BreachExchange mailing list archives

Anonymous hacks Bureau of Justice, leaks 1.7GB of data


From: Jake Kouns <jkouns () opensecurityfoundation org>
Date: Tue, 22 May 2012 09:42:41 -0400

https://www.zdnet.com/blog/security/anonymous-hacks-bureau-of-justice-leaks-17gb-of-data/12260

Summary: Anonymous has apparently hacked the United States Bureau of
Justice Statistics and posted 1.7GB of data belonging to the agency on
The Pirate Bay. This is a Monday Mail Mayhem release.

The hacktivist group Anonymous claims to have leaked 1.7GB of data
belonging to the United States Bureau of Justice Statistics (BJS). The
file, which has been uploaded as a torrent and posted on The Pirate
Bay, reportedly contains internal e-mails as well as the website’s
“entire database dump.”

It remains to be seen if there’s anything incriminating in this leak.
After all, the BJS is simply a federal government agency belonging to
the U.S. Department of Justice (DOJ) that collects, analyzes, and
publishes data relating to crime in the U.S. (including hacker
attacks).

As you can see in the video above, the group also claims the BJS took
down its website in response to the attack. By then it was supposedly
too late. Here’s the video’s transcript of the English part:

Greetings world,
We are Anonymous.
Today we are releasing 1.7GB of data that used to belong to the United
States Bureau of Justice, until now.
Within the booty you may find lots of shiny things such as internal
emails, and the entire database dump.
We Lulzed as they took the website down after being owned, clearly
showing they were scared of what inevitably happened.

We do not stand for any government or parties; we stand for freedom of
people, freedom of speech and freedom of information.
We are releasing data to spread information, to allow the people to be
heard and to know the corruption in their government. We are releasing
it to end the corruption that exists, and truly make those who are
being oppressed free.
The price we pay very often is our own freedom. The price governments
pay is the exposure of their corruption and the truth being revealed,
for the truth will set us free in the end.
So once more we call on you. Hackers, activists, and freedom fighters;
join us in our struggle against these corporate

Curiously, an unmasked gentleman is shown at the end of the video. He
says the following:

What’s next? What’s next is… all they can do is shut down the Internet
itself. And we see, how that went for them, in Egypt. And we the
people know, that when the government shuts down the Internet, that’s
when it’s time to shut down the government.

He then puts on the Guy Fawkes mask and repeats the well-known Anonymous slogan:

We are Anonymous
We do not forgive
We do not forget
Expect us

To keep things more interesting, he throws in a little something
extra: “And now, expect a whole lot more.”

I have contacted the United States Bureau of Justice Statistics and
will update you if I hear back.

Update at 6:00 PM PST - “The department is looking into the
unauthorized access of a website server operated by the Bureau of
Justice Statistics that contained data from their public website,” a
DOJ spokesperson statement. “The Bureau of Justice Statistics website
has remained operational throughout this time. The department’s main
website, justice.gov, was not affected.”
_______________________________________________
Dataloss Mailing List (dataloss () datalossdb org)
Archived at http://seclists.org/dataloss/
Unsubscribe at http://datalossdb.org/mailing_list

Supporters:

Risk Based Security (http://www.riskbasedsecurity.com/)
Risk Based Security equips organizations with security intelligence, risk
management services and on-demand security solutions to establish
customized risk-based programs to address information security and
compliance challenges. 

Tenable Network Security (http://www.tenable.com/)
Tenable Network Security provides a suite of solutions which unify real-time
vulnerability, event and compliance monitoring into a single, role-based, interface
for administrators, auditors and risk managers to evaluate, communicate and
report needed information for effective decision making and systems management.


Current thread: