The US National Nuclear Security Administration (NNSA) has been confirmed as one of the organizations affected by the recent breach exploiting a Microsoft SharePoint vulnerability. An anonymous source from the NNSA stated that no classified data was reported stolen.
Overview of the breach
The exploitation of a zero-day vulnerability in SharePoint began affecting the Department of Energy on July 18. An agency spokesman noted the limited impact due to the widespread use of Microsoft M365 cloud and robust cybersecurity systems.
Response from NNSA and Department of Energy
NNSA referred all inquiries to the Department of Energy in response to the breach. A representative confirmed that a small number of systems were impacted and all affected systems are currently being restored.
Previous hacking incidents involving NNSA
This is not the first time hackers have penetrated NNSA-linked networks via third-party tools. In 2020, the agency was targeted in an attack on SolarWinds Corp., where malware was reportedly isolated to business networks only. The SharePoint breach also affected various state agencies both in the US and abroad.
The breach of NNSA systems highlights the vulnerability of government institutions to cyber threats. Such incidents raise concerns not only about potential data leaks but also about risks to national security.