Pentagon breach exposed sensitive data on nearly 3 million people

71 Views

It has been reported that a breach of the Pentagon’s sprawling personnel database exposed sensitive information belonging to a massive swath of military personnel, including Social Security numbers and details about the jobs they held, according to a U.S. defense official.

The breach affected 2.76 million living people and another 294,000 who are deceased, the official said. The scope and sensitivity of the exposed information could raise national security concerns, particularly because the files included details about the jobs performed by military and civilian personnel.

Commenting on this, Collin Hogue-Spears, Senior Director of Solutions Management at Black Duck, had the followingto say:

“The occupational specialty that DMDC’s letter lists for some people turns an identity-theft list into a roster an adversary can search by role. A Social Security number identifies a person. An occupational specialty tells an adversary why that person matters. U.S. data brokers already sell identified records on active-duty service members, and a list sorted by specialty narrows the search. No public record places these files with a buyer.

If they reach one, the sorting by specialty is already done. Security leaders must swap names, Social Security numbers, and contact details for a pseudonymous key for any export that carries job or role data. Resolve that key only inside the HR system of record. If your exports put job titles beside personal phone numbers, one file-share flaw hands an attacker your roster, phone numbers included. The Pentagon’s credit monitoring ends in 12 months. A record of who held which job does not.

Missing encryption is the headline; the harder failure is that Social Security numbers were reachable through a DMDC file-sharing system for nine months. Encryption at rest stops a stolen drive, not someone reading files through the system that decrypts them. DMDC has not said which kind of flaw it patched.

Data minimisation limits what any flaw can expose, because a file-sharing system cannot leak a Social Security number it never held. Security leaders must run DLP content discovery for Social Security numbers and other direct identifiers across every file-sharing and collaboration system this quarter. Remove unauthorised copies, and restrict approved ones to named accounts. Encryption asks how DMDC protected the files. The breach asks why a file-sharing system had them”.