Data Security, Identity

Extensive US civil servant credential exposure uncovered

concept of leaky software, data with a tap sticking out.3d illustration

U.S. civil servants had 53,070 passwords leaked publicly since the beginning of last year, FedScoop reports.

Most of the exposed credentials were from the State Department, while the Defense Department had the greatest exposure of unique passwords, according to a NordPass report. Also among the most impacted were the U.S. Army and the Department of Veterans Affairs, as well as the Washington, D.C., government, and the City of Virginia Beach.

Additional findings showed that more than 91,000 credentials with matching email addresses and public-sector domains across six countries.

"If affected passwords weren't updated following the related incidents and multi-factor authentication wasn't switched on, attackers could have potentially accessed these accounts and other sensitive information, creating data security risks," said the report.

While neither the Pentagon nor the VA commented on the findings, the State Department emphasized its commitment to improving cybersecurity through regular credential rotation and multi-factor authentication.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds