Biodun Iginla, BBC News

Biodun Iginla, BBC News
Showing posts with label chinese data hack. Show all posts
Showing posts with label chinese data hack. Show all posts

Friday, June 12, 2015

Chinese hackers got US security files: report


by Melissa Gruz and Biodun Iginla, France24. Washington DC

© AFP/File | A data breach of US government workers allowed hackers to access sensitive information, including security clearances of the workers and contractors, according to the Washington Post
WASHINGTON -  A data breach of millions of US government employees allowed Chinese hackers to access sensitive information including security clearances of the workers and contractors, the Washington Post said.
The report, released Friday, said investigators are looking at two separate attacks, widely believed to be from China, accessing government employee records in a database at the Office of Personnel Management (OPM).
The database "is very sensitive and it has lots of interfaces to it," a US official told the newspaper on condition of anonymity.
The report, which called the breach "wider than first acknowledged," said the database could possibly contain files on some CIA employees.
"That's the open question -- whether it's going to hit CIA folks," a second official was quoted as saying. "It would be a huge deal. They could start unmasking identities."
The database contains personal information on employees including their financial histories, investment records, family data, contacts with foreigners and names of neighbors and friends, according to the report.
Earlier this week, a public employees union said the hackers obtained sensitive information on all federal employees.
Samuel Schumach, spokesman for the OPM, would not confirm if the hack originated in China.
An investigation that included the FBI found that "there was a high degree of confidence that OPM systems containing information related to the background investigations of current, former, and prospective federal government employees, and those for whom a federal background investigation was conducted, may have been exfiltrated," he said.
The OPM was still assessing how many people had been affected, he added.

Thursday, June 11, 2015

Hackers may have snared details of Chinese linked to US: report


by Biodun Iginla, France24, New York

© AFP/File | Chinese hackers accused of attacking US federal databases may have snared the names of Chinese with links to American officials, putting them in danger, The New York Times said
NEW YORK  -  Chinese hackers accused of attacking US federal databases may have snared the names of Chinese with links to American officials, putting them in danger, The New York Times said.
Last week, the US government admitted hackers accessed the personal data of at least four million current and former federal employees, in a vast cyberattack suspected to have originated in China.
Investigators say that the hackers who breached the databases of the Office of Personnel Management could have obtained the names of Chinese relatives, friends and associates of American diplomats and other government officials, the Times said.
Beijing -- which labeled claims of Chinese involvement in the huge hack "irresponsible" -- could use that information for blackmail or retaliation, the newspaper said.
Federal employees involved with national security information are required to list some or all of their foreign contacts to receive high-level clearance, the report said.
According to the Times, intelligence officials have in recent days described in classified briefings to members of Congress "what appears to be a systematic Chinese effort to build databases that explain the inner workings of the US government," the newspaper said.
"It gives the Chinese the ability to exploit who is listed as a foreign contact," James Lewis, a cyberexpert at the Center for Strategic and International Studies, told the Times.
"And if you are a Chinese person who didn?t report your contacts or relationships with an American, you may have a problem."
The breach at the Office of Personnel Management was just the latest in a series of major incursions that have shown the vulnerability of the US federal government.

Friday, June 5, 2015

US warns victims of 'Chinese' data hack

by Melissa Gruz, Tamara Kachelmeier, and Biodun Iginla, Reuters and BBC News, Washington

22 minutes ago


Four million current and former US government employees are being told to take precautions after having personal information stolen by cyber hackers.
Chinese perpetrators are suspected of carrying out a "massive breach" of the personal data, officials said.
Employees have been told to monitor or close bank accounts, freeze credit reports, and change online passwords.
Some have spoken to the BBC expressing fears over how their personal information will be used.
"Identity theft is one thing I'm concerned about," said Bryan Sivak, a former technology officer with the Department of Health and Human Services.
"But depending on what information was accessed, I'm more worried about this information being used to illegally access various networks or against individuals directly."
Mr Sivak said he had not yet been notified if his personal data has been exposed, but another employee told the BBC they had already received instructions.

J David Cox Sr, president of the largest union representing federal employees, says he "will demand accountability" and push for the information to be secured.
The Office of Personnel Management (OPM) OPM said it became aware of the breach in April during an "aggressive effort" to update its cyber security systems.
It said it would be offering those affected 18 months of free credit monitoring and identity theft insurance.
OPM serves as the human resource department for the federal government. The agency issues security clearances and compiles records of all federal government employees.
Information stored on OPM databases includes employee job assignments, performance reviews and training, according to officials.

What was stolen?

  • security clearances and background checks dating back to 1985
  • social Security numbers for current and retired employees
  • performance reviews and testing
  • birthdays, addresses, bank information, and other personal data
An unnamed US official told the Reuters news agency that some of the stolen information includes security clearances and background checks from as far back as 1985.
"This is deep. The data goes back to 1985. This means that they potentially have information about retirees, and they could know what they did after leaving government," said the official, speaking on condition of anonymity.
Some of the sensitive personal information could be used to access critical weapons systems, according to the official.
Susan Collins, a member of the Senate Intelligence Committee, said the hackers were believed to be based in China.
But China denied there was any official involvement in the attack.

A spokesman for the Chinese embassy in Washington called the allegations "not responsible, and counterproductive".
The FBI and the Department of Homeland Security are investigating the latest breach.
Ken Ammon, chief strategy officer of Xceedium - a cyber security firm - warned that the hacked data could be used to impersonate or blackmail federal employees with access to sensitive information.
Congressman Adam Schiff has called for cyber databases to be upgraded saying that "a substantial improvement in our cyber databases and defences is perilously overdue".