DEA Investigating Breach of Law Enforcement Data Portal
krebsonsecurity.com
krebsonsecurity.com
I think Krebs misses the point a little with the discussion of MFA and PIV cards - sure, this system should absolutely have MFA, but what it really should do is not exist in the first place, and barring that, at least have scoped access control.
https://www.beyondidentity.com/blog/us-government-now-requir...
That reporting also showed how the core members of LAPSUS$ were involved in selling a service offering fraudulent Emergency Data Requests (EDRs), wherein the hackers use compromised police and government email accounts to file warrantless data requests with social media firms, mobile telephony providers and other technology firms, attesting that the information being requested can’t wait for a warrant because it relates to an urgent matter of life and death.
If we assume for the moment that state-sponsored foreign hacking groups can gain access to sensitive government intelligence in the same way as teenage hacker groups like LAPSUS$, then it is long past time for the U.S. federal government to perform a top-to-bottom review of authentication requirements tied to any government portals that traffic in sensitive or privileged information.