Picture: Lorie Shaull (CC BY 2.0 DEED)
The District of Columbia Board of Elections (DCBOE) is presently probing a knowledge leak involving an unknown variety of voter information following breach claims from a menace actor often known as RansomedVC.
DCBOE operates as an autonomous company throughout the District of Columbia Authorities and is entrusted with overseeing elections, managing poll entry, and dealing with voter registration processes.
Its investigation into the claims has revealed that the attackers accessed the data by way of the online server of DataNet, the internet hosting supplier for Washington D.C.’s election authority.
Notably, the breach didn’t contain a direct compromise of DCBOE’s servers and inside techniques.
“On 10/5, DCBOE turned conscious of cybersecurity incident involving DC voter information. Whereas the incident stays underneath investigation, DCBOE’s inside databases & servers weren’t compromised,” the company stated.
In shut cooperation with MS-ISAC’s Laptop Incident Response Workforce (CIRT), DCBOE took down its web site and changed it with a upkeep web page to include the state of affairs after figuring out it because the supply of the breach.
For the reason that discovery of the incident, the election board labored with information safety consultants, the Federal Bureau of Investigation (FBI), and the Division of Homeland Safety (DHS) to conduct a complete safety evaluation of its inside techniques.
Moreover, DCBOE initiated vulnerability scans throughout its database, server, and IT networks to establish potential safety points which may have facilitated the attackers’ entry to the stolen info.
Stolen information up on the market on the darkish net
RansomedVC alleges that the latest incident resulted within the theft of over 600,000 traces of U.S. voter information, encompassing information of D.C. voters.
“We’ve got efficiently breached the District of Columbia Board Of Elections and have gotten greater than 600k traces of USA Voters,” the menace actor says.
The stolen info is presently being provided on the market on the menace actor’s darkish net leak web site, however the precise worth is undisclosed.
As verification of the info’s authenticity, RansomedVC has offered a single document containing what it claims to be the non-public particulars of a Washington D.C. voter.
This dataset contains the person’s title, registration ID, voter ID, partial Social Safety quantity, driver’s license quantity, date of delivery, telephone quantity, electronic mail, and extra.
“It must be famous that within the District of Columbia, some voter registration data-such as voter names, addresses, voting information, and celebration affiliation-is public info, except it has been made confidential in accordance with District of Columbia guidelines and laws,” the Washington election authority stated in its assertion.
Nonetheless, election authorities don’t present entry to confidential info resembling voters’ contact info and SSNs.
RansomedVC told DataBreaches.net, who first reported the info leak on Thursday, that the stolen voter information could be offered to a single purchaser.
Recognized for controversial claims
Whereas RansomedVC has claimed the breach and is now promoting the info on their leak web site, an nameless supply informed BleepingComputer on October third that DCBOE’s stolen database was first put up on the market on the BreachForums and Sinister.ly hacking boards by a consumer named pwncoder (these posts have since been deleted).
As BleepingComputer was informed, the info was dumped from a stolen MSSQL database and contained the data of greater than 600,000 D.C. voters.
Latest claims made by RansomedVC to have breached Sony’s systems and stolen over 260GB of information (with a 2MB leaked archive as proof) have been disputed by one other menace actor who identifies as MajorNelson.
The latter celebration launched a 2.4 GB archive of information on BreachForums, allegedly taken from Sony’s techniques.
Whereas the info shared by these attackers appears linked to Sony, BleepingComputer couldn’t independently validate the authenticity of both celebration’s claims.