NASA employee PII server compromise disclosed by internal memo, December 2018
What happened
On 18 December 2018 Bob Gibbs, NASA's Assistant Administrator in the Office of the Chief Human Capital Officer, sent an internal message to all NASA employees disclosing that on 23 October 2018 NASA cybersecurity personnel had begun investigating a possible compromise of NASA servers holding personally identifiable information, and that information from one of those servers, including Social Security numbers and other personal data of current and former employees, may have been compromised. The affected population as the memo defines it is NASA Civil Service employees who were on-boarded, separated from the agency, or transferred between Centers from July 2006 to October 2018. NASA said its cybersecurity personnel had taken immediate action to secure the servers and the data on them, that determining the scope of the potential exfiltration and identifying affected individuals would take time, that senior leadership was actively involved, and that identity protection services would be offered to those found to be affected. No source states how the servers were reached, by whom, what was taken as opposed to potentially taken, or how many individuals were affected. No mission system, spacecraft data, ground segment or link appears in any account of this incident.
HOLD RECOMMENDED, and the record deliberately carries no technique edges. SPARTA's bibliography associates EXF-0007 and IMP-0006 with this incident and both are rejected for the same reason: both are mission-data techniques, and what was compromised was a human-resources server holding Social Security numbers. There is no mission system, no spacecraft data, no ground segment and no link anywhere in the account. Nothing else is mappable either, because no source states the entry path, the actor, or what was actually taken. primary_segment and affected_segments are left unset rather than forced to ground: the segment enum has no value meaning an organisation's enterprise IT, and asserting ground would claim that a satellite operator's ground segment was involved, which is false. The document at the centre of this record is an internal HR communication rather than an incident report, and no NASA incident report, OIG audit or follow-up disclosure covering this breach was found.
Attack vector
Not stated in any source. The memo describes a possible compromise of servers and the response to it, not an entry path.
Operational impact
None reported. The incident concerns human-resources records; no mission, spacecraft or ground system is described as affected.
Data compromised
Potentially compromised rather than confirmed taken: Social Security numbers and other personally identifiable information of current and former NASA Civil Service employees who were on-boarded, separated or transferred between Centers from July 2006 to October 2018.
Disclosed
2018-12-18
SPARTA techniques evidenced
No SPARTA technique is mapped to this record.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
The compromised server is human-resources infrastructure. EXF-0007's subject is mission ground infrastructure with reach to the spacecraft and its data. Re-evaluated under decision 67 and held. The ruling removes the segment half of this rejection, but EXF-0007 requires data to have been siphoned, and NASA's memo says only that information may have been compromised and that determining the scope of the potential exfiltration would take time. No source states anything was taken. The same bar keeps
EXF-0007offmckinnon-nasa-dod-intrusions-2001-2002andesa-ftp-server-compromise-2011.Social Security numbers and personnel records are not the mission data IMP-0006 is about. The same distinction is applied on
mckinnon-nasa-dod-intrusions-2001-2002,doppelpaymer-dmi-nasa-contractor-2020andnoaa-nesdis-intrusion-2014.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
Tier 2: Named security-vendor reporting quoting the NASA memo directly. Primary here only because it is the retrievable carrier of the memo's wording; the memo itself is the underlying document.
- Potential Personally Identifiable Information (PII) Compromise of NASA ServersOperator statementsupporting
Tier 2: A republication of NASA's own internal memo. The memo is a first-party operator statement; SpaceRef is the venue, not the author, and it is an internal HR communication rather than an incident report, which is why it is Tier 2.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.