In a scenario that’s become all too common these days, it seems that a subcontractor responsible for the development of F-35, JDAM, P-8, and C-130 parts and assemblies has been hacked.
Unfortunately, it wasn’t just credit card and other consumer data compromised. It was detailed information on some of the world’s major shared military defense systems – aircraft, bombs and naval vessels. Additionally, it seems that this breach has been active for a bit of time.
In fact, it was said that almost a year ago, in November 2016, by the Australian Cyber Security Centre (ACSC):
…became aware that a malicious cyber adversary had successfully compromised the network of a small Australian company with contracting links to national security projects. ACSC analysis confirmed that the adversary had sustained access to the network for an extended period of time and had stolen a significant amount of data.
The attackers had been inside the company’s network at least since the previous July, had “full and unfettered access” for several months, and exfiltrated about 30GB of data including, “restricted technical information on the F-35 Joint Strike Fighter, the P-8 Poseidon maritime patrol aircraft, the C-130 transport aircraft, the Joint Direct Attack Munition (JDAM) smart bomb kit, and a few Australian naval vessels.”
Though the company was not named, it has been described as a 50-person company with a single IT person handling all aspects of Information Technology and Security. It’s also apparent that the company was not compliant with CSC or similar regulatory frameworks, as…