On Thursday, the Oak Ridge National Laboratory (ORNL) said a “sophisticated cyberattack” executed over the past several weeks might have allowed hackers to steal the personal information of thousands of lab visitors.
According to ORNL Lab Director Thom Mason’s memo to the 4,200 employees at the Department of Energy facility, the assault appeared “to be part of a coordinated attempt to gain access to computer networks at numerous laboratories and other institutions across the country.”
ORNL did not return requests for comments, but the lab has publicly stated that the hackers might have gained access to a database of names, birth dates, and Social Security numbers of every lab visitor between 1990 and 2004.
“Our cyber security staff has been working nights and weekends to understand the nature of this attack,” Mason wrote. “Reconstructing this event is a very tedious and time-consuming effort that likely will take weeks, if not longer, to complete.”
Tracing the Root Cause
Some news reports call the hack a phishing attack, but Carole Theriault, a security analyst at Sophos, said she has a gut feeling the network was infected by a Trojan. Whatever the case, she continued, using social-engineering tricks to lure users into clicking on a malicious link or open an infected attachment is nothing new.
“What is scary is the number of facilities and organizations one would assume to have adequate security and user education that are falling victim to these attacks,” Theriault noted. “So many companies have our names and addresses, our bank details, and, in the case of labs and hospitals, our very private health records.”
A recent PCI Security Standards Council report suggested only half of the United States’ large companies have appropriate security in place to help mitigate attacks. Theriault said she wants to shout from the rooftops that companies need to wake up and…