• MSN
  • Hotmail
  • More
    • Autos
    • My MSN
    • Video
    • Careers & Jobs
    • Personals
    • Weather
    • Delish
    • Quotes
    • White Pages
    • Games
    • Real Estate
    • Wonderwall
    • Horoscopes
    • Shopping
    • Yellow Pages
    • Local Edition
    • Traffic
    • Feedback
    • Maps & Directions
    • Travel
    • Full MSN Index
  • Bing
  • NBCNews.com
  • TODAY
  • Nightly News
  • Rock Center
  • Meet the Press
  • Dateline
  • msnbc
  • Breaking News
  • Newsvine
  • Home
  • US
  • World
  • Politics
  • Business
  • Sports
  • Entertainment
  • Health
  • Tech
  • Science
  • Travel
  • Local
  • Weather
Advertise | AdChoices
  • Recommended: In first public acknowledgement, Holder says 4 Americans died in US drone strikes
  • Recommended: Why aren't there more storm shelters in Oklahoma?
  • Recommended: Ex-Cincy IRS official doubts agency's explanation for Tea Party scandal
  • Recommended: Moore officials: Federal grants to help build 'safe rooms' delayed by red tape

Investigative reporting from NBC News, with your story ideas and documents. Share your ideas. Read about this blog. Follow us on Facebook and Twitter.

  • ↓ About this blog
  • ↓ Archives
    • Icons Email E-mail updates
    • Icons Twitter Follow on Twitter
    • Icons Feed Subscribe to RSS
  • 20
    Nov
    2012
    5:40pm, EST

    One email exposes millions of people to data theft in South Carolina cyberattack

    A report is expected to be released Tuesday detailing how an unknown cyber hacker broke into South Carolina's computers and stole millions of tax returns from residents dating back years. NBC's Michael Isikoff reports.

    By Michael Isikoff
    NBC News National Investigative Correspondent

    Follow @IsikoffNBC

    COLUMBIA, S.C. -- A single malicious email sent to workers at the South Carolina  Department of Revenue last August enabled an international hacker to crack into state computers and gain access to 3.8 million tax returns, including Social Security numbers and bank account information, in what experts say is the biggest cyber-attack ever against a state government, according to details in a report released Tuesday.

    “We were a cocktail for an attack,” Gov. Nikki Haley said, referring to the necessary ingredients for cyberassault, as she released a report by a computer security firm Mandiant, which was commissioned to investigate the data breach. At the same time, Haley accepted the resignation of her Department of Revenue director, Jim Etter, and acknowledged that state officials “could have done more” to protect the personal data of state residents.

    The release of the report came amid a mounting political uproar here over the cyberattack and criticism of Haley over her handling of the issue.


    “I’ve gotten more phone calls and emails about this than anything else in the last four years,” said Tom Davis, a state senator and former chief of state to Gov. Mark Sanford. “There’s a great degree of anger and frustration over what happened. This is information you’ve got to give the government; if you don’t, they put you in jail. There’s a real sense of betrayal,” he said.

    According to the Mandiant report, the cyberattack, which state sources say is believed to have originated inside Russia, started with a “phishing” scheme, a common tactic used by cyber criminals. 

    Last Aug. 13, a hacker sent multiple South Carolina Department of Revenue  employees a malicious email containing an embedded link containing malware or a computer virus. When at least one of the employees clicked on the link, the malware was activated and allowed the hacker to steal the employee’s user name and password.

    From there, the hacker was off to the races. Two weeks later, the attacker logged onto the remote-access service for Department of Revenue computers, using the credentials of an employee who had clicked on the Aug. 13 email. The invader then “leveraged the user’s access rights to access other Department of Revenue systems and databases with the user’s credentials,” the report states.

    The attacker performed “reconnaissance activities” over the next several weeks, then started copying large amounts of data and transferring them onto zip files that were moved onto the Internet. The breach was not discovered until the Secret Service notified state officials on Oct. 10 that it had uncovered information that data on three state residents had been stolen.

    Since then, Haley and other state officials have scrambled to react as the magnitude of the attack has become increasingly apparent. In addition to 3.8 million tax returns, including the Social Security numbers of 1.9 million children and other dependents, the hackers got access to data on 699,900 business tax returns and 3.3 million bank accounts.

    The attack has exposed vulnerabilities that experts say will cause state governments across the country to reexamine their cyber-defenses. Although South Carolina had encrypted credit card numbers according to industry standards, it had never encrypted the Social Security numbers. And some cyber experts say there is evidence that that data may now be marketed on Internet black market sites that peddle personal information on millions of Americans.

    Haley on Tuesday blamed the federal government for not requiring Social Security numbers to be encrypted. She released a letter to IRS Commissioner Steven Miller “to strongly encourage the Internal Revenue Service to require all states to have stronger security measures for handling federal tax information, particularly encryption of tax information that is stored or ‘at rest.’” 

    356 comments

    Haley on Tuesday blamed the federal government for not requiring Social Security numbers to be encrypted

    Show more
    Explore related topics: cyber-crime, cyber-attack, michael-isikoff-featured

Browse

  • featured,
  • documents,
  • terrorism,
  • al-qaida,
  • election-2012,
  • investigative-reporting,
  • iran,
  • crime,
  • reading,
  • environment,
  • investigation,
  • military,
  • health,
  • obama,
  • fbi,
  • campaign-finance,
  • pakistan,
  • u-s,
  • huguette-clark,
  • campaign,
  • updated,
  • cia,
  • guns,
  • news21,
  • voting-fraud,
  • voter-id,
  • who-can-vote,
  • nbc,
  • isikoff,
  • nuclear,
  • center-for-public-integrity,
  • penn-state,
  • windrem,
  • security,
  • politics,
  • osama-bin-laden,
  • romney,
  • safety,
  • wikileaks,
  • shooting,
  • fracking
Also
Advertise | AdChoices

Bill Dedman

Investigative reporter Bill Dedman of NBC News is always looking for good investigative story ideas and documents. Bill received the 1989 Pulitzer Prize for investigative reporting, and has written full time for NBCNews.com since 2006.

