The Idaho National Laboratory confirmed that attackers stole the personal information of more than 45,000 individuals after breaching its cloud-based Oracle HCM HR management platform last month.
INL is one of 17 U.S. Department of Energy's national laboratories, and it employs 6,100 researchers and support staff involved in national security and nuclear research.
CISA and FBI are looking into its impact as part of an ongoing joint investigation.
The research lab says in breach notification letters filed with the Maine Attorney General's Office this week that the attackers exfiltrated the data of 45,047 current and former employees, as well as their dependents and spouses.
The breach did not affect employees hired after June 1, 2023.
While the laboratory is still investigating the incident's full impact, it said that multiple forms of sensitive personally identifiable information was affected, including names, social security numbers, salary information, and banking details.
Even though INL hasn't attributed the attack to a specific group, SiegedSec hacktivists claimed the attack on November 20 and leaked stolen human resources data on a hacking forum.
Just as they did when they leaked data allegedly stolen from NATO and Atlassian, SiegedSec has made no attempt to negotiate or demand a ransom from INL, directly publishing it online instead. They provided evidence of their access to INL's systems by sharing a custom announcement they made using INL's system to notify everyone on the campus, along with screenshots of internal INL tools.
SiegedSec claims the data they leaked online includes a wide range of sensitive information, including affected individuals' full names, dates of birth, email addresses, phone numbers, Social Security Numbers, physical addresses, and employment information.
Hacktivists breach U.S. nuclear research lab, steal employee data.
Toyota warns customers of data breach exposing personal, financial info.
Navy contractor Austal USA confirms cyberattack after data leak.
Auto parts giant AutoZone warns of MOVEit data breach.
Canadian government discloses data breach after contractor hacks.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Thu, 14 Dec 2023 18:00:19 +0000