The slow drip of information allegedly stolen from CIA Director John Brennan’s personal email account continues to find its way onto WikiLeaks, with a list of personal information about 20 members of President Obama’s transition team added to the leak in the most recent post on Oct. 26.
The list — which includes names, personal emails, phone numbers, Social Security numbers and more — was originally posted to Twitter by user @_CWA_ on Oct. 19, however the account was quickly suspended and the post removed.
After the Twitter account was shut down, “Crackas With Attitude” — the duo claiming to have perpetrated the hack — began slowly posting the information to WikiLeaks. The third and latest dump came on Oct. 26, including the list and the dossier of a FBI agent in the counterterrorism division.
The list posted Monday mostly includes names of former intelligence and national security officials, some of whom served under President George W. Bush and some who served or currently serve under President Barack Obama, including Homeland Security Secretary Jeh Johnson.
The names have something else in common, as well.
All of the people listed were part of the Obama administration’s transition team, with most of them serving on the National Security Team. The team members listed covered the Defense Department, DHS, CIA and Office of the Director of National Intelligence.
Only three names advised on other aspects of the transition but Federal Times confirmed that everyone whose information was exposed served in some capacity.
The document was created (or most recently updated) on Nov. 16, 2008, according to the associated metadata.
The breadth of the release is minor compared to the high-profile breach of the Office of Personnel Management last year but the implications are still serious, especially as this information was released publicly on the Internet.
“It’s a pretty serious proposition to have any of that information out there,” said Marcus Christian, a former federal prosecutor and current partner with the law firm of Mayer Brown’s cybersecurity and data privacy practice.
While the perpetrators reportedly used social engineering to trick a helpline support employee into changing Brennan’s account password, the subsequent exfiltration of data and postings online still constitute a cyber crime, Christian said.
“Often times we look to the technological solution [for cybersecurity] but often times the problem — no matter how intricate and hardened we think our technology happens to be — there’s always some weakness,” he said, including the human element.
If the perpetrators are caught, Christian expects they could be prosecuted under a combination of the Computer Fraud and Abuse Act and federal Aggravated Identity Theft statutes, with the latter carrying a two-year mandatory minimum sentence.




