Thousands of US government workers have data leaked online

Data Breach
Image Credit: Shutterstock (Image credit: Shutterstock)

The US Transportation Department (USDOT) has been hit by a cyberattack that saw data on current and former employees stolen.

In a report, Reuters, citing “sources briefed on the matter”, states that the incident affected a total of 237,000 people - 114,000 current USDOT employees, and 123,000 former ones.

The agency, in charge of handling the US transportation system, has notified Congress of the breach via an email seen by Reuters, which said that the breach was "isolated [...] to certain systems at the department used for administrative functions, such as employee transit benefits processing."

Safety systems unaffected

The systems referenced in the email process TRANServe transit benefits that reimburse government employees for some commuting costs, it was said. 

The announcement does not discuss which data was taken, if there is enough to run identity theft attacks, or if any payment information was compromised. The organization also did not discuss if the data was already used in the wild for criminal purposes. Transportation safety systems were unaffected by the breach, USDOT added, and claims it doesn’t know which threat actor was behind the breach.

The incident is currently being investigated, and the organization froze access to the transit benefit system until it’s deemed safe again. As per the Reuters report, the maximum benefit allowance is $280 per month, for federal employee mass transit commuting costs. 

Government agencies and their staff are a constant target as cybercriminals, both state-sponsored and profit motivated, seek vulnerabilities to exploit and sensitive data to steal. 

Employee information can either be used to run even more devastating attacks, or it can be sold on the dark web for profit. 

Recently, the US government banned the TikTok app from agency-issued mobile devices, claiming matters of national security. 

The country is also looking to use its RESTRICT act to ban TikTok from even more users, again on the grounds of online safety.

This follows a recent report which found tracking pixels belonging to TikTok across numerous websites including US government pages. While tracking pixels - or web beacons - are typically used for collecting data to better target audiences with relevant ads, concerns have been raised about the information collected and how it may be used by the Chinese company and other entities in the country.

Via: Reuters

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
China
US Treasury declares ‘major incident’ after apparent state-sponsored Chinese hack
China US flags cropped
CISA says ‘no indication’ other US government agencies affected in Treasury hack
Representational image of data security
Travel data of almost 500,000 users exposed in Daytrip leak
US coast guard boat
US Coast Guard paychecks delayed by cyberattack
China
US Government officials urged to lock down devices amid telecoms breach
An American flag flying outside the US Capitol building against a blue sky
More alleged Chinese intrusions into the US Treasury revealed
Latest in Security
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Woman using iMessage on iPhone
Apple to take legal action against British Government over backdoor request
Red padlock open on electric circuits network dark red background
Aviaton firms hit by devious new polyglot malware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Latest in News
AMD Ryzen 9950X
Ryzen CPUs are the cheapest Zen 5 cores you can buy, but I was surprised to see this AMD 192-core CPUs on the value leaderboard
A hand holding a phone showing the Android Find My Device network
Android's Find My Device can now let you track your friends – and I can't decide if that's cool or creepy
Insta360 X4 360 degree camera without lens protector
Leaked DJI Osmo 360 image suggests GoPro and Insta360 should be worried – here's why
A YouTube Premium promo on a laptop screen
A cheaper YouTube Premium Lite plan just rolled out in the US – but you’ll miss out on these 4 features
Viaim RecDot AI true wireless earbuds
These AI-powered earbuds can also act as a dictaphone with transcription when left in their case
The socket interface of the Intel Core Ultra processor
Intel unveils its most powerful AI PCs yet - new Intel Core Ultra Series 2 processors pack in vPro for lightweight laptops and high-performance workstations alike