DHS had a privacy incident that resulted in the exposure of information for 247,167 active and retired federal employees.
The database utilised by the DHS Office of the Inspector General (OIG) and kept in the Department of Homeland Security OIG Case Management System was compromised by a data breach.
Employee names, Social Security numbers, dates of birth, jobs, grades, and duty locations are among the data that has been made public.
In addition to putting additional security measures in place to restrict access to this kind of information, the Department of Homeland Security notified those who were impacted through notification letters.
Source: https://securityaffairs.com/67403/data-breach/dhs-privacy-incident.html
TPRM report: https://www.rankiteo.com/company/us-department-of-homeland-security
"id": "usd331181223",
"linkid": "us-department-of-homeland-security",
"type": "Breach",
"date": "6/2017",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Government',
'name': 'Department of Homeland Security',
'size': 'Large',
'type': 'Government Agency'}],
'data_breach': {'number_of_records_exposed': 247167,
'personally_identifiable_information': ['Employee names',
'Social Security '
'numbers',
'Dates of birth',
'Positions',
'Grades',
'Duty locations'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally Identifiable '
'Information']},
'description': 'A privacy incident at the Department of Homeland Security '
'(DHS) resulted in the exposure of information for 247,167 '
'active and retired federal employees. The compromised data '
'includes employee names, Social Security numbers, dates of '
'birth, positions, grades, and duty locations. The DHS Office '
'of the Inspector General (OIG) Case Management System was '
'affected.',
'impact': {'data_compromised': ['Employee names',
'Social Security numbers',
'Dates of birth',
'Positions',
'Grades',
'Duty locations'],
'systems_affected': ['DHS OIG Case Management System']},
'response': {'remediation_measures': ['Notification letters sent to affected '
'individuals',
'Additional security measures '
'implemented to restrict access to '
'information']},
'title': 'DHS Data Breach Incident',
'type': 'Data Breach'}