05 Feb 2013
DOE employee passwords stolen
According to a NY Times , former Energy Department security official Ed McCallum states that the agency continues to have issues despite managing the most “sophisticated military and intelligence technology the country owns.” Here is the e-mail that the Energy Department sent to its employees:
The Department of Energy (DOE) has just confirmed a recent cyber incident that occurred in mid-January which targeted the Headquarters’ network and resulted in the unauthorized disclosure of employee and contractor Personally Identifiable Information (PII). The Department is strongly committed to protecting the integrity of each employee’s PII and takes any cyber incident very seriously. The Department’s Cybersecurity Team, the Office of Health, Safety and Security and the Inspector General’s office are working with federal law enforcement to promptly gather detailed information on the nature and scope of the incident and assess the potential impacts to DOE staff and contractors. Based on the findings of this investigation, no classified data was compromised. We believe several hundred DOE employees’ and contractors’ PII may have been affected. As individual affected employees are identified, they will be notified and offered assistance on steps they can take to protect themselves from potential identity theft. Once the full nature and extent of this incident is known, the Department will implement a full remediation plan. As more specific information is gathered regarding affected employees and contractors, the Department will make further notifications. The Department is also leading an aggressive effort to reduce the likelihood of these events occurring again. These efforts include leveraging the combined expertise and capabilities of the Department’s Joint Cybersecurity Coordination Center to address this incident, increasing monitoring across all of the Department’s networks and deploying specialized defense tools to protect sensitive assets. Cybersecurity is a shared responsibility, and we all play an important role in maintaining the integrity and security of our networks. To help minimize impacts and reduce any potential risks, please keep the following best practices in mind: * Encrypt all files and emails containing PII or sensitive information, including files stored on hard drives or on the shared network. * Do not store or email non-government related PII on DOE network computers]]>