U.S. Department of Defense notified 20,600 people of 2023 email exposure
- Organization
- U.S. Department of Defense
- Exploit
- Misconfiguration
- Industry
- Federal Government
The U.S. Department of Defense started notifying people in February 2024 that their personal information had been caught up in an email exposure that took place a year earlier. A Pentagon spokesperson put the number affected at more than 20,600, after initial reporting had said more than 26,000. Letters dated February 1, 2024 and sent by the Defense Intelligence Agency told recipients that numerous email messages had been inadvertently exposed to the internet by a service provider between February 3 and February 20, 2023.
The messages sat on a cloud email server hosted on Microsoft's platform for U.S. government customers, which had been left reachable without a password. The exposed mailbox held about three terabytes of internal military email, described as sensitive but unclassified, including correspondence tied to U.S. Special Operations Command and completed security clearance questionnaires submitted by people seeking federal employment.
Security researcher Anurag Sen found the open server in February 2023 and alerted TechCrunch, which passed the finding to senior U.S. officials. The server was removed from public access on February 20, 2023.
A Pentagon spokesperson said the vendor had resolved the issues that resulted in the exposure and that the department was continuing to work with the service provider on improving prevention and detection. The notification letters said there was no evidence the exposed information had been misused, and offered recipients identity theft protection services.
Sources
- TechCrunch, US military notifies 20,000 of data breach after cloud email leak
- Nextgov/FCW, The Pentagon is notifying individuals affected by 2023 email data breach
- ClearanceJobs, Pentagon Notifies Thousands of Individuals of Data Breach Impacting Sensitive Military Emails
- DefenseScoop, DOD notifying more than 26,000 people who may be impacted by a year-old data breach