Millions More of Americans Hit By Government Personnel Data Hack
By: Reuters (Business Insurance) July 2015
Data breaches at the U.S. government’s personnel management agency by hackers, with suspicions centering on China, involve millions more people than previously estimated, U.S. officials said on Thursday.
The Office of Personnel Management said data stolen from its computer networks included Social Security numbers and other sensitive information on 21.5 million people who have undergone background checks for security clearances.
That is in addition to data on about 4.2 million current and former federal workers that was stolen in what the OPM called a “separate but related” hacking incident. Because many people were affected by both hacks, a total of 22.1 million people were affected, or almost 7% of the U.S. population.
The breach had already been considered one of the most damaging on record because of its scale and, more importantly, the sensitivity of the material taken.
Those exposed included 19.7 million who applied for the clearances — current, former, and prospective federal employees and contractors — plus 1.8 million non-applicants, mostly spouses or co-habitants of applicants, the agency said.
Lawmakers from both parties demanded OPM Director Katherine Archuleta’s removal. House of Representatives Speaker John Boehner, a Republican, said President Barack Obama “must take a strong stand against incompetence in his administration and instill new leadership at OPM.”
“The technological and security failures at the Office of Personnel Management predate this director’s term, but Director Archuleta’s slow and uneven response has not inspired confidence that she is the right person to manage OPM through this crisis,” added Virginia Democratic Sen. Mark Warner.
Ms. Archuleta said neither she nor OPM chief information officer Donna Seymour would be resigning. “I am committed to the work that I am doing at OPM,” Ms. Archuleta told reporters during a conference call. “I have trust in the staff that is there.”
The White House said Obama retains confidence in Archuleta.
Chinese role
The United States has identified China as the leading suspect in the massive hacking of the U.S. government agency, an assertion China’s Foreign Ministry dismissed as “absurd logic.”
Asked during a conference call with reporters on Thursday whether China was responsible, a White House National Security Council official, Michael Daniel, said “we’re not really prepared to comment at this time on the attribution behind this event.”
Mr. Daniel, special assistant to the president and cyber security coordinator at the National Security Council, said that “at this point the investigation into the attribution of this event is still ongoing and we are exploring all of the different options that we have.”
OPM said the stolen personal identification data included: Social Security numbers; residency and educational history; employment history; information about immediate family and other personal and business acquaintances; and health, criminal and financial history. Also stolen were about 1.1 million fingerprints, the agency said.
Since they were revealed last month, the hacking incidents have alarmed the millions of Americans affected. OPM said in a statement that its investigation had found no information “at this time” to suggest any misuse or further dissemination of the information stolen from its systems.
OPM said it is highly likely that anyone who went through a background investigation after 2000 was affected by the cyber breach. Those who underwent background checks before 2000 might be impacted but it is less likely, the personnel agency said.
“Rather than simply place blame on the hackers, we need to acknowledge our own culpability in failing to adequately protect so obvious a target,” said the top Democrat on the House of Representatives intelligence committee, Adam Schiff.
The Social Security numbers are just the tip of the iceberg. The critical information, which was not encrypted, involves a complete rundown of the personal lives of about 90% of applicants for security clearances, mainly excepting most undercover CIA agents.
That includes drug use, romantic histories and close friends abroad of those in the military, National Security Agency and sensitive State Department posts, among many others, essentially a road map for what weaknesses might be used for blackmail by a foreign power.
Though not attributing the attack in public to China, investigators have told Reuters that their prime suspect is a team tied to that nation’s Ministry of State Security. The evidence includes a specific piece of malicious software and the use of a stolen digital certificate, both of which had been seen in only a small number of attacks that had been tied to the same group.
Dmitri Alperovitch, chief technology officer at security firm CrowdStrike, said his company’s analysis of data about the breach provided by the government made it clear that one or another part of the Chinese government directed the hacking.
“It’s a tremendous coup for China,” Mr. Alperovitch said.
Categories
- Benefits Resources
- Bonding
- BOP
- Business Insurance
- Commercial Auto
- Commercial Property
- Company News
- Construction
- Crime Insurance
- Cyber Insurance
- Directors & Officers
- Employee Benefits
- Employment Practice Liability Insurance
- Entertainment
- General Liability
- Health Insurance
- Healthcare
- Healthcare Reform
- Homeowners Insurance
- Hospitality
- Manufacturing
- Medical Malpractice
- Mining & Energy
- Nightclubs
- Personal Auto
- Personal Insurance
- Professional
- Restaurants
- Retail & Wholesale
- Risk Management Resources
- Safety Topics
- SBA Bonds
- Security
- Seminars
- Technology
- Tourism
- Transportation
- Uncategorized
- Workers Compensation
Archives
- May 2021
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- November 2018
- September 2018
- August 2018
- May 2018
- April 2018
- March 2018
- February 2018
- January 2018
- December 2017
- November 2017
- October 2017
- September 2017
- August 2017
- July 2017
- June 2017
- May 2017
- April 2017
- March 2017
- February 2017
- January 2017
- October 2016
- September 2016
- August 2016
- July 2016
- June 2016
- May 2016
- April 2016
- March 2016
- February 2016
- January 2016
- December 2015
- November 2015
- October 2015
- September 2015
- August 2015
- July 2015
- June 2015
- May 2015
- April 2015
- March 2015
- February 2015
- January 2015
- December 2014
- November 2014
- October 2014
- September 2014
- August 2014
- July 2014
- June 2014
- May 2014
- April 2014
- March 2014
- February 2014
- January 2014
- December 2013
- November 2013
- October 2013
- September 2013
- August 2013
- July 2013
- June 2013
- February 2013
- November 2011
- October 2011
- September 2011
- July 2011
- June 2011
- March 2011
- November 2010
- October 2010
- September 2010
- April 2010
- February 2010
- November 2009
- October 2009
- November 2008
- August 2008