Idaho National Laboratory confirmed HR system breach claimed by SiegedSec

Organization
Idaho National Laboratory
Exploit
Hacking
Industry
Nuclear Research

Idaho National Laboratory, the U.S. Department of Energy site that conducts nuclear energy and critical infrastructure research, confirmed in November 2023 that human resources data on its workforce had been stolen and published online. The hacktivist collective SiegedSec announced the theft on Telegram on November 19, 2023 and released the files publicly rather than demanding payment.

The compromised system was a cloud-hosted Oracle Human Capital Management platform used for the laboratory's HR applications and run from an off-site data center. INL said its own systems and networks were not breached. A laboratory spokesperson confirmed the incident and said INL had moved immediately to protect employee data while the scope was assessed.

The leaked records covered current and former employees along with retirees, postdoctoral researchers, graduate fellows, interns, and their spouses and dependants. Fields in the published files included full names, dates of birth, home addresses, email addresses, telephone numbers, Social Security numbers, salary and banking details, and employment status. Sample files reviewed by CyberScoop carried entries updated as recently as October 31, 2023.

INL said it was working with the Department of Energy, the FBI and the Cybersecurity and Infrastructure Security Agency. The laboratory did not initially state how many people were affected. It later put the figure at just over 45,000 and began sending notification letters in December 2023, with credit monitoring and identity protection offered through Experian.

Updates

  1. Idaho National Laboratory began notifying affected people on December 12, 2023, putting the number at 45,047 current and former employees along with dependents and spouses. Exposed data included Social Security numbers, salary information and bank account details.

Sources