• Starting today August 7th, 2024, in order to post in the Married Couples, Courting Couples, or Singles forums, you will not be allowed to post if you have your Marital status designated as private. Announcements will be made in the respective forums as well but please note that if yours is currently listed as Private, you will need to submit a ticket in the Support Area to have yours changed.

Federal court filing system hit in sweeping hack, compromising identities of confidential informants

essentialsaltes

Fact-Based Lifeform
Oct 17, 2011
42,494
45,605
Los Angeles Area
✟1,014,154.00
Country
United States
Faith
Atheist
Marital Status
Legal Union (Other)
The electronic case filing system used by the federal judiciary has been breached in a sweeping cyber intrusion that is believed to have exposed sensitive court data across multiple U.S. states, according to two people with knowledge of the incident.

The hack, which has not been previously reported, is feared to have compromised the identities of confidential informants involved in criminal cases at multiple federal district courts, said the two people, both of whom were granted anonymity because they were not authorized to speak publicly about the hack.

It is not immediately clear who is behind the hack, though nation-state-affiliated actors are widely suspected, the people said. Criminal organizations may also have been involved, they added.

In addition to records on witnesses and defendants cooperating with law enforcement, the filing system includes other sensitive information potentially of interest to foreign hackers or criminals, such as sealed indictments detailing non-public information about alleged crimes, and arrests and search warrants that criminal suspects could use to evade capture.

The incident does not appear to have exposed the most highly protected federal court witnesses, [which data is held by DoJ]
 

ThatRobGuy

Part of the IT crowd
Site Supporter
Sep 4, 2005
28,245
17,044
Here
✟1,470,317.00
Country
United States
Gender
Male
Faith
Atheist
Marital Status
Single
Politics
US-Others
Granted, I've only had very limited exposure to the inner workings of some of the infrastructure setups for things happening at a federal level...but I have a fair amount of experience with state government systems in a few different states. If the federal systems are the same (or even only just a little bit better, but not a lot) - then there's cause for concern.


In a lot of cases, what they refer to as "hacks" aren't even actually hacks, but merely accessing stuff that easily accessible due to a weak design.

I may be getting "into the tech weeds", but remember when they arrested that guy and putting him in prison, who they called "A hacker named Weev" claiming he "hacked AT&T", when it turns out, all he did was simply discover that AT&T's old tablet-version of the account management app used the account number in the URL query string. He found that if you incremented the number, there was no re-auth, and it would simply show you someone else's account info (their address, email address, name, etc...)

He wrote a loop that would start at 1, and go up to 200,000, and scrape the info off the page (not hard to do), and he ended up harvesting the email addresses of over 100k people, and sent the info to a reporter to say "hey, look, AT&T is exposing customer info".

The reality is, he didn't hack anyone at all, he didn't bypass or disable any security systems, he merely scraped something that was already easily accessible to anyone with above-average tech savvy.


When big fortune 500 companies or governments call things "hacks", everyone should keep their "bovine excrement detectors" on high... because in many cases, that's a "saving face" move to avoid talking about the fact that they were exposing something inadvertently. If they present it as "we were the victims of elite hackers", it lets them convey the notion that they did everything right and didn't skimp on the design.
 
Upvote 0

Belk

Senior Member
Site Supporter
Dec 21, 2005
30,709
15,174
Seattle
✟1,176,698.00
Gender
Male
Faith
Agnostic
Marital Status
Married
This is CJIS data. Not sure if you have dealt with CJIS at all but it is not accessible outside the secured system. This was most likely a breaching attack of some sort. I don't doubt that it was something left open foolishly or was phished in some fashion but I doubt it was simply a exploited loophole.
 
Upvote 0

Hans Blaster

Raised by bees
Mar 11, 2017
22,010
16,565
55
USA
✟417,317.00
Country
United States
Gender
Male
Faith
Atheist
Marital Status
Private
Politics
US-Democrat
I'm not sure how much we can learn from "weev". He is a very slimy person.
 
Upvote 0

ThatRobGuy

Part of the IT crowd
Site Supporter
Sep 4, 2005
28,245
17,044
Here
✟1,470,317.00
Country
United States
Gender
Male
Faith
Atheist
Marital Status
Single
Politics
US-Others
I'm not sure how much we can learn from "weev". He is a very slimy person.
I'm aware of his persona, yes...

I obviously wasn't suggesting that we learn from him (as in his ideas), more or less just wanted to highlight the fact that what a lot of big companies and government entities will call "hacking" isn't actually hacking at all, and it's just a way for those entities to save face (and sometimes get revenge) when they've been publicly embarrassed.


With regards to hacking, I like the analogy one of my professors some 20 years backed used.

If there's a big wall that's designed for the purpose stopping you from seeing what's inside...
If you build an apparatus to destroy the wall or get over the wall to see what's in there, you're a hacker
If they already have a big hole in their wall and you merely look through it and make others aware of it so they can look through it too, you're not a hacker
 
Upvote 0

essentialsaltes

Fact-Based Lifeform
Oct 17, 2011
42,494
45,605
Los Angeles Area
✟1,014,154.00
Country
United States
Faith
Atheist
Marital Status
Legal Union (Other)
Reactions: DaisyDay
Upvote 0