The Department of Energy, the US Army, and the Department of Health and Human Services are all mentioned as targets.
The attacks are said to have started last December, using an exploit present in Adobe's ColdFusion software. After gaining access, the perpetrators reportedly installed back doors in the systems so they could regain access at a later date; Reuters states that many of the compromised computers were still being accessed as of last month. The FBI memo tell IT personnel how to evaluate whether their systems have been compromised.
As for the stolen information, an October 11th email from Kevin Knobloch, the Energy Secretary's chief of staff, reportedly states that information on at least 104,000 DOE employees, family members, and contractors had been pilfered. The email also warns that details on nearly 2,000 bank accounts had also been stolen.
Via : The Verge
Source : Reuters
No comments