Bill Dedman Blogroll

  • Bill's investigative reporting feed on Twitter
  • ABC News The Blotter
  • Center for Investigative Reporting
  • Center for Public Integrity
  • Center for Public Integrity's Paper Trail blog
  • Huffington Post Investigative Fund
  • Investigative Reporters and Editors' Extra! Extra!
  • McClatchey blog Nukes & Spooks
  • New York Times' City Room Records blog
  • New York Times' Open data blog
  • ProPublica
  • ProPublica blog
  • Yahoo! News The Upshot
  • TPM Muckraker
  • Washington Post Investigations
  • WhoWhatWhy forensic journalism
  • New England Center for Investigative Center at Bos
  • Wisconsin Center for Investigative Journalism
  • Pulitzer Center on Crisis Reporting
  • Schuster Institute for Investigative Journalism, B
  • MinnPost.com
  • The Washington Independent
  • AU Investivative Reporting Workshop
  • Become a fan on Facebook
  • Follow on Twitter
Have an idea?
Send your ideas and documents for investigative stories.

Michael Isikoff

Michael Isikoff joined NBC News in July 2010 as national investigative correspondent. He had been at Newsweek since 1994 as an investigative correspondent. He has written extensively on the U.S. government's war on terrorism, the Abu Ghraib scandal, campaign-finance and congressional ethics abuses, presidential politics and other national issues.

Amna Nawaz

Amna Nawaz is Bureau Chief/Correspondent for NBC News' Pakistan bureau. She reports for all NBC News platforms from across the country and the region. Previously, she reported for the network's investigative unit.

Mike Brunker, Investigations Editor, NBC News

Mike Brunker is the investigations editor at NBCNews.com. He's worked for the site (formerly msnbc.com) as a reporter and editor since August 1996. Before that, he was an editor at the San Francisco Examiner and Hayward Daily Review in California.

Mike Brunker, Investigations Editor, NBC News Blogroll

  • White Collar Crime Prof blog
  • The Volokh Conspiracy: Legal news now
  • Frederick Lane Blog -- legal news
  • Social Networking Law Blog
  • Sports Law Blog
  • Business of Horse Racing Blog
  • The Long War Journal
  • The Red Tape Chronicles -- consumer/tech news

Azriel James Relph

Azriel James Relph is a researcher for NBC News Investigations. He is a graduate of the CUNY Graduate School of Journalism, and was a reporter for several years at the Hunts Point Express -- a South Bronx newspaper serving the poorest Congressional District in the United Sates. He has written for Newsweek, The Daily Beast, and MSNBC.com.

Robert Windrem

Robert Windrem is investigative producer for special projects at NBC Nightly News. He is also a Fellow at the Center on National Security at Fordham Law School. He has worked at NBC News for more than three decades, focusing on issues of international security, strategic policy, intelligence and terrorism.

M. Alex Johnson

M. Alex Johnson is a reporter for NBC News specializing in national affairs, technology and data analysis. He joined NBC News in 1999 from The Washington Post.

M. Alex Johnson Blogroll

  • Alex Johnson — Journalist at Large
  • Ars Technica
  • Krebs on Security
  • GetStats
  • Technolog
  • Sophos Security Trends
  • Muckety
  • Pew Internet Research
  • Investigative Reporters and Editors
  • Fund for Investigative Journalism
  • Data Journalism Blog
  • Follow on Twitter
  • Follow on Facebook
Follow Alex
Twitter
Facebook
LinkedIn

Archives

  • 2013
    • May (43)
    • April (34)
    • March (42)
    • February (21)
    • January (27)
  • 2012
    • December (33)
    • November (30)
    • October (39)
    • September (34)
    • August (46)
    • July (36)
    • June (42)
    • May (52)
    • April (28)
    • March (24)
    • February (38)
    • January (42)
  • 2011
    • December (27)
    • November (23)
    • October (15)
    • September (9)
    • August (6)
    • July (11)
    • June (12)
    • May (12)
    • April (5)
    • March (11)
    • February (11)
    • January (21)
  • 2010
    • December (11)
    • November (13)

Most Commented

  • Dzhokhar Tsarnaev scribbled note inside boat where he was hiding, sources say (721)
  • Moore officials: Federal grants to help build 'safe rooms' delayed by red tape (402)
  • Ex-Cincy IRS official doubts agency's explanation for Tea Party scandal (244)
  • Why aren't there more storm shelters in Oklahoma? (293)
  • DOJ's secret subpoena of AP phone records broader than initially revealed (247)
  • Fracking boom triggers water battle in North Dakota (228)
  • In first public acknowledgement, Holder says 4 Americans died in US drone strikes (136)

Other blogs

  • The Body Odd
  • Cosmic Log
  • Red Tape Chronicles
  • PhotoBlog
  • US News

NBCNews.com top stories

3147,10
© 2013 NBCNews.com
  • US news on NBCNews.com
  • About us
  • Contact
  • Help
  • Site map
  • Careers
  • Closed captioning
  • Terms & Conditions
  • Privacy policy
  • Advertise