State Department reportedly suffers a cyber attack

Details of the hack are still developing

State Department sign in front of a building

Hackers recently hit the Department of State with a cyber attack, according to Fox News and Reuters reports, The Department of Defense Cyber Command also reportedly released notifications of a potentially serious data breach.

According to a tweet by a Fox News reporter on Saturday, the breach is believed to have happened a couple of weeks ago. In a later tweet, the reporter said the extent of the breach, the investigation into the suspected entity behind it, efforts taken to mitigate it, and any ongoing risk to operations remain unclear.

However, a source told Reuters that the State Department has not experienced significant disruptions and has not had its operations impeded in any way.

"The Department takes seriously its responsibility to safeguard its information and continuously takes steps to ensure information is protected. For security reasons, we are not in a position to discuss the nature or scope of any alleged cybersecurity incidents at this time," a State Department spokesperson said in a statement to Reuters.

Steven Hope, CEO and co-founder of Authlogics, told IT Pro the State Department is a juicier target for hackers than the shop around the corner. 

“While we don’t know what was breached, and we may never know in this case, the fact it is listed as ‘serious’ indicates that there could be a lot behind this, either in terms of the volume of data accessed or importance of it. It would be very interesting to know how the bad guys got in to affect the breach,” Hope said.

“By far the most common way into a network is via weak authentication, e.g. breached passwords or poor MFA. After all, we do have over 12 thousand breached U.S. State Department credentials in our database alone, but again, in this case, we may never know."

Sam Curry, chief security officer at Cybereason, told IT Pro that while the State Department isn’t likely to disclose any further details of this attack, given the chaos in Afghanistan, and lingering tensions with Russia over the Colonial and JBS attacks and China for the Microsoft Exchange Server attacks, public and private sector security teams should be on high alert. 

Related Resource

Don’t just educate: Create cyber-safe behaviour

Designing effective security awareness and training programmes

How to define effective security awareness and training programmesDownload now

“Also, allies of the U.S. across Europe, Asia-Pacific, and Africa should also be on high alert. Let's hope the perception by some that the U.S. is distracted doesn't lead to more attacks and chaos,” he said.

“The State Department attack is one of the reasons for the EDR mandate for the US Federal government agencies in the recent White House Executive Order. Having a means of finding the attacks like the one on the State Department as threat actors move in the slow, subtle, stealthy way through networks is the only option in returning defenders to higher ground above threat actors.

"Advanced prevention, building resilience, ensuring that the blast radius of payloads is minimized and generally using peacetime to foster antifragility is achievable. Today, it’s not about who we hire or what we buy. It’s about how we adapt and improve every day."

Featured Resources

The definitive guide to warehouse efficiency

Get your free guide to creating efficiencies in the warehouse

Free download

The total economic impact™ of Datto

Cost savings and business benefits of using Datto Integrated Solutions

Download now

Three-step guide to modern customer experience

Support the critical role CX plays in your business

Free download

Ransomware report

The global state of the channel

Download now

Recommended

DoJ fines former intel operatives who provided hacker-for-hire services to UAE
hacking

DoJ fines former intel operatives who provided hacker-for-hire services to UAE

15 Sep 2021
Senators accuse Amazon of mistreating pregnant workers
Policy & legislation

Senators accuse Amazon of mistreating pregnant workers

10 Sep 2021
Dual citizen sentenced to 11 years for role in North Korean crypto hacking scheme
hacking

Dual citizen sentenced to 11 years for role in North Korean crypto hacking scheme

10 Sep 2021
Commerce Department creates an artificial intelligence committee
Policy & legislation

Commerce Department creates an artificial intelligence committee

9 Sep 2021

Most Popular

What are the pros and cons of AI?
machine learning

What are the pros and cons of AI?

8 Sep 2021
Google takes down map showing homes of 111,000 Guntrader customers
data breaches

Google takes down map showing homes of 111,000 Guntrader customers

2 Sep 2021
Intuit plans end-to-end SMB platform after $12 billion Mailchimp acquisition
mergers and acquisitions

Intuit plans end-to-end SMB platform after $12 billion Mailchimp acquisition

14 Sep 2021