Saturday, August 23, 2014

 

U.S. undercover investigators among those exposed in data breach

A cyber attack at a firm that performs background checks for U.S. government employees compromised data of at least 25,000 workers, including some undercover investigators, and that number could rise, agency officials said on Friday.

The breach at Falls Church, Virginia-based US Investigations Services (USIS) exposed highly personal information of workers at the Department of Homeland Security's headquarters as well as its U.S. Immigration and Customs Enforcement and U.S. Customs and Border Protection units, two officials familiar with the investigation into the breach told Reuters.

Some employees have already received letters warning them about the breach that say compromised information includes Social Security numbers, education and criminal history, birth dates along with information about spouses, other relatives and friends including their names and addresses.

"Records including this data were exposed to unauthorized users during the cybersecurity intrusion," according to a notification letter obtained by Reuters. "We do not yet know whether the data was actually taken."

One DHS official told Reuters the agency has identified some 25,000 employees whose information it believes were exposed in the breach.

"More could be notified in coming weeks as we learn more about the breach," said the official, who asked not to be identified by name.

The company disclosed the attack earlier this month, but did not say how many records had been compromised or which agencies were affected. It did say the intrusion has "all the markings of a state-sponsored attack."

While the number of employees affected is relatively small compared to breaches at retailers such as Target Corp, which have affected tens of millions of customers, security experts say the attack on USIS is nonetheless quite serious.

Files on background checks contain highly sensitive data that foreign intelligence agencies could attempt to exploit to intimidate government workers with access to classified information.

"They would be collecting this data to identify individuals who might be vulnerable to extortion and recruitment," said Dmitri Alperovitch, chief technology officer with cybersecurity firm CrowdStrike, which sells intelligence on state-sponsored cyber attacks.

The Department of Homeland Security has suspended all work with USIS since the breach was disclosed and the FBI launched an investigation.

USIS says it is the biggest commercial provider of background investigations to the federal government, with over 5,700 employees, and provides services in all U.S. states and territories, as well as abroad.

A spokeswoman for Altegrity, which owns USIS, declined comment. Altegrity is majority owned by Providence Equity Partners.
Tags : ,

Share

Popular Stories

Quotes

Well, the way they make shows is, they make one show. That show's called a pilot. Then they show that show to the people who make shows, and on the strength of that one show they decide if they're going to make more shows.

Like you, I used to think the world was this great place where everybody lived by the same standards I did, then some kid with a nail showed me I was living in his world, a world where chaos rules not order, a world where righteousness is not rewarded. That's Cesar's world, and if you're not willing to play by his rules, then you're gonna have to pay the price.

You think water moves fast? You should see ice. It moves like it has a mind. Like it knows it killed the world once and got a taste for murder. After the avalanche, it took us a week to climb out. Now, I don't know exactly when we turned on each other, but I know that seven of us survived the slide... and only five made it out. Now we took an oath, that I'm breaking now. We said we'd say it was the snow that killed the other two, but it wasn't. Nature is lethal but it doesn't hold a candle to man.

You see? It's curious. Ted did figure it out - time travel. And when we get back, we gonna tell everyone. How it's possible, how it's done, what the dangers are. But then why fifty years in the future when the spacecraft encounters a black hole does the computer call it an 'unknown entry event'? Why don't they know? If they don't know, that means we never told anyone. And if we never told anyone it means we never made it back. Hence we die down here. Just as a matter of deductive logic.