https://krebsonsecurity.com/2022/05/dea-investigating-breach-of-law-enforcement-data-portal/ Advertisement [1] Advertisement [2] Krebs on Security Skip to content * Home * About the Author * Advertising/Speaking DEA Investigating Breach of Law Enforcement Data Portal May 12, 2022 13 Comments The U.S. Drug Enforcement Administration (DEA) says it is investigating reports that hackers gained unauthorized access to an agency portal that taps into 16 different federal law enforcement databases. KrebsOnSecurity has learned the alleged compromise is tied to a cybercrime and online harassment community that routinely impersonates police and government officials to harvest personal information on their targets. [esp-screenshot] Unidentified hackers shared this screenshot of alleged access to the Drug Enforcement Administration's intelligence sharing portal. On May 8, KrebsOnSecurity received a tip that hackers obtained a username and password for an authorized user of esp.usdoj.gov, which is the Law Enforcement Inquiry and Alerts (LEIA) system managed by the DEA. KrebsOnSecurity shared information about the allegedly hijacked account with the DEA, the Federal Bureau of Investigation (FBI), and the Department of Justice, which houses both agencies. The DEA declined to comment on the validity of the claims, issuing only a brief statement in response. "DEA takes cyber security and information of intrusions seriously and investigates all such reports to the fullest extent," the agency said in a statement shared via email. According to this page at the Justice Department website, LEIA "provides federated search capabilities for both EPIC and external database repositories," including data classified as "law enforcement sensitive" and "mission sensitive" to the DEA. A document published by the Obama administration in May 2016 (PDF) says the DEA's El Paso Intelligence Center (EPIC) systems in Texas are available for use by federal, state, local and tribal law enforcement, as well as the Department of Defense and intelligence community. EPIC and LEIA also have access to the DEA's National Seizure System (NSS), which the DEA uses to identify property thought to have been purchased with the proceeds of criminal activity (think fancy cars, boats and homes seized from drug kingpins). "The EPIC System Portal (ESP) enables vetted users to remotely and securely share intelligence, access the National Seizure System, conduct data analytics, and obtain information in support of criminal investigations or law enforcement operations," the 2016 White House document reads. "Law Enforcement Inquiry and Alerts (LEIA) allows for a federated search of 16 Federal law enforcement databases." The screenshots shared with this author indicate the hackers could use EPIC to look up a variety of records, including those for motor vehicles, boats, firearms, aircraft, and even drones. Claims about the purloined DEA access were shared with this author by "KT," the current administrator of the Doxbin -- a highly toxic online community that provides a forum for digging up personal information on people and posting it publicly. As KrebsOnSecurity reported earlier this year, the previous owner of the Doxbin has been identified as the leader of LAPSUS$, a data extortion group that hacked into some of the world's largest tech companies this year -- including Microsoft, NVIDIA, Okta, Samsung and T-Mobile. That reporting also showed how the core members of LAPSUS$ were involved in selling a service offering fraudulent Emergency Data Requests (EDRs), wherein the hackers use compromised police and government email accounts to file warrantless data requests with social media firms, mobile telephony providers and other technology firms, attesting that the information being requested can't wait for a warrant because it relates to an urgent matter of life and death. From the standpoint of individuals involved in filing these phony EDRs, access to databases and user accounts within the Department of Justice would be a major coup. But the data in EPIC would probably be far more valuable to organized crime rings or drug cartels, said Nicholas Weaver, a researcher for the International Computer Science Institute at University of California, Berkeley. Weaver said it's clear from the screenshots shared by the hackers that they could use their access not only to view sensitive information, but also submit false records to law enforcement and intelligence agency databases. "I don't think these [people] realize what they got, how much money the cartels would pay for access to this," Weaver said. "Especially because as a cartel you don't search for yourself you search for your enemies, so that even if it's discovered there is no loss to you of putting things ONTO the DEA's radar." [epicaccess] The DEA's EPIC portal login page. ANALYSIS The login page for esp.usdoj.gov (above) suggests that authorized users can access the site using a "Personal Identity Verification" or PIV card, which is a fairly strong form of authentication used government-wide to control access to federal facilities and information systems at each user's appropriate security level. However, the EPIC portal also appears to accept just a