DISA breach likely exposed personal data on at least 200K
Monday, February 24, 2020
Ilia Kolochenko, founder and CEO of ImmuniWeb agreed that on the surface, the incident seems to be “comparatively insignificant.” But he urged an in-depth investigation “to ascertain whether other systems or devices have been impacted.”
Nation-state attackers frequently “commence their attacks by breaching the weakest link accessible from the Internet and then silently propagate to all other interconnected systems in a series of chained attacks,” Kolochenko said. “Worse, access to personal data of the agency staff greatly facilitates a wide spectrum of sophisticated spear-phishing and identity theft attacks capable to bypass virtually any modern layers of defense.”
The disclosure timeline may hold some clues as to the severity of the attack and what’s to come. It “seems to be impermissibly protracted given that the breach reportedly happened almost a year ago,” said Kolochenko. That might very well indicate “attack sophistication, and what has been reported so far may just the tip of the iceberg,” he explained. Read Full Article
Silicon UK: US DoD Department Hacked And Data Compromised
TechRepublic: MGM Hotel breach highlights need for sophisticated cloud security