NASA investigating 'cyber incidents'
Full article451 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
NASA civil service employees who worked there between July 2006 and October 2018 are impacted.
NASA says it was hacked earlier this year, according to a memo sent to employees Tuesday.
In the memo, NASA said an unauthorized user accessed a server containing Social Security numbers and personally identifiable information on current and former employees. Personnel began investigating the breach on Oct. 23, at which point NASA “took immediate action to secure the servers,” the agency said. An investigation is ongoing, though NASA says it does not believe any agency missions were jeopardized by the “cyber incidents.”
NASA Civil Service employees who joined the agency, separated from the agency, and/or were transferred between NASA centers between July 2006 and October 2018 may have been affected, according to the internal memo.
“NASA and its federal cybersecurity partners are continuing to examine the servers to determine the scope of the potential data exfiltration and identify potentially affected individuals,” the agency said. “This process will take time. The ongoing investigation is a top agency priority, with senior leadership actively involved.”
A NASA spokeswoman, when reached by phone, said the agency waited nearly two months to disclose the breach while investigators examined the full scope of the incident.
“We didn’t want to rattle people,” she added.
The U.S. space agency has struggled with cybersecurity in recent years, once admitting it experienced 13 separate major network security breaches in 2011 alone. Other government agencies with a related focus are similarly vulnerable.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/nasa-breach-december-2018/