Back
Two Federal Agencies Hacked in a Month: Sensitive Pentagon and FBI Data Exposed
SiTech AI Team3 min read

Two Federal Agencies Hacked in a Month: Sensitive Pentagon and FBI Data Exposed

The Pentagon is notifying more than 2 million current and former service members that their personnel records were stolen in a monthslong network compromise. It is the second major breach of federal systems in recent months.

The Pentagon is notifying more than 2 million current and former service members that their records, which contain sensitive personal information, were stolen in a monthslong compromise of one of its networks. It is the second breach in recent months to expose sensitive government information.

The Pentagon breach

The records, according to one notification letter posted to Reddit, included Social Security numbers, names, addresses, sex, race and occupational specialty. That last category could be especially valuable to foreign adversaries, because it could help their intelligence agencies identify high-value military personnel.

Starting last October, hackers gained access to a system operated by the Defense Manpower Data Center, which collates Department of Defense personnel records. The Pentagon says the breach compromised the records of 2.8 million living individuals.

The center handles more than 60 million person records, including those of military, civilian and contractor personnel, retirees, veterans and their family members. The department hasn't said how the attackers breached its systems, whether officials have had contact with those responsible or whether it received ransom demands. Officials have said the stolen data hasn't been misused, but haven't explained how they reached that conclusion.

The FBI hack

Last month, the ransomware group ShinyHunters claimed it hacked into FBI systems and stole records of thousands of the agency's current or former employees. Reuters reported that job titles in the records included ones related to investigating China or Russia.

ShinyHunters said it has no plans to release the information, but the promises of a criminal organization that has hacked and extorted hundreds of organizations mean very little. The group's cyber defenses are also likely no match against nation-state intelligence hackers.

FBI Cyber Division Assistant Director Brett Leatherman this week called on group members to turn themselves in. “The longer you stay in this, the more we learn about you,” he said. “You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.” The statement came after Dutch police arrested a ShinyHunters member.

Why it matters

Together, the recent breaches represent one of the biggest potential espionage hauls since the 2015 hack of the US Office of Personnel Management, when China-state hackers obtained 22.1 million records related to government employees or others who had undergone background checks. The stolen data included nearly the entire gamut of personal information, including fingerprint scans of millions of individuals.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.