Schumpeter

Business and management

A security breach at Booz Allen Hamilton

Hackers strike at a foe

Jul 12th 2011, 19:27 by R.L.G. | NEW YORK

ANONYMOUS, a group of “hacktivist” computer-savvy attackers, has already speared a number of big fish: credit-card companies, the church of Scientology, and Monsanto, a biotechnology firm. And the hackers have flaunted their skills by successfully attacking computer-security expert firms, like HBGary.

Its latest victim is Booz Allen Hamilton, a big consulting firm to America’s government, including on cybersecurity, with bigwigs like a former CIA head and a former director of national intelligence on its payroll. Anonymous opposes Booz Allen’s work for the government in the fight against terrorism. This included an alleged plan to fill social-networking sites with “sock puppets”—fake commenters who would spread disinformation. The hackers’ response has been to steal from Booz Allen what it says are 90,000 military e-mail addresses and passwords.

Booz Allen went public in November 2010, and just two weeks ago issued a confident first annual report as a public company. In it, the firm’s boss, Ralph Shrader, wrote “who would have imagined that in a single year Congress would pass landmark healthcare legislation and financial regulatory reform, a major cybersecurity breach would reveal sensitive government secrets, and an exploding oil rig would lead to the worst environmental disaster in US history? Years like this challenge us at Booz Allen Hamilton to do the best work for our clients.”  Now the company is on the wrong end of its own "major cybersecurity breach".

This comes after a good year, with $5.6 billion in revenue, 9.1% up on the previous year, and net income growth from $25.4m to $84.7m. In August, the firm's non-compete agreement with Booz & Co expires. Booz & Co and Booz Allen were split apart in 2008 so that Booz & Co could focus on the private sector, Booz Allen on the public sector. Booz Allen is expecting to expand its private-sector work when the agreement expires. So Anonymous’s attack comes at an especially awkward time.

Sitting duck
Booz Allen does not seem to have done its homework—which is somewhat embarrassing for a security contractor working with classified materials. Critics say that it did not protect its servers sufficiently and used algorithms to encrypt data that can be easily cracked. The firm is also said to have left its databases open to "SQL injection", a means of inserting malicious code. Anonymous says that the server it targeted “basically had no security measures in place”.

The stockmarket quickly shook off a small drop in Booz Allen’s share price. The long-term damage to the company—which was still boasting on its website on Tuesday evening that it was "leading the way in helping organisations develop skills for the Cyber Age"—may not be clear until fuller details of the hacking emerge. In any case, there is little doubt that the anxiety will be felt more widely. One executive vice-president at Booz Allen, Mike McConnell, used to run the National Security Agency, America’s electronic eavesdroppers. Hacking the company isn’t quite like hacking the Pentagon or the NSA, but it is not a million miles away, either. Mocking the government’s use of contractors, Anonymous sent Booz Allen an invoice for a “security audit” in the amount of $310. For “media and press” services, the charge was an even $0.00.

Read on: Hackers strike repeatedly at big American corporations (Jun 3rd)

Readers' comments

The Economist welcomes your views. Please stay on topic and be respectful of other readers. Review our comments policy.

Hank Smith

It is better to have security vulnerabilities exposed early than late. Hacking started with the birth of the internet, and everyone understands that online data is vulnerable. It goes without saying. That is better than a system secretly manipulated for decades.

Ah Beng

@thomas, bpai

I doubt many members of Anonymous are stupid enough to accept a job offer. Remember the German kid that hacked Valve's servers and released the Half-Life 2 development snapshot? He was arrested the moment he reached the US after being lured on the pretense of a job offer.

zerge

This is not about Booz Allen not knowing how to prevent SQL injection; of course they know how. This was most likely an IT administrative oversight: some little used, uncatalogued server out there with a public IP, that nobody was keeping track of, with obsolete software. An Anonymous found it for them.
It has nothing to do with technology, and everything to do with business processes.

nharmon

A security breach can happen to just about anyone unfortunately, but Booz-Allen-Hamilton should know how to prevent a SQL injection attack, given that it runs the Department of Defense's Information Assurance Technology Analysis Center (IATAC), the principle clearinghouse for data security information for the US military. The web site is http://iac.dtic.mil/iatac/index.jsp

bpai

Booz Allen ought to offer jobs to members of Anonymous (seriously). Who would be better qualified to stop hackers than a hacker?

Doubting_Thomas

*sigh* Oh Anon... I'm wondering when some of these firms will get smart and offer them absurd sums of money to work for them, instead of playing the blame game, doing nothing, then spending billions investing in facebook, twitter, and other tech bubbles.

vinayaksathe

Nothing is safe in cyberspace. A word written in cyberspace is less secure than that written on paper which in turn is less secure than that written in clay tablets or stone.
The danger posed by hackers may be more than leakage of information. Hackers may manupulate information stored or alter it to cause inintended consequences. Imagine tinkering with commands controlling a drone on combat mission.

Artificial Intelligence

In fact, Anonymous' methods bear a remarkable similarity to the journalism practiced by Murdoch's News International. Perhaps the Dirty Digger will shortly be offering them all a job?!

Artificial Intelligence

I find myself sympathizing with Anonymous. If they're exposing laxity and incompetence in contractors receiving government money, then they're doing an important job. You might even call it journalism! And they're entertaining us too. It's nearly a public service.

About Schumpeter

In this blog, our Schumpeter columnist and his colleagues provide commentary and analysis on the topics of business, finance and management. The blog takes its name from Joseph Schumpeter, an Austrian-American economist who likened capitalism to a "perennial gale of creative destruction"

Advertisement

Money talks audio

Trending topics

Read comments on the site's most popular topics

Advertisement

Products & events