CODERED VTA

US Supreme Court and Federal Agencies Breached by Credential Theft

High
Network cables closeup
Photo by Clint Patterson

A Tennessee man, Nicholas Moore, has pleaded guilty to hacking the U.S. Supreme Court's electronic filing system, as well as breaching accounts at the AmeriCorps U.S. federal agency and the Department of Veterans Affairs. The breaches occurred between August and October 2023, with Moore accessing the Supreme Court's restricted electronic filing system at least 25 times using stolen credentials. He also accessed a second victim's AmeriCorps account seven times, obtaining personal information, and accessed the Department of Veterans Affairs' My HealtheVet online personal health record portal five times, accessing a veteran's private health information. The breaches were reportedly carried out using compromised login credentials, which Moore used to access sensitive information and post screenshots on his Instagram account. The incident highlights the risks associated with credential theft and the importance of robust password management and access controls.

The attacks were carried out by exploiting weak passwords and leveraging compromised credentials to gain unauthorized access to the targeted systems. Moore allegedly used the stolen credentials to log into the Supreme Court's electronic filing system, where he accessed sensitive information, including filing system details and victim's names. He also used the compromised MyAmeriCorps credentials to access a second victim's account, obtaining personal information, including name, date of birth, email address, home address, phone number, citizenship status, veteran status, service history, and the last four digits of the social security number. The Department of Veterans Affairs breach involved Moore using stolen login credentials from a U.S. Marine Corps veteran to access the My HealtheVet online personal health record portal, where he accessed the veteran's private health information, including prescribed medications and other intimate data. The attacks demonstrate the potential consequences of poor password management and the need for robust security measures to protect sensitive information.

The breach of the US Supreme Court and federal agencies has significant strategic implications, highlighting the importance of robust cybersecurity measures to protect sensitive information. The incident demonstrates the potential consequences of credential theft and the need for organizations to implement robust password management and access controls. The breach also underscores the importance of monitoring and detecting suspicious activity, as well as implementing incident response plans to quickly respond to security incidents. To mitigate the risks associated with credential theft, organizations should implement multi-factor authentication, regularly review and update access controls, and provide training to employees on password management and security best practices. Additionally, organizations should consider implementing threat intelligence and threat hunting capabilities to detect and respond to potential security threats.

Attack Surface

Endpoint, Web Application

Tactics

Initial Access, Credential Access, Exfiltration

Techniques

  • T1078 – Valid Accounts
  • T1003 – OS Credential Dumping

SuperPRO's Threat Countermeasures Procedures

  1. Implement multi-factor authentication to prevent unauthorized access to sensitive systems and data
  2. Regularly review and update access controls to ensure that only authorized personnel have access to sensitive information
  3. Provide training to employees on password management and security best practices
  4. Implement threat intelligence and threat hunting capabilities to detect and respond to potential security threats
  5. Use password managers to generate and store complex passwords
  6. Limit access to sensitive information based on the principle of least privilege
  7. Monitor and detect suspicious activity, including login attempts from unknown locations or at unusual times

References

  1. https://storage.courtlistener.com/recap/gov.uscourts.dcd.288314/gov.uscourts.dcd.288314.8.0_2.pdf