NEW - IDC WebcastFree E-NewslettersRSS Feeds | Site Map
Security Resource CentreBusiness Value of TechnologyMunicipal Centre
SearchSearch
Tips
Collaboration
Slice by Program

U.S. tech labs report cyber attack

By: Ellen Messmer, Network World US (MD)(Dec 10, 2007 06:00:00)

Computer systems at Oak Ridge National Laboratory, an American science and technology lab under the U.S. Department of Energy, has reportedly suffered a cyber attack last week and there were indications other institutions may have also been targets.

Oak Ridge National Laboratory Thursday disclosed it has been compromised by what it described as a "sophisticated cyber attack that appears to be part of a coordinated attempt to gain access to computer networks at numerous laboratories and other institutions across the country."

Other reports indicate ORNL's sister institution at Los Alamos was also hit, though it has not been confirmed that Los Alamos was hit successfully.

In a public statement, Oak Ridge National Laboratory, which has 3,800 staff and US$1.06 billion budget under management by the U.S. Deptartment of Energy with UT-Battelle, said a hacker gained access to ORNL computers by sending staff e-mails that appeared to be official legitimate communications.

"When the employee opened the attachment or accessed an embedded link, the hacker planted a program on the employees' computers that enabled the hacker to copy and retrieve information," ORNL said.

ORNL said the compromise has been traced back to Oct. 29, 2007, and that the lab has "reason to believe that data was stolen from a database used for visitors to the Laboratory."

ORNL, which conducts highly sensitive energy research in the neutron science and high-energy physics as well as biology research, does not believe that classified information was lost. However, ORNL said anyone who visited the lab, which is based in Oak Ridge, Tenn., between the years 1990 and 2004 may have had their name and other personal information, such as Social Security numbers and birth date, stolen by the attackers.

Thom Mason, director of ORNL, on Monday sent an e-mail to staff employees that said, "Our cyber security staff has been working nights and weekends to understand the nature of this attack."

"Our review to date has shown that while every security system at ORNL was in place and in compliance, the hackers potentially succeeded in gaining access to one of the laboratory's non-classified databases that contained personal information of visitors to the laboratory between 1990 and 2004. At this point we have determined that the thieves made approximately 1,100 attempts to steal data with a very sophisticated strategy that involved sending staff a total of seven 'phishing' e-mails, all of which at first glance appeared legitimate. One of these fake e-mails notified employees of a scientific conference.

Another pretended to notify the employee of a complaint on behalf of the Federal Trade Commission, " Mason said.

Mason said it looks as though 11 staff opened the attachments, which then "enabled the hackers to infiltrate the system and remove data."

Mason said reconstructing the exact chain of events in their entirety "will likely take weeks, if not longer, to complete."

ORNL is making the effort to contact all the people whose personal information was compromised, but that a large number of out-of-date addresses is complicating this effort. He added there is no evidence to date that the stolen information has been used.

ORNL spokesman Ron Walli said the lab couldn't comment further on the nature of the attack or its possible origination due to its extreme sensitivity. "It's a serious matter and we've told not to discuss it," he said.

Related content:

Cyber attack prompts US to send team to Estonia

Government lags cyber crime fight, says report

RCMP urges cyber crime reporting
Bookmark on:del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article?
Add a new commentLetter to the Editor
Find an inappropriate comment? You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields
Blog Spotlight: Sandford Borins
Sandford Borins

As Professor of Strategic Management at the University of Toronto, Sandford Borins brings InterGovWorld.com readers exclusive insights into how and why the public sector is changing. You'll find new perspectives and questions, observations and objectives, lessons and answers. Cover to Cover, the blog by Prof. Sandford Borins, appears every Thursday.

Inside Cover to Cover

Unified Communications
Data Defence

Unity is a word often heard in the public sector, with myriad agencies and departments looking to foster collective thinking around some of today's most pressing issues. The word, however, doesn't usually get mentioned in the same breath as technology. That's a situation, though, that might soon be changing, thanks to a new software platform known as unified communications.

Inside the latest issue of CGR

More Resources
Driving innovation through effective service management
This white paper discusses how a service-oriented governance framework can help ensure that IT decisions are consistent with business vision, values and strategies-and that IT delivers maximum value to the business. Complimentary with registration.
IT Service Management Solutions and the service desk
This white paper presents the capabilities of IBM Tivoli CCMDB, and describes how Tivoli CCMDB extends the value of the service desk and integrates other essential ITIL processes in support of IBM Service Management. Complimentary with registration.
Info-Tech Research Note: WAN Optimization Tools worth the investment
Multi-site enterprises experiencing WAN bandwidth demand growth and struggling to maintain acceptable application performance should evaluate WAN optimization technology immediately. WAN optimization appliances can dramatically improve inter-site WAN performance, reduce bandwidth requirements, and allow for server centralization. For many enterprises a positive ROI can be achieved in less than a year. Download this research note now. Complimentary with registration.
Advertisement
2007 Salary Calculator
Knowledge Centres at a Glance
White Papers
read more white papers
New blog entries
Thoughts of the day
This week's top stories
Most popular stories of the week
Readers write back
Comments from Intergovworld readers
Government to government
Inside the public sector machine
Government to business
P3: Public-private partnerships
Government to citizen
e-Government service transformation
Blogs
Browse Blogs By:
WiFi Hot Spot Finder
Upload Centre
Upload Your Documents
Contribute and share with your peers by uploading:
- Initiative updates
- White Papers
- Job Links
- Events
- Other
Download Centre
Most popular downloads:
Download More Documents
Download:
- Initiative updates
- White Papers
- Job Links
Subscription Services
Manage your InterGovWorld.com account!
Change your account information, password, e-mail address, and existing e-newsletter subscriptions.
Site Feedback Survey
Tell us what you think of InterGovWorld.com!
FUN SurveyFUN Survey
Take the one-minute Family Unit Networking survey!
IT Salary Survey IT Salary Survey
Take the IT Salary Survey '06 Today
Career Resources
InterGovWorld provides links to resources for government job seekers and current employees, including: current job postings, job search strategies, career options and training, and employee rights, provided by all levels of government from everywhere across Canada.

Public Service Commission of Canada
Service Canada
Jobs in Canada
Service Canada
Public Service Human Resources Management Agency of Canada