It is unclear when the breach was discovered, but it is believed to have happened a couple weeks ago. A source familiar tells Fox the State Department’s ongoing mission to evacuate Americans and allied refugees in Afghanistan “have not been affected”.
-
-
Show this thread
-
The extent of the breach, investigation into the suspected entity behind it, efforts taken to mitigate it, and any ongoing risk to operations remains unclear. A DoS spox tells me:
Show this thread -
“The Department takes seriously its responsibility to safeguard its information and continuously takes steps to ensure information is protected. For security reasons, we are not in a position to discuss the nature or scope of any alleged cybersecurity incidents at this time.”
Show this thread -
Notably, a Senate Homeland Security committee report this month rated State Department’s overall information security a ‘D’, the lowest possible rating in the model, calling it ineffective in 4 of 5 function areas https://www.hsgac.senate.gov/imo/media/doc/Federal%20Cybersecurity%20-%20America's%20Data%20Still%20at%20Risk%20(FINAL).pdf …pic.twitter.com/ALqq94l1hd
Show this thread -
The scope of this attack can be inferred, to an extent, by congressional notification requirements. Under federal law each agency determines whether the cyberattack or info security incident meets “major incident” criteria – if so, they are required to tell Congress within 7 days
Show this thread
End of conversation
New conversation -
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
This Tweet is unavailable.
-
Too predictable at this point
End of conversation
-
-
-
Blood in the water…
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
BREAKING, thread:
The State Department has been hit by a cyber attack, and notifications of a possible serious breach were made by the Department of Defense Cyber Command.