IG finds data security practices lacking at Customs and Border Protection before big hack

The U.S. Customs and Border Protection agency failed to enforce basic security practices at a contractor that was hacked last year, exposing some 100,000 individual photos of travelers, a new inspector general report has found. Some of the hacked images ended up on the dark web, but the entire episode “may damage the public’s trust in the government’s ability to safeguard biometric data,” the Department of Homeland Security’s inspector general concluded in a report released Wednesday. It’s an example of how, as federal immigration and security agencies increasingly draw on biometric data for their work, the stakes for protecting that data from hackers have grown. The data collection was for a CBP pilot to use facial recognition to screen travelers at ports of entry. The project went awry when surveillance technology company Perceptics, a subcontractor, downloaded sensitive CBP data from an unencrypted device and transferred it to the company’s network, […]

The post IG finds data security practices lacking at Customs and Border Protection before big hack appeared first on CyberScoop.

Continue reading IG finds data security practices lacking at Customs and Border Protection before big hack

Secret Service Investigates Breach at U.S. Govt IT Contractor

The U.S. Secret Service is investigating a breach at a Virginia-based government technology contractor that saw access to several of its systems put up for sale in the cybercrime underground, KrebsOnSecurity has learned. The contractor claims the access being auctioned off was to old test systems that do not have direct connections to its government partner networks.

In mid-August, a member of a popular Russian-language cybercrime forum offered to sell access to the internal network of a U.S. government IT contractor that does business with more than 20 federal agencies, including several branches of the military. The seller bragged that he had access to email correspondence and credentials needed to view databases of the client agencies, and set the opening price at six bitcoins (~USD $60,000). Continue reading Secret Service Investigates Breach at U.S. Govt IT Contractor

CBP suspends Perceptics from doing government business following data breach

U.S. Customs and Border Protection officials suspended Perceptics, the provider of license-plate scanners and other surveillance technology, from federal contracting following a data breach that exposed travelers’ information, according to federal records first obtained by the Washington Post. CBP last month said one of its subcontractors, later identified as Perceptics, was breached in a “malicious cyberattack” that resulted in images of travelers’ faces, license plates, contracting documents and other data being made publicly available on the internet. Now, the Post reports, CBP has taken the rare step of punishing a federal contractor, citing “evidence of conduct indicating a lack of business honesty or integrity.” As a result, Perceptics is prohibited from doing business with the government, a punishment that could last for years if the company is placed on a government blacklist. CBP said on June 12 that a subcontractor had violated government policy by transferring images of license plates […]

The post CBP suspends Perceptics from doing government business following data breach appeared first on CyberScoop.

Continue reading CBP suspends Perceptics from doing government business following data breach

Border Protection Loses Photos of Travelers in Data Hack

Customs and Border Protection admits to losing some pictures of people going in and out of the US. Or rather, that its contractor lost them, which amounts to the same thing.
The post Border Protection Loses Photos of Travelers in Data Hack appeared fi… Continue reading Border Protection Loses Photos of Travelers in Data Hack