username and password, which would seem to radically diminish the security value of requiring users to present (or prove possession of) an authorized PIV card. Indeed, KT said the hacker who obtained this illicit access was able to log in using the stolen credentials alone, and that at no time did the portal prompt for a second authentication factor. It's not clear why there are still sensitive government databases being protected by nothing more than a username and password, but I'm willing to bet big money that this DEA portal is not only offender here. The DEA portal esp.usdoj.gov is listed on Page 87 of a Justice Department "data inventory," which catalogs all of the data repositories that correspond to DOJ agencies. There are 3,330 results. Granted, only some of those results are login portals, but that's just within the Department of Justice. If we assume for the moment that state-sponsored foreign hacking groups can gain access to sensitive government intelligence in the same way as teenage hacker groups like LAPSUS$, then it is long past time for the U.S. federal government to perform a top-to-bottom review of authentication requirements tied to any government portals that traffic in sensitive or privileged information. I'll say it because it needs to be said: The United States government is in urgent need of leadership on cybersecurity at the executive branch level -- preferably someone who has the authority and political will to eventually disconnect any federal government agency data portals that fail to enforce strong, multi-factor authentication. I realize this may be far more complex than it sounds, particularly when it comes to authenticating law enforcement personnel who access these systems without the benefit of a PIV card or government-issued device (state and local authorities, for example). It's not going to be as simple as just turning on multi-factor authentication for every user, thanks in part to a broad diversity of technologies being used across the law enforcement landscape. But when hackers can plunder 16 law enforcement databases, arbitrarily send out law enforcement alerts for specific people or vehicles, or potentially disrupt ongoing law enforcement operations -- all because someone stole, found or bought a username and password -- it's time for drastic measures. This entry was posted on Thursday 12th of May 2022 07:00 AM A Little Sunshine Data Breaches Ne'er-Do-Well News The Coming Storm Department of Justice Domain Block List Doxbin Drug Enforcement Administration El Paso Intelligence Center emergency data request EPIC esp.usdoj.gov fbi ICSI KT LAPSUS$ Law Enforcement Inquiry and Alerts LEIA National Seizure System Nicholas Weaver NSS spamhaus U.S. Drug Enforcement Agency Post navigation - Microsoft Patch Tuesday, May 2022 Edition 13 thoughts on "DEA Investigating Breach of Law Enforcement Data Portal" 1. Unblinking May 12, 2022 Agreed, "it's time for drastic measures." Chief among these might be: - Terminate non-technical managers who misrepresent conditions to avoid doing the real work. - Eliminate CXO committees that prioritize career gain over security policy, staff, and programs. Among less drastic measures that would produce similar benefits: - Trust auditors, examiners, and technical staff more than you trust management. - Allow implementation of security standards that have been well known for years. Reply - 2. Gary May 12, 2022 I deliberately use a censored DNS (quad 9) to avoid websites with malware. But would Google (quad 8) be censored? As it turns out you can Google uncensored DNS and find https:// blog.uncensoreddns.org/ Reply - 3. Jeff harvey May 12, 2022 Bet they also have access proton database (phone call detail records) Reply - 4. Idm May 12, 2022 There is an executive branch policy to force use of phishing-resistant MFA for all government employees and contractors, but it stops short of enforcing it outside of that one group. No good guidance on partner access or public user access. PIV is only for government employees and contractors. There is a PIV Interoperable which is based on PIV without the background check, but it never caught on. Best hope is to get all government websites that require public or partner access to use something like login.gov and require a minimum MFA. Reply - 5. Reader May 12, 2022 Horrifying! Frightening! Appalling! Indefensible! Right on, Brian! Time for law enforcement to enforce... cybersecurity. Thank you for saying it and thank you for your service. I just started using a security key and am finding that there are ways around it because services often provide alternatives if the key is lost, meaning a feeling of "insecurity" with lost keys (and need to avoid increased support costs) is built into their design. Reply - 1. Gary May 12, 2022 A scheme like a common access card works because the card is issued by a live human being where you work. No social engineering work arounds. Any scheme where there is a work around will be social engineered. Reply - 1. JamminJ May 12, 2022 Agreed, I use a CAC and they are issued by a live person. They also require a significant amount of identity proofing. I have to bring in documents to prove who I am and where I work. Identity