HomeSecurityIdaho National Laboratory: Data breach affects 45,000 people

Idaho National Laboratory: Data breach affects 45,000 people

The Idaho National Laboratory (INL) has confirmed breach data affecting more than 45,000 people. The breach stemmed from a breach of the Oracle HCM last month.

Idaho National Laboratory Laboratory

INL is one of 17 national laboratories of the U.S. Department of Energy (DOE) and employs 6,100 researchers and support staff engaged in national security and nuclear research.

On November 20, it announced a breach that affected its off-site Oracle HCM system. The impact of the incident is still being investigated, and both CISA and the FBI.

See also: Americold: Data breach after malicious attack

The research lab says in breach notification letters that the perpetrators made off with the data of 45,047 current and former employees (including graduate fellows and interns), as well as their own individuals (e.g., their spouses).

The breach did not affect employees hired after June 1, 2023. While the lab is still investigating the full impact of the incident, it said that various sensitive personal data, including names, Social Security numbers, salary information and banking details, were affected.

The incident did not impact INL's network or other networks or databases used by employees, lab customers, or other contractors. The breach only affected the cloud-based Oracle HCM test environment located off-site“.

See also: Toyota: Data breach affects personal and financial information

A well-known hacking group claimed responsibility via social media, but further investigation is needed to confirm this information“.

The group that claimed responsibility for the data breach at the research lab is hacktivists SiegedSec , who allegedly leaked stolen HR data to a hacking forum

It appears that the SiegedSec group made no attempt to negotiate or demand a ransom from INL. They simply published the data directly online.

data breach
Idaho National Laboratory: Data breach affects 45,000 people

They provided evidence of their access to systems through an announcement they made using the INL system to alert the entire campus. There were also screenshots of INL internal tools.

SiegedSec claims that the data leaked online includes a wide range of sensitive information, including affected individuals' names addresses email, phone numbers, Social Security Numbers (SSNs), physical addresses, and employment information.

See also: Norton Healthcare: May ransomware attack led to data breach

A potential consequence of this data breach is a loss of public trust in the research laboratory. Citizens and partners may be concerned about the security of their personal data and the laboratory's ability to protect their information.

Another potential risk is the misuse of employees' personal data. Hackers may use this information to commit fraud, steal identities, or cause damage to employees.

Furthermore, this breach may lead to a loss of trust from the government or other organizations that collaborate with the research laboratory. This loss of trust may have negative consequences for collaboration, information , and achieving common goals in future research and development.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS