[ad_1]
The U.S. Department of Defense (DOD) has begun the process of alerting approximately 20,000 people regarding the exposure of their personal data due to an email leak from a cloud server last year.
A notification letter dated February 1 indicates that the Defense Intelligence Agency—a key intelligence division within the DOD—reported that “a number of email messages” were unintentionally made public on the internet by a service provider between February 3 and February 20, 2023.
As gathered by TechCrunch, the letters of disclosure pertain to an unprotected U.S. government cloud-based email server that unwittingly made sensitive emails available on the internet due to what appears to be a configuration mistake. This server was part of Microsoft’s specialized cloud services tailored for government clientele and was inadvertently left accessible without requiring a password.
The DOD has initiated the distribution of breach notification letters to the roughly 20,600 individuals whose data was implicated in this incident.
DOD spokesperson Cdr. Tim Gorman communicated via email to TechCrunch, stating: “Our standard policy, which is centered on operational security, prevents us from discussing the details of our network and system statuses. The compromised server was detected and its public accessibility was promptly revoked on February 20, 2023. The service provider has since addressed the flaws that led to the data exposure. We continue our collaboration with the service provider to strengthen our capabilities to prevent and detect cybersecurity events more efficiently. The process of informing the individuals impacted is currently in motion.”
News of the breach notification letters was initially disclosed by DefenseScoop.
In February 2023, TechCrunch exclusively reported that the DOD inadvertently disclosed roughly three terabytes of internal military correspondence. These emails included some from the U.S. Special Operations Command (SOCOM), which is responsible for overseeing specialized military initiatives abroad. The leaked data also comprised sensitive personal information and security clearance questionnaires completed by prospective federal employees.
The compromised cloud email server’s data was accessible to anyone possessing its public IP address. Access to the confidential but unclassified emails was possible via a simple web browser.
Anurag Sen, a security researcher, identified the data being openly disseminated online and sought the assistance of TechCrunch to convey details of the exposure to U.S. government authorities. TechCrunch relayed their findings to SOCOM on February 19. The server at risk was secured the next day, on February 20, subsequent to TechCrunch’s report and escalated communications with high-level government officials due to lack of initial response.
The reasons behind the DOD’s one-year delay in investigating the incident and the eventual notification of the affected parties remain uncertain at this time.
Microsoft, as the cloud service provider, did not offer a response when asked for a comment on the matter.
[ad_2]
FAQ about the US Military Data Breach
- How many individuals were affected by the US military cloud email leak?
- About 20,600 individuals were notified that their personal information was exposed due to the leak.
- When did the email data breach occur?
- The data breach occurred between February 3 and February 20, 2023.
- How was the email server breach discovered?
- The breach was discovered by security researcher Anurag Sen, who then reported it to TechCrunch.
- What type of information was exposed in the breach?
- The exposed information included sensitive but unclassified emails, personal information, and security clearance documentation.
- Has the vulnerable server been secured?
- Yes, the server was secured on February 20, 2023, after TechCrunch escalated the incident to U.S. government officials.
- Why did it take a year for the DOD to notify the affected individuals?
- The exact reasons for the delay in investigation and notification by the DOD are unclear.
Conclusion
The inadvertent exposure of thousands of individuals’ personal data through an unprotected U.S. government cloud email server raises significant concerns about cybersecurity practices within the Department of Defense. Though the server has been secured, the delayed notification of affected individuals underscores the complexities and challenges in responding to data breaches. Continuous efforts to improve data protection and breach response times are essential to maintain trust and the security of sensitive information in the digital age.










































