For years, security professionals have been preaching about the need for basic cyber security hygiene, including vulnerability, patch, and password management. Indeed, many successful cyber attacks are conducted leveraging these three threat vectors. In a recent report filed by the BBC we read that the Australian government, despite ASD mandates, received a critical reminder of the need for basic cyber security hygiene and are now dealing with the ramifications of failing to maintain it.
Details on the breach
In the breach (related to an Adelaide-based aerospace engineering company) we can speculate that requirements like those found in NIST 800-171 where clearly not enforced, but applicable, because some of the breach material included the F-35 Joint Strike Fighter, P-8 Poseidon, and C130 transport aircraft (in addition to other navy vessels) which are manufactured in the United States. In total, about 30GB of data was compromised. But like any good hack, the threat actor has still not been positively identified despite speculation of regional nation state involvement.
What went wrong
This sensitive military breach at a contractor is particularly annoying since so many basic cyber security hygiene policies, procedures and indicators where not followed, or just completely missed. For example:
- The breach began in July 2016, but government officials (ASD) were not notified until November 2016 – four months before disclosure and much too long by any standards.
- The exploit occurred in a software application that had not received security updates for a full year. No red flags from vulnerability or patch management were raised to remediate or mitigate the threat? It sounds like Equifax to me.
- The contractor was also using default passwords on the application! Wait. What? You’re protecting sensitive military secrets and cannot even change the default password on an application that could be leveraged against the crown jewels of your organization? Clearly, hygiene went out the window here too.
If there is a silver lining, the stolen data was allegedly commercial information about the aircraft and not military data. Please think about that for a moment. What commercial information, totaling 30GB, is available about three military aircraft and a few navy vessels? High resolution JPGs? 30GB is a lot of commercially available information for a country’s offensive and defensive systems no matter how you look at it. It just was not relevant Australian military information; just information on the assets. This is completely the opposite of reports that North Korea hacked South Korea and stole vital military plans. It is the difference of knowing about your enemy’s weapons verses knowing what they plan to do with them.
What we can learn
As we continue into the middle of October, we are reminded yet again from our allies down under of the important of basic cyber security hygiene. October is National Cybersecurity Awareness Month and incidents like this are a firm reminder that we must always be vigilant in securing, protecting, monitoring, and enforcing our basic policies and procedures – including the Essential Eight.
If you would like more information on how BeyondTrust can help with NIST, ASD, or Essential Eight implementations and reporting, contact us today. Our goal: to make sure you do not become the next victim.
Morey J. Haber, Chief Security Officer, BeyondTrust
Morey J. Haber is the Chief Security Officer at BeyondTrust. He has more than 25 years of IT industry experience and has authored four books: Privileged Attack Vectors, Asset Attack Vectors, Identity Attack Vectors, and Cloud Attack Vectors. He is a founding member of the industry group Transparency in Cyber, and in 2020 was elected to the Identity Defined Security Alliance (IDSA) Executive Advisory Board. Morey currently oversees BeyondTrust security and governance for corporate and cloud based solutions and regularly consults for global periodicals and media. He originally joined BeyondTrust in 2012 as a part of the eEye Digital Security acquisition where he served as a Product Owner and Solutions Engineer since 2004. Prior to eEye, he was Beta Development Manager for Computer Associates, Inc. He began his career as Reliability and Maintainability Engineer for a government contractor building flight and training simulators. He earned a Bachelor of Science degree in Electrical Engineering from the State University of New York at Stony Brook.