Attackers hacked Department of Energy 159 times in 4 years
Cyberattackers successfully compromised U.S. Department of Energy computer systems 159 times over a span of 48 months.
After filing a Freedom of Information Act request, USA Today scored on the Energy Department’s Joint Cybersecurity Coordination Center report. Federal records revealed that between 2010 and 2014:
- The DOE was attacked 1,131 times.
- There were 159 successful cyber intrusions.
- 53 of the 159 successful compromises “were ‘root compromises,’ meaning perpetrators gained administrative privileges to Energy Department computer systems.” It is unclear if those DOE computers were office PCs, or if the root compromises were on computers managing critical infrastructure. The DOE is not known for having good operational security habits; after the Inspector General audited the Energy Department last year, the report said 41 DOE servers and 14 workstations “were configured with default or easily guessed passwords.”
- 90 of the 159 successful hacks “were connected to the DOE's Office of Science, which directs scientific research and is responsible for 10 of the nation's federal energy laboratories.”
- Over the same 4-year period, “the National Nuclear Security Administration, a semi-autonomous agency within the Energy Department responsible for managing and securing the nation's nuclear weapons stockpile, experienced 19 successful attacks.”
“The potential for an adversary to disrupt, shut down (power systems), or worse … is real here,” stated Scott White, Drexel University Professor of Homeland Security and Security Management and Director of the Computing Security and Technology. “It's absolutely real.”
To read this article in full or to leave a comment, please click here