致敏感的美国政府人事记录外泄,这些记录可能被犯罪集团或外国敌对势力利用。上个月,勒索软件组织 ShinyHunters 声称其入侵了联邦调查局(FBI)系统,并窃取了该机构数千名现任或前任员工的记录。

Reuters reported the job titles in the records included ones related to investigating China or Russia. ShinyHunters said that it has no plans to release the information, but the promises of a criminal organization that has hacked and extorted hundreds of organizations mean very little. Additionally, the group’s cyber defenses are likely no match against nation-state intelligence hackers.

据路透社报道,这些记录中的职位名称包括与调查中国或俄罗斯相关的工作。ShinyHunters 表示没有计划发布这些信息,但一个曾入侵并勒索过数百个组织的犯罪团伙所作出的承诺毫无意义。此外,该组织的防御能力很可能无法与国家级情报黑客相抗衡。

An FBI official this week called on group members to turn themselves in. “The longer you stay in this, the more we learn about you,” FBI Cyber Division Assistant Director Brett Leatherman said. “You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.” Leatherman made the statement after Dutch police arrested a ShinyHunters member.

本周,一名 FBI 官员呼吁该组织成员自首。FBI 网络部门助理局长 Brett Leatherman 表示:“你们在这个行当里待得越久,我们对你们的了解就越多。你们知道如何找到我们,我们也知道如何找到你们。我建议你们在还有选择权的时候主动联系我们。”Leatherman 是在荷兰警方逮捕了一名 ShinyHunters 成员后发表上述声明的。

Together, the recent breaches represent one of the biggest potential espionage hauls since the 2015 hack of the US Office of Personnel Management. In the breach, China-state hackers obtained 22.1 million records related to government employees or others who had undergone background checks.

总的来说,近期发生的这些入侵事件是自 2015 年美国人事管理局(OPM)遭黑客攻击以来,潜在间谍窃取规模最大的事件之一。在那次入侵中,中国背景的黑客获取了 2210 万份与政府雇员或其他接受过背景调查的人员相关的记录。

The Defense Manpower Data Center says it handles more than 60 million Defense Department “person records,” including military, civilian, contractor, retiree, and veteran personnel and their family members. The department hasn’t said how the attackers breached its security systems, whether officials have had contact with those responsible, or whether they received ransom demands. Department officials have said the stolen data hasn’t been misused, but haven’t explained how they reached that conclusion.

国防人力数据中心表示,其处理超过 6000 万份国防部“人员记录”,包括军人、文职人员、承包商、退休人员、退伍军人及其家属。国防部尚未说明攻击者是如何突破其安全系统的,也未透露官员是否与责任人有过接触,或是否收到了赎金要求。国防部官员表示被窃数据尚未被滥用,但并未解释他们是如何得出这一结论的。