Story image

NASA got hacked (again)

20 Dec 18

The US National Aeronautics and Space Administration (NASA) is one of 2018’s latest data breach casualties, according to media reports.

Website SpaceRef published a NASA internal company memo appearing to coming from Bob Gibbs, NASA’s assistant administrator in the Office of Chief Human Capital Officer.

The memo claims that criminals potentially gained access to NASA servers on October 23, 2018. The compromised servers stored personally identifiable information (PII) belonging to current and former NASA employees. That information included social security numbers and other data.

NASA Civil Service employees who were onboarded, separated from NASA, or transferred between locations from July 2006 to October 2018 may be affected.

The memo was sent to all NASA employees, regardless of whether they were affected by the breach. 

“Once identified, NASA will provide specific follow-up information to those employees, past and present, whose PII was affected, to include offering identity protection services and related resources, as appropriate,” the memo allegedly states.

NASA says that it took immediate action to secure servers and data as soon as it discovered the breach.

“NASA and its Federal cybersecurity partners are continuing to examine the servers to determine the scope of the potential data exfiltration and identify potentially affected individuals. This process will take time. The ongoing investigation is a top agency priority, with senior leadership actively involved. NASA does not believe that any Agency missions were jeopardized by the cyber incidents,” the memo states.

NASA’s leadership team stresses that it takes personal information protection and information security seriously.

“NASA is continuing its efforts to secure all servers, and is reviewing its processes and procedures to ensure that the latest security practices are being followed throughout the agency,” the memo concludes.

While NASA has not yet released any public statements about the breach, the company is no stranger to being a target.

Back in 2016 hacking group AnonSec leaked almost 276GB of confidential NASA data. 

The group even went so far as trying to hack and crash a $222 million NASA drone into the Pacific Ocean. But before the group could crash the drone, NASA spotted the security anomaly and took manual control.

In 2013, an Italian hacker belonging to the ‘Master Italian Hackers Team’ gained access and ‘defaced’ a number of NASA Ames Research Center subdomains, as well as a slew of Italian government websites.  In October 2018, the 25-year-old hacker was sentenced. He was caught after allegedly boasting about the hacks online.

Hillstone CTO's 2019 security predictions
Hillstone Networks CTO Tim Liu shares what key developments could be expected in the areas of security compliance, cloud, security, AI and IoT.
Can it be trusted? Huawei’s founder speaks out
Ren Zhengfei spoke candidly in a recent media roundtable about security, 5G, his daughter’s detainment, the USA, and the West’s perception of Huawei.
Oracle Java Card update boosts security for IoT devices
"Java Card 3.1 is very significant to the Internet of Things, bringing interoperability, security and flexibility to a fast-growing market currently lacking high-security and flexible edge security solutions."
Updated: Chch crypto-exchange Cryptopia suffers breach
Cryptopia has reportedly experienced a security breach that has taken the entire platform offline – and resulted in ‘significant losses’.
Sophos hires ex-McAfee SVP Gavin Struther
After 16 years as the APAC senior vice president and president for McAfee, Struthers is now heading the APJ arm of Sophos.
Security platform provider Deep Instinct expands local presence
The company has made two A/NZ specific leadership hires and formed several partnerships with organisations in the region.
Half of companies unable to detect IoT device breaches
A Gemalto study also shows that the of blockchain technology to help secure IoT data, services and devices has doubled in a year.
Stepping up to sell security services in A/NZ
WatchGuard Technologies A/NZ regional director gives his top tips on how to make a move into the increasingly lucrative cybersecurity services market.