VA investigating data breach that compromised sensitive credentials, source codes

A federal contractor published source codes containing sensitive credentials from the Department of Veterans Affairs, FedScoop reported Sept. 29. 

Advertisement

The VA has opened a cyber breach investigation into a July data breach incident after hard-coded administrator account privileges, encrypted key tokens and specific database table information was published on internet hosting service GitHub.  

The breach occurred after the contractor had allegedly copied source code from a VA-managed GitHub account and published it on their own personal GitHub account, which was then switched to public mode, allowing others access. 

Sources familiar with the matter told FedScoop after the information was published online on July 5, six foreign IP addresses cloned the source code, including at least one from a country hostile to the U.S.

A VA spokesperson told Fedscoop that the compromised credentials are part of system-to-system communications that can only be utilized within the VA network and that it has no evidence of a data breach or data being cloned by other countries or validated by foreign IP addresses.

IT leaders at the VA were not made aware of the incident until Sept. 9 after it was discovered through the Cybersecurity and Infrastructure Security Agency’s vulnerability disclosure program.

GitHub, which is owned by Microsoft, is used by government agencies for software development and version control. 

Microsoft provided the VA with a detection and response team to conduct an analysis of the security risks posed by the breach of information.

“Copying [source code] from government private side to personal is strictly forbidden, so if the repo was private then that’s a firing and dismissal offense,” one of the sources told FedScoop.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement

Comments are closed.