Government contractor exposed path to immigration records
A government contractor's security vulnerability was exposed when developers successfully changed firewall rules to ease code deployment between low-security and classified datacentres, despite warnings from security officer Joe Brinkley. This change potentially exposed immigration records for 50 million people to thousands of VPN users who were supposed to have no access to the classified system.
Brinkley had advised the Change Review Board against the modification, warning it would allow unauthorised access from low-security networks into production systems. However, whilst he was on holiday, the developers appealed directly to the Change Acceptance Board and secured approval. Upon his return, Brinkley demonstrated to company and government officials that using a simple VPN connection, he could access and control the production server containing immigration data; the system relied only on username and password authentication with weak standards and no multi-factor authentication, leaving it vulnerable to brute-force attacks. The firewall rule was immediately reverted following this demonstration.
- Firewall rule change exposed 50 million immigration records to thousands of unauthorised VPN users.
- Security officer's warnings ignored whilst on leave; vulnerability demonstrated upon return.
- Weak password standards and lack of multi-factor authentication compounded the exposure.