proofing for initial enrollment is absolutely needed to allow the uses of security keys without an "insecure" fallback/recovery method. The problem is, people don't want Identity Proofing and they scream about privacy. Often, it's the users who demand to be insecure. Reply - 1. BrianKrebs Post authorMay 12, 2022 That does not seem to be a barrier in this case. The federal government can and very much should require strong authentication from any federal employees accessing federal data systems. I believe the Biden administration laid down a deadline last year about this that DEA and others have obviously missed. How the feds deal with state and local is a bigger challenge. https://www.federalregister.gov/documents/2021/05/17/ 2021-10460/improving-the-nations-cybersecurity Reply - 1. JamminJ May 12, 2022 Yes, I was just addressing the non-gov use case that Reader expressed. "willing to bet big money that this DEA portal is not only offender here" I could not take that bet, as I know this to be true. It is a sad fact that although we've made progress and advise the private sector to take security more seriously, the federal government moves much slower than the words travel. Lots of agencies and lots of bureaucracy. And of course, federalism prevents a concerted effort down to the state and local levels too. Thanks for the link. "Agencies that are unable to fully adopt multi-factor authentication and data encryption within 180 days of the date of this order shall, at the end of the 180-day period, provide a written rationale to the Secretary of Homeland Security through the Director of CISA, the Director of OMB, and the APNSA." As with any Executive Order, there are lots of caveats and loopholes that can neuter the effect. Having single factor "backup" authentication methods is a common one unfortunately. Reply - 6. Mike May 12, 2022 A reminder that this agency (like many) has a virtually unlimited budget, and vast forfeiture powers (that are not just used against "kingpins" as said in the article), yet still takes security shortcuts that border negligence. The real question is, what are the reprocussions (if any) going to be? Reply - 1. Larry wannabetech May 12, 2022 Of course as you know, the answer is none. Is there ever? Reply - 7. Newport May 12, 2022 HI Brian, Thanks for posting. If this happened this is quite a breach! Maybe time for PIV cards for all users who need access to these systems. Regards, Newport Reply - 8. Ashfak May 12, 2022 Your writing skills just amazing Reply - Leave a Reply Cancel reply Your email address will not be published. Required fields are marked * [ ] [ ] [ ] [ ] [ ] [ ] [ ] Comment * [ ] Name * [ ] Email * [ ] Website [ ] [Post Comment] [ ] [ ] [ ] [ ] [ ] [ ] [ ] D[ ] Advertisement [3] Advertisement Mailing List Subscribe here Search KrebsOnSecurity Search for: [ ] [Search] Recent Posts * DEA Investigating Breach of Law Enforcement Data Portal * Microsoft Patch Tuesday, May 2022 Edition * Your Phone May Soon Replace Many of Your Passwords * Russia to Rent Tech-Savvy Prisoners to Corporate IT? * You Can Now Ask Google to Remove Your Phone Number, Email or Address from Search Results Spam Nation Spam Nation A New York Times Bestseller! Thinking of a Cybersecurity Career? Thinking of a Cybersecurity Career? Read this. All About Skimmers All About Skimmers Click image for my skimmer series. Story Categories * A Little Sunshine * All About Skimmers * Ashley Madison breach * Breadcrumbs * Data Breaches * DDoS-for-Hire * Employment Fraud * How to Break Into Security * Latest Warnings * Ne'er-Do-Well News * Other * Pharma Wars * Ransomware * Russia's War on Ukraine * Security Tools * SIM Swapping * Spam Nation * Target: Small Businesses * Tax Refund Fraud * The Coming Storm * Time to Patch * Web Fraud 2.0 The Value of a Hacked PC valuehackedpc Badguy uses for your PC Badguy Uses for Your Email Badguy Uses for Your Email Your email account may be worth far more than you imagine. Donate to Krebs On Security Most Popular Posts * Sextortion Scam Uses Recipient's Hacked Passwords (1076) * Online Cheating Site AshleyMadison Hacked (798) * Sources: Target Investigating Data Breach (620) * Trump Fires Security Chief Christopher Krebs (534) * Cards Stolen in Target Breach Flood Underground Markets (445) * Reports: Liberty Reserve Founder Arrested, Site Shuttered (416) * Was the Ashley Madison Database Leaked? (376) * DDoS-Guard To Forfeit Internet Space Occupied by Parler (374) * True Goodbye: 'Using TrueCrypt Is Not Secure' (363) * Who Hacked Ashley Madison? (361) Why So Many Top Hackers Hail from Russia [computered-580x389] Category: Web Fraud 2.0 Criminnovations Innovations from the Underground [shreddedID-copy-285x189] ID Protection Services Examined Is Antivirus Dead? Is Antivirus Dead? The reasons for its decline The Growing Tax Fraud Menace The Growing Tax Fraud Menace File 'em Before the Bad Guys Can Inside a Carding Shop Inside a Carding Shop A crash course in carding. Beware Social Security Fraud Beware Social Security Fraud Sign up, or Be Signed Up! How Was Your Card Stolen? How Was Your Card Stolen? Finding out is not so easy. Krebs's 3 Rules... Krebs's 3 Rules... ...For Online Safety. (c) Krebs on Security