Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Government Security United States

Dept. of Energy Compromised 159 Times Over Four-Year Period 35

An anonymous reader writes: USA TODAY obtained records through a Freedom of Information Act request indicating that the U.S. Department of Energy was targeted by over a thousand cyberattacks between October 2010 and October 2014. 159 of the attacks were successful in compromising some level of security. "Energy Department officials would not say whether any sensitive data related to the operation and security of the nation's power grid or nuclear weapons stockpile was accessed or stolen in any of the attacks, or whether foreign governments are believed to have been involved. ... The National Nuclear Security Administration, a semi-autonomous agency within the Energy Department responsible for managing and securing the nation's nuclear weapons stockpile, experienced 19 successful attacks during the four-year period, records show. ... Records show 53 of the 159 successful intrusions from October 2010 to October 2014 were 'root compromises,' meaning perpetrators gained administrative privileges to Energy Department computer systems."
This discussion has been archived. No new comments can be posted.

Dept. of Energy Compromised 159 Times Over Four-Year Period

Comments Filter:
  • They should really install a UTM appliance
    • oh my sides hurt!

      usually UTM from big network iron vendor == very poorly maintained Linux system with more holes than a fishnet

  • by Opportunist ( 166417 ) on Saturday September 12, 2015 @01:51PM (#50510469)

    I that run by the same government that wants to collect all our private data for security reasons?

    • I that run by the same government that wants to collect all our private data for security reasons?

      Yes, that's right, by Obama's government. He's been the chief executive since 2009.

      That's what people wanted right, "progressive"-ly more Orwellian?

      • Yeah, because every government worker got replaced in 2009, all the awesome officials we had before have been replaced by the idiots we have now. But luckily we will be getting the awesome ones back come next election.

        Please. Don't pretend elections would change jack shit here.

  • Wooo Over a 1000! (Score:4, Interesting)

    by TechyImmigrant ( 175943 ) on Saturday September 12, 2015 @02:19PM (#50510569) Homepage Journal

    I log in a root to the server of my HOA:

    Last failed login: Sat Sep 12 11:52:54 PDT 2015 from 43.229.53.41 on ssh:notty
    There were 59462 failed login attempts since the last successful login.

    So over 59000 attempts since last week, on a server with nothing of interest to anyone.

  • A talking head telling us what we could read below. Is this the future of the Internet - TELEVISION ..
  • by nickweller ( 4108905 ) on Saturday September 12, 2015 @03:10PM (#50510727)
    "Incident reports .. shows a near-consistent barrage of attempts to breach the security of critical information systems that contain sensitive data about the nation's power grid, nuclear weapons stockpile and energy labs."

    Have you considered not connecting your critical infrastructure directly to the Internet. The fact that the 'Cyber attackers' can even see your computers shows extreme complacency by whoever is in charge of your 'computers'.
    • Comment removed based on user account deletion
      • @toejam13: "For all we know .. there was an air gap between it and the outside .. In many cases, you just need a wireless adapter and the proper software" ..

        a) We do know there wasn't an 'air gap' as the compromised servers were connected to the Internet. That's the meaning behind the words 'cybersecurity breach'.

        b) An air gaped computer with a wireless adapter isn't really air gapped.

        c) I never mentioned 'air gap'ed ...
  • by account_deleted ( 4530225 ) on Saturday September 12, 2015 @05:24PM (#50511155)
    Comment removed based on user account deletion

Sendmail may be safely run set-user-id to root. -- Eric Allman, "Sendmail Installation Guide"

Working...