US Government sued after mass emails to federal workforce allegedly sent from insecure server – Computerworld
The OPM, of course, has form when it comes to data security. In 2015, it detected a huge data breach affecting 22.1 million employee records, including PII such as social security numbers. That led to Congressional hearings and several government reports that identified a depressing list of underlying causes.
But with this history in mind, the idea that an unknown party could simply plug their email server into the OPM network without security vetting of either the server itself or its data collection and storage routines will astonish anyone in cybersecurity.
The incident suggests a culture where speed and shock matters above all. It’s not clear how many employees were forewarned that the emails might turn up but asking employees to reply to an email or click on a link is lax in an era of phishing attacks. That’s before considering the possibility that the email server or its data might itself be targeted.
Source link