Report: Fed hacked 50 times in four years

President Trump has nominated Randal Quarles to be the Federal Reserve’s vice chair for bank supervision. The nominee, who now co-heads an investment firm, was a senior Treasury official under both Bush presidencies and is expected to be confirmed.

Federal agencies — particularly the high-profile ones — are under constant cyberattack. That is no less true for the Federal Reserve, which suffered at least 51 data breaches between 2011 and 2015, according to a new Reuters report published June 1.

Reuters reporters Jason Lange and Dustin Volz obtained documentation on cybersecurity incidents at the Fed’s Board of Governors through a Freedom of Information request, which showed at least 140 “hacking attempts” over four years.

Of those attempts, at least eight were categorized as involving “malicious code” and four were labeled acts of espionage.

“In all, the Fed’s national team of cybersecurity experts, which operates mostly out of New Jersey, identified 51 cases of ‘information disclosure’ involving the Fed’s board,” according to the report.

Reuters reporters noted the data only covers the Board of Governors, which, unlike the privately owned regional branches of the Fed, is subject to FOI.

A former Fed employee who worked on the cybersecurity team told Reuters the agency was “compromised frequently” while they were employed there but noted that’s not unique in the public or private sector these days.

Representatives from the Fed declined to comment for Reuters’ story.

While the report raises some alarm, security researchers warn readers not to jump to conclusions.

“Without more information on each of the specific incidents, it can be difficult to draw conclusions,” according to Cris Thomas, a network security strategist at Tenable and a founding member of the hacker collective L0pht. “That could be one reason for the heavy redactions and why these types of internal reports should be taken with a grain of salt. The malicious code listed in the reports could just be random malware and the unauthorized access might be employees sharing passwords — there’s really no way to tell from the information provided.”

Earlier this year, Federal Times did a similar analysis of cyber incidents at the Department Health and Human Services, discovering troubling trends at two of the department’s most sensitive components: the Centers for Disease Control and Prevention and the National Institutes of Health.

“This isn’t anything new,” Thomas said. “Regardless of how the reports define a cyber incident, it’s critical that federal agencies keep their networks updated and secure to stop these types of attacks from happening.”

About 

Aaron Boyd is an awarding-winning journalist currently serving as editor of Federal Times — a Washington, D.C. institution covering federal workforce and contracting for more than 50 years — and Fifth Domain — a news and information hub focused on cybersecurity and cyberwar from a civilian, military and international perspective.