Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

US Toughens Background Check Process After Major Hack

The US government said Friday it was revamping its background check process for federal employees and contractors with a more secure database, following a major hack disclosed last year.

The US government said Friday it was revamping its background check process for federal employees and contractors with a more secure database, following a major hack disclosed last year.

A new government entity will be created to conduct the checks, and the Department of Defense will provide security for the data gathered in the process, officials said.

The announcement came in response to disclosures last year that hackers accessed some 20 million personnel records for US government employees and contractors, including sensitive personal data in some cases gathered from background checks.

Several analysts have linked the hack to China, but US officials have avoided directly blaming Beijing for the breach. The new background check system will take over many functions from the Office of Personnel Management, which was roundly criticized for weak security following news of the breach.

The new “National Background Investigations Bureau,” with a presidentially appointed director, will take over the role of managing checks.

The new entity will be housed within OPM but the Defense Department will keep the data secure.

“This entity will have a considerable amount of operational autonomy,” said Michael Daniel, the White House cybersecurity coordinator, on a conference call with reporters.

“The Department of Defense will be providing the cybersecurity for this new entity,” Daniel said, adding that the revamped process would “represent real change from how we are doing business now.”

Advertisement. Scroll to continue reading.

Officials said that in addition to hardened cybersecurity, the new system would allow for an evaluation of how much data is stored online for accessibility and what is kept offline, inaccessible to hackers.

Officials said the administration’s budget calls for $95 million to upgrade the computer systems for the new initiative.

The disclosure of the breach last year rocked the federal government, revealing one of the worst cyber failures in the public sector.

The news led to congressional hearings and prompted the resignation of the OPM director.

The administration launched a government-wide review of cybersecurity last year as well as the background investigation process.

Related: CIA Pulled Officers from China After Govt Hack

Related: Top US Official Quits After Massive Government Hack

Written By

AFP 2023

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.