U.S. Department of Defense notified 20,600 people of 2023 email exposure

Organization
U.S. Department of Defense
Exploit
Misconfiguration
Industry
Federal Government

The U.S. Department of Defense started notifying people in February 2024 that their personal information had been caught up in an email exposure that took place a year earlier. A Pentagon spokesperson put the number affected at more than 20,600, after initial reporting had said more than 26,000. Letters dated February 1, 2024 and sent by the Defense Intelligence Agency told recipients that numerous email messages had been inadvertently exposed to the internet by a service provider between February 3 and February 20, 2023.

The messages sat on a cloud email server hosted on Microsoft's platform for U.S. government customers, which had been left reachable without a password. The exposed mailbox held about three terabytes of internal military email, described as sensitive but unclassified, including correspondence tied to U.S. Special Operations Command and completed security clearance questionnaires submitted by people seeking federal employment.

Security researcher Anurag Sen found the open server in February 2023 and alerted TechCrunch, which passed the finding to senior U.S. officials. The server was removed from public access on February 20, 2023.

A Pentagon spokesperson said the vendor had resolved the issues that resulted in the exposure and that the department was continuing to work with the service provider on improving prevention and detection. The notification letters said there was no evidence the exposed information had been misused, and offered recipients identity theft protection services.

Sources