EPA denies breach after hacker posts 8.5 million contact records

Organization
U.S. Environmental Protection Agency (EPA)
Exploit
Hacking
Industry
Government

A threat actor using the handle USDoD posted a dataset on a criminal forum in early April 2024 and said it came from the U.S. Environmental Protection Agency's database of critical infrastructure contacts.

The posting appeared on April 7, 2024. The actor claimed the EPA database had been shared with a total of 15 million rows. An analysis of the files by Hackread found three of them, named Contact, Inter_Contact and Staff, holding about 17 million records that reduced to roughly 8.46 million accounts once duplicates were filtered out. Reported fields included names, email addresses, phone and fax numbers, mailing addresses, job titles, employer names and location data. No passwords were included. Accounts of the file size differed: CSO Online described about 500 megabytes of compressed CSV data, while The Record reported the actor offering 3 gigabytes.

The EPA disputed that any intrusion had taken place. An agency spokesperson said a preliminary analysis indicated the material was business contact information already published to give a comprehensive picture of environmental impacts, drawn from the EPA's public Facility Registry Service. The agency later said there had been no breach of its data and that the actor had acknowledged never entering EPA systems, an assessment it said CISA and the FBI shared.

Analysts who examined the records generally considered them authentic, while noting that a consolidated list of infrastructure contacts could still be useful to attackers running phishing campaigns.

Sources