SC247    Topics     Technology    Security    TrapX

China Suspected of U.S. Postal Service Hack

The U.S. Postal Service said today it is the victim of a cyberattack and that information about its employees, including Social Security numbers, may have been compromised.


As President Obama gallivants about in a Vulcan costume behind the Bamboo Curtain, his mandarin hosts have been busy spying on the United States Postal Service (USPS).

The Washington Post reports that the Chinese government is suspected of breaching the computer networks of the senescent government agency charged with delivering our snail mail.

The data of more than 800,000 employees have reportedly been compromised:

The compromised data included names, dates of birth, Social Security numbers, addresses, dates of employment and other information, officials said. Every employee from the letter carrier to the postmaster general was exposed. But no customer credit card information from post offices or online purchases at usps.com was breached, they said.

The Postal Service was notified of the breach by the FBI and other federal agencies in mid-September. Planning to deal with the hack began immediately, but the actual remediation did not take place until the weekend.

Earlier this year, the Office of Personnel Management and a security-clearance contracting company were also hacked. But it was fairly clear why the Chinese government should target both these institutions: They are staffed by people with security clearances and access to potentially sensitive government information.

Experts are not entirely sure why China would target the USPS, of all places. But one potential reason for its interest in the Newmans of the federal workforce is that, well, China just doesn’t know any better:

Some analysts say that targeting a federal agency such as the post office makes sense for China as an espionage tool. For one thing, the Chinese may be assuming that the U.S. Postal Service is more like theirs - a state-owned entity that has vast amounts of data on its citizens.

China might also just be vacuuming up as much data as possible in its search for new intelligence leads of any kind. Of particular interest, for example, could be the photographs of addressing information stored by the USPS at the behest of American law enforcement.

The Associated Press reports that the postal service security breach is one among many in recent years:

From 2009…to 2013, the number of reported breaches just on federal computer networks…rose from 26,942 to 46,605, according to the U.S. Computer Emergency Readiness Team or US-CERT. Last year, US-CERT responded to a total of 228,700 cyberincidents involving federal agencies, companies that run critical infrastructure like nuclear power plants, dams and transit systems, and contract partners. That’s more than double the incidents in 2009.

But the zinger is that gullible or otherwise careless federal employees are responsible for at least half of known cyberattacks since 2010:

They have clicked links in bogus phishing emails, opened malware-laden websites and been tricked by scammers into sharing information.

Last year…about 21 percent of all federal breaches were traced to government workers who violated policies; 16 percent who lost devices or had them stolen; 12 percent who improperly handled sensitive information printed from computers; at least 8 percent who ran or installed malicious software; and 6 percent who were enticed to share private information.

Given the government’s poor track record of protecting sensitive data, it may only be a matter of time before a serious breach threatens the personal information of millions of Americans.

Source: reason.com

Related Article: Malware Hidden In Chinese Inventory Scanners Targeting Logistics and Shipping Companies

Download the White Paper: Anatomy of the Attack: Zombie Zero

Article Topics


TrapX News & Resources

China Suspected of U.S. Postal Service Hack
Anatomy of the Attack: Zombie Zero
Malware Hidden In Chinese Inventory Scanners Targeting Logistics and Shipping Companies

Latest in Technology

Spotlight Startup: Cart.com is Reimagining Logistics
Walmart and Swisslog Expand Partnership with New Texas Facility
Taking Stock of Today’s Robotics Market and What the Future Holds
Biden Gives Samsung $6.4 Billion For Texas Semiconductor Plants
Apple Overtaken as World’s Largest Phone Seller
Walmart Unleashes Autonomous Lift Trucks at Four High-Tech DCs
Talking Supply Chain: Procurement and the AI revolution
More Technology

TrapX is a leading provider of cloud-based and on-premises cyber-security solutions. Some of the world’s leading Global 2000 enterprises serving the financial services, national critical infrastructure, retail, healthcare, pharmaceutical, and other industries rely on TrapX to strengthen their IT ecosystems and reduce the risk of costly and disruptive compromises, data breaches, and compliance violations. With the TrapX 360 platform, Global 2000 enterprises are able to detect and analyze Zero-Day and undetected malware used by the world’s most destructive Advanced Persistent Threat (APT) organizations, build threat profiles, block attacks, and automatically remediate damage inflicted on IT ecosystems. The TrapX 360 platform captures Zero-Day malware in its virtualized sensor network of honeypots and next-generation malware traps before the malware can inflict significant damage to customers’ data centers or cloud deployments.


View TrapX company profile

 

Featured Downloads

GEP Procurement & Supply Chain Tech Trends Report 2024
GEP Procurement & Supply Chain Tech Trends Report 2024
We’ve researched the five biggest trends in the supply chain space this year, and, drawing on our expertise in procurement and...
Unified Control System - Intelligent Warehouse Orchestration
Unified Control System - Intelligent Warehouse Orchestration
Download this whitepaper to learn Unified Control System (UCS), designed to orchestrate automated and human workflows across the warehouse, enabling automation technologies...

An Inside Look at Dropshipping
An Inside Look at Dropshipping
Korber Supply Chain’s introduction to the world of dropshipping. While dropshipping is not for every retailer or distributor, it does provide...
C3 Solutions Major Trends for Yard and Dock Management in 2024
C3 Solutions Major Trends for Yard and Dock Management in 2024
What trends you should be focusing on in 2024 depends on how far you are on your yard and dock management journey. This...
Packsize on Demand Packing Solution for Furniture and Cabinetry Manufacturers
Packsize on Demand Packing Solution for Furniture and Cabinetry Manufacturers
In this industry guide, we’ll share some of the challenges manufacturers face and how a Right-Sized Packaging On Demand® solution can...