Insider attack involving sailor on USS Midway

Year

2012

Month

June

Reference number

20120601

Impact area

Shore

Incident location

Incident country

USA

Victim country

USA

Victim identity

United States Navy

Victim Type

Navy, Vessel

Method

Hacking

Attacker country

USA

Summary:

In June 2012, the United States Navy got hit by a hacking attack. The attackers employed a common hacking technique called a SQL injection, in which attackers probe a database to understand and (ultimately) exploit it. They did it because of boredom. The hackers found they were 'somewhat politically inclined to release the things [they had]'. Also because it was 'fun and we can'. The impact of hacking the Navy-SWM was theft of confidential information of approximately 220,000 Navy servicepeople who were being transferred. They posted the information, with social security numbers redacted, and crowed about it on Twitter. As a result Navy-SWM was shut down and never resumed operation. Over 700 deployed overseas Service Members could not access logistical support for transfers for more than 10 weeks. Caused loss to the Navy of approximately 514,000 dollars. The threat actor was TeamDigi7al (Nicholas Paul Knight, while on USS Harry S. Truman and Daniel Trenton Krueger). It is not exactly clear what measures the company took during and after the incident.

Reference URL

https://www.theatlantic.com/technology/archive/2014/05/the-hacker-who-worked-on-a-navy-nuclear-aircraft-carrier/361952/  
https://cdn.theatlantic.com/assets/media/img/posts/050514_Knight.pdf
https://www.wired.com/2014/05/navy-sysadmin-hacking/
https://nakedsecurity.sophos.com/2014/10/29/teamdigi7al-us-navy-hacker-sentenced-to-2-years-in-jail/