USDA: Personal Data Safe

Forensics indicate personal data wasn't moved to an attacking computer

Dark Reading logo in a gray background | Dark Reading

The 25,000 employees and contractors from the U.S. Department of Agriculture whose personal data was at risk after last month's computer break-in can exhale -- for now. The agency informed them this week that forensic analysis concluded no personal identity information was downloaded or moved to a non-agency computer. (See Data Losses Hit Four More.)

But does that mean the data wasn't viewed by hackers? There's no way to know for sure until the data gets exploited, security experts say. "They are a little optimistic here," says Andrew Jaquith, senior analyst with Yankee Group Research Inc. "It's easy to get stuff without leaving an audit trail. They don't say anything about local access. Did somebody with a USB drive access it and copy it?"

A USDA spokesman couldn't confirm whether the data had at the very least been eyeballed by intruders. "We are confident that there wasn't any personal data transferred outside the [USDA computer] system or downloaded," he says.

The agency is apparently confident about the safety of the personal data, because it also announced it was halting the free credit-monitoring services it had offered the potentially victimized users, who are located in the Washington, D.C., area.

The USDA Inspector General's office is handling the investigation into the break-in. Its forensics analysis studied computer logs from a machine involved in the breach and concluded personal data hadn't been moved.

In a press release, USDA deputy secretary Chuck Conner acknowledged that hackers attempt break-ins at the agency on an average of 2,000 times a day. "We take very seriously our responsibility to protect personal information," Conner said in a USDA press release.

The agency says it's reviewing how to minimize the amount of personal data it stores on its systems as well as its security measures to protect such data. Yankee's Jaquith says reducing personal data on the agency's systems is a smart move.

— Kelly Jackson Higgins, Senior Editor, Dark Reading

Read more about:

2006

About the Author

Kelly Jackson Higgins, Editor-in-Chief, Dark Reading

Kelly Jackson Higgins is the Editor-in-Chief of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise Magazine, Virginia Business magazine, and other major media properties. Jackson Higgins was recently selected as one of the Top 10 Cybersecurity Journalists in the US, and named as one of Folio's 2019 Top Women in Media. She began her career as a sports writer in the Washington, DC metropolitan area, and earned her BA at William & Mary. Follow her on Twitter @kjhiggins.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights