AplusWebMaster
Topic Starter
FYI…
No classified information was lost but the personal information of visitors may have been stolen from the Oak Ridge National Laboratory.
- http://www.informationweek.com/shared/prin…cleID=204702720
Dec. 7, 2007 - "Oak Ridge National Laboratory (ORNL), a U.S. Department of Energy facility, said on Thursday that its computer network had been comprised by a spear-phishing attack. "A hacker illegally gained access to ORNL computers by sending staff e-mails that appeared to be official legitimate communications," ORNL said in a statement. "When the employees opened the attachment or accessed an embedded link, the hacker planted a program on the employees' computers that enabled the hacker to copy and retrieve information. The original e-mail and first potential corruption occurred on October 29, 2007. We have reason to believe that data was stolen from a database used for visitors to the Laboratory." ORNL said that no classified information was lost but that the personal information of visitors may have been stolen. Visitors to the laboratory between 1990 and 2004 may have had their personal information, such as social security number and date of birth, stolen as a result of the data theft. The breach occurred on October 29, 2007. ORNL said there's no evidence that the stolen information has been used for identity theft fraud, but nonetheless recommended that anyone who visited the lab between 1990 and 2004 place a fraud alert on their credit file…"

No classified information was lost but the personal information of visitors may have been stolen from the Oak Ridge National Laboratory.
- http://www.informationweek.com/shared/prin…cleID=204702720
Dec. 7, 2007 - "Oak Ridge National Laboratory (ORNL), a U.S. Department of Energy facility, said on Thursday that its computer network had been comprised by a spear-phishing attack. "A hacker illegally gained access to ORNL computers by sending staff e-mails that appeared to be official legitimate communications," ORNL said in a statement. "When the employees opened the attachment or accessed an embedded link, the hacker planted a program on the employees' computers that enabled the hacker to copy and retrieve information. The original e-mail and first potential corruption occurred on October 29, 2007. We have reason to believe that data was stolen from a database used for visitors to the Laboratory." ORNL said that no classified information was lost but that the personal information of visitors may have been stolen. Visitors to the laboratory between 1990 and 2004 may have had their personal information, such as social security number and date of birth, stolen as a result of the data theft. The breach occurred on October 29, 2007. ORNL said there's no evidence that the stolen information has been used for identity theft fraud, but nonetheless recommended that anyone who visited the lab between 1990 and 2004 place a fraud alert on their credit file…"