This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

DOE Lab hacked

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

No classified information was lost but the personal information of visitors may have been stolen from the Oak Ridge National Laboratory.
- http://www.informationweek.com/shared/prin…cleID=204702720
Dec. 7, 2007 - "Oak Ridge National Laboratory (ORNL), a U.S. Department of Energy facility, said on Thursday that its computer network had been comprised by a spear-phishing attack. "A hacker illegally gained access to ORNL computers by sending staff e-mails that appeared to be official legitimate communications," ORNL said in a statement. "When the employees opened the attachment or accessed an embedded link, the hacker planted a program on the employees' computers that enabled the hacker to copy and retrieve information. The original e-mail and first potential corruption occurred on October 29, 2007. We have reason to believe that data was stolen from a database used for visitors to the Laboratory." ORNL said that no classified information was lost but that the personal information of visitors may have been stolen. Visitors to the laboratory between 1990 and 2004 may have had their personal information, such as social security number and date of birth, stolen as a result of the data theft. The breach occurred on October 29, 2007. ORNL said there's no evidence that the stolen information has been used for identity theft fraud, but nonetheless recommended that anyone who visited the lab between 1990 and 2004 place a fraud alert on their credit file…"

:angry: :ph34r:
More on this…

Sophisticated cyber attacks break into computer systems at the U.S. military's Oak Ridge National Laboratory in Tennessee and Los Alamos National Laboratory in New Mexico
- http://preview.tinyurl.com/2audjb
December 07, 2007 (Computerworld) - "…Thom Mason, director of the government research facility, reported that the lab has been the target of what he described as a sophisticated cyberattack by hackers seeking to gain access to computer networks at numerous research facilities and other government institutions across the country. According to the note, the unknown hackers gained access to a nonclassifed laboratory database, which contained personal information on people who have visited the facility in Oak Ridge, Tenn., over a 14-year period starting in 1990. Mason said the hackers made about 1,100 attempts to steal data by sending an unknown number of staffers a total of seven phishing e-mails… According to Mason's e-mail, the phishing e-mails appeared legitimate and attempted to persuade recipients to open attachments or links. One of the bogus e-mails, for instance, purported to notify individuals of a scientific conference. Another pretended to notify the recipients of Federal Trade Commission complaint, he noted…"

:angry: