US military notifies 20,000 of data breach after cloud email leak

Date:

Share post:


The U.S. Department of Defense is notifying tens of thousands of individuals that their personal information was exposed in an email data spill last year.

According to the breach notification letter sent out to affected individuals on February 1, the Defense Intelligence Agency — the DOD’s military intelligence agency — said, “numerous email messages were inadvertently exposed to the Internet by a service provider,” between February 3 and February 20, 2023.

TechCrunch has learned that the breach disclosure letters relate to an unsecured U.S. government cloud email server that was spilling sensitive emails to the open internet. The cloud email server, hosted on Microsoft’s cloud for government customers, was accessible from the internet without a password, likely due to a misconfiguration.

The DOD is sending breach notification letters to around 20,600 individuals whose information was affected.

“As a matter of practice and operations security, we do not comment on the status of our networks and systems. The affected server was identified and removed from public access on February 20, 2023, and the vendor has resolved the issues that resulted in the exposure. DOD continues to engage with the service provider on improving cyber event prevention and detection. Notification to affected individuals is ongoing,” said DOD spokesperson Cdr. Tim Gorman in an email to TechCrunch.

DefenseScoop first reported news of the breach notification letters.

TechCrunch exclusively reported in February 2023 that the DOD was spilling about three terabytes of internal military emails, some of which pertained to U.S. Special Operations Command, or SOCOM, which carries out special military operations overseas. Some of the exposed information included sensitive personnel information and questionnaires by prospective federal employees seeking security clearances.

Anyone with the public IP address of the exposed cloud email server could access the sensitive but unclassified emails inside using only a web browser.

Security researcher Anurag Sen discovered the exposed data spilling online and asked for TechCrunch’s help in reporting the data exposure to the U.S. government. TechCrunch reported the spill to SOCOM on February 19. The cloud email server was secured on February 20 after TechCrunch escalated the incident to senior U.S. government officials after not hearing back.

It’s not clear for what reason the DOD took a year to investigate the incident or notify those affected.

A spokesperson for Microsoft did not respond to a request for comment.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

Microsoft’s new ‘Volumetric Apps’ for Quest headsets extend Windows apps into the 3D space

Microsoft announced on Tuesday during its annual Build conference that it’s bringing “Windows Volumetric Apps” to Meta...

The ‘vote Trump’ spam that hit Bluesky in May came from decentralized rival Nostr

Decentralized social networks aren’t immune to botnet-driven spam, as a recent spam attack on Bluesky demonstrates. Earlier...

There’s a real appetite for a fintech alternative to QuickBooks

Welcome to TechCrunch Fintech! This week, we’re looking at the continued fallout from Synapse’s bankruptcy, how Layer...

Bill Gates-backed wind startup AirLoom is raising $12M, filings reveal

It started with a drawing on a napkin. Now, AirLoom Energy is raising $12.7 million in fresh...

As a U.S. ban looms, TikTok announces a $1M program for socially driven creators

TikTok is pulling out all the stops to prevent its impending ban in the United States. Aside...

Stack AI wants to make it easier to build AI-fueled workflows

Stack AI’s co-founders, Antoni Rosinol and Bernardo Aceituno, were PhD students at MIT wrapping up their degrees...

Senate study proposes ‘at least’ $32B yearly for AI programs

A long-running working group in the Senate has issued its policy recommendation for federal funding for AI:...

FBI seizes hacking forum BreachForums — again

The FBI along with a coalition of international law enforcement agencies seized the notorious cybercrime forum BreachForums...