Hackers were able to gain access to the Office of Personnel Management’s networks using credentials stolen from an agency contractor, but they might not have had to work that hard.
More: Contractor breach gave hackers a way in to OPM data
A new report issued by threat intelligence company Recorded Future shows government logins and passwords are widely available on the open Internet. Coupled with a lack of multifactor authentication, this exposes agencies to a significant threat.
Special Report: The OPM Data Breach: What You Need to Know
Researchers scanned paste sites – open online text repositories used for any manner of sharing – and discovered user names and emails and their associated passwords for thousands of federal employees.
More: OPM breach a failure on encryption, detection
A search of more than 680,000 websites in seven languages found logins and passwords for 47 federal agencies on 89 separate domains. Recorded Future researchers note 12 of these agencies don’t use multifactor authentication to access their systems, enabling users to log on with just a username and password.
More: Could OPM have prevented the breach?
The data was largely obtained through low-level hacks, using known vulnerabilities and widely available malware. Specifically, known entry points were identified through a natural history museum, a news website and a single federal employee. Access through those vectors allowed hackers to gain entry to federal networks, discover more login credentials and release them on the Internet.
“The presence of these credentials on the open Web leaves these agencies vulnerable to espionage, socially engineered attacks and tailored spear-phishing attacks against their workforce,” the report reads. “While some agencies employ VPNs, two-factor authentication and other tokens to provide a safety net, many agencies lag behind as cited by the OMB report to congress.”
Recorded Future identified the Department of Energy as having the “widest exposure.” The Departments of Commerce and Interior were close behind.
Some of the larger paste sites, such as pastebin.com, immediately removed the logins and passwords from their sites, however others allow the exposed credentials to remain online.
The report notes that, “to Recorded Future’s knowledge, no efforts are made to contact government agencies whose credentials may be posted on a paste site.”




