Capitol Fax.com - Your Illinois News Radar » “Foreign” hack attack on state voter registration site
SUBSCRIBE to Capitol Fax      Advertise Here      About     Exclusive Subscriber Content     Updated Posts    Contact Rich Miller
CapitolFax.com
To subscribe to Capitol Fax, click here.
“Foreign” hack attack on state voter registration site

Thursday, Jul 21, 2016 - Posted by Rich Miller

* From the McLean County Clerk’s Facebook page

The State Board of Elections (SBE) fell victim to a cyberattack that was detected on July 12, 2016. Specifically, the target was the [Illinois Vital Records System] database. Once discovered, State Board of Elections closed the point of entry. On July 13th, once the severity of the attack was realized, as a precautionary measure, the entire IVRS system was shut down, including online voter registration.

SBE’s Information Technology and Voting and Registration Systems staff immediately began researching the extent of the infiltration. Thus far, we have determined the following:

    · The pathway into IVRS was NOT through our firewalls but through a vulnerability on our public web page that an applicant may use to check the status of their online voter registration application.
    · The method used was SQL injection. The offenders were able to inject SQL database queries into the IVRS database in order to access information. This was a highly sophisticated attack most likely from a foreign (international) entity.
    · We have found no evidence that they added, changed, or deleted any information in the IVRS database. Their efforts to obtain voter signature images and voter history were unsuccessful.
    · They were able to retrieve a number of voter records. We are in the process of determining the exact number of voter records and specific names of all individuals affected. (Because of the complex methods used to access the data, this may take 10-15 days.)
    · In an effort to prevent an attack such as this from happening in the future, we have made a number of security enhancements to the IVRS and POVA systems.
    · Once the system is brought back online, all IVRS user passwords will need to be changed at the first login (or by your vendor for system specific accounts). The new password must be a minimum of eight characters in length, one of which must be a non-alphanumeric character ($, *, # etc.).

Pursuant to the Personal Information Protection Act (815 ILCS530/), the Illinois General Assembly and the Office of the Attorney General have been notified of the incursion. Furthermore, once we have determined the number of voter records and the individuals whose information was collected, we are prepared to take the proper steps required to notify those persons.

A separate notification will be sent indicating when you and your staff may access IVRS. Thank you for your patience regarding this matter.

Kyle Thomas
Illinois State Board of Elections
Director-Voting and Registration Systems

* Dan Petrela

The registration database is a frequent target of cyberattacks, [Ken Menzel, the Illinois State Board of Elections’ general counsel] said, but “this is the first time that we’re aware of that anybody’s gotten into anything — not for lack of trying .”

Menzel said the board is confident that no voter information in the database was altered and will follow the proper notification procedures if any personal information was compromised.

       

15 Comments
  1. - Union Dues - Thursday, Jul 21, 16 @ 12:37 pm:

    SQL injection is not an advanced techique at all and only possible if your web page is poorly written.


  2. - Ghost - Thursday, Jul 21, 16 @ 12:39 pm:

    Points to them for detecting this and their actions afterward. well done.


  3. - Formerly Known as Frenchie M - Thursday, Jul 21, 16 @ 12:42 pm:

    I’m sorry this happened — but there’s very little excuse these days to not prevent a SQL injection attack. They’ve been — for years — a primary attack vector for publicly accessible websites.

    Another issue, though, and one that’s even more troubling — and something I don’t see in the post — is how the passwords were stored (encrypted? properly salted and then hashed?). They say the passwords need to be changed — and that’s good. But I hope — I hope — they’re stored properly.


  4. - Bigtwich - Thursday, Jul 21, 16 @ 12:58 pm:

    So, an early story today was about,

    “Schneider complimenting Rauner’s campaign for helping get tons more data and info on IL voters”

    Hum? s/


  5. - illinois manufacturer - Thursday, Jul 21, 16 @ 1:05 pm:

    Probably China but funny on Rauner. China has been hacking huge amounts of medical data.No one really knows why


  6. - Skeptic - Thursday, Jul 21, 16 @ 1:19 pm:

    *facepalm* You got breached by SQL Injection? Really?


  7. - Jon - Thursday, Jul 21, 16 @ 1:32 pm:

    Isn’t Vital Records, like birth certificates, etc., IDPH, not SBOE? Could it be Illinois Voter Registration System?


  8. - Honeybear - Thursday, Jul 21, 16 @ 1:47 pm:

    I don’t know what this all means but it sounds quite bad.


  9. - PENSIONS ARE OFF LIMITS - Thursday, Jul 21, 16 @ 1:57 pm:

    SQL injection is hacking 101. The superstars at the newly created division of IT definitely dropped the ball here. “Phony” superstars.


  10. - Rhino - Thursday, Jul 21, 16 @ 3:42 pm:

    The registration database is not private but is supposed to be available to anyone at any time. The key question is whether data was or could have been altered. If not, no harm, no foul.


  11. - Arthur Andersen - Thursday, Jul 21, 16 @ 4:38 pm:

    All snark aside, they need a guy like John Bambenek right now.


  12. - Downstate Libertarian - Thursday, Jul 21, 16 @ 6:15 pm:

    Not happy to see this. As other said, it is not an advanced attack. Not happy to see the password standards that are in place. Considering the “sophistication” of the attack, the point raised by Formerly… is a definite concern. Would not be surprised that any encryption not be up to current standards and salting is probably out of the question.


  13. - PENSIONS ARE OFF LIMITS - Thursday, Jul 21, 16 @ 9:33 pm:

    These rookies need to figure out what information was obtained. I’m not going to tell them what constitutes a breach. I ain’t no superstar. Hint: PIPA


  14. - PENSIONS ARE OFF LIMITS - Thursday, Jul 21, 16 @ 9:38 pm:

    Rhino

    There is personal information in the database that is not publicly available. SQL injection gets that information from a poorly hosted website. Don’t argue for people who messed up. Ever.


  15. - OneMan - Monday, Jul 25, 16 @ 3:23 pm:

    Guess they should be thankful Little Bobby Tables isn’t of voting age yet.

    https://xkcd.com/327/

    Others have said it, but SQL injection is not a sophisticated attack.

    Is the IVRS more than just voter data?


Sorry, comments for this post are now closed.


* Reader comments closed for the holidays
* And the winners are…
* SUBSCRIBERS ONLY - Update to previous editions
* Isabel’s afternoon roundup
* Report: Far-right Illinois billionaires may have skirted immigration rules
* Question of the day: Golden Horseshoe Awards (Updated)
* Energy Storage Brings Cheaper Electricity, Greater Reliability
* Open thread
* Isabel’s morning briefing
* SUBSCRIBERS ONLY - Today's edition of Capitol Fax (use all CAPS in password)
* Live coverage
* Selected press releases (Live updates)
* Yesterday's stories

Support CapitolFax.com
Visit our advertisers...

...............

...............

...............

...............

...............

...............

...............


Loading


Main Menu
Home
Illinois
YouTube
Pundit rankings
Obama
Subscriber Content
Durbin
Burris
Blagojevich Trial
Advertising
Updated Posts
Polls

Archives
December 2024
November 2024
October 2024
September 2024
August 2024
July 2024
June 2024
May 2024
April 2024
March 2024
February 2024
January 2024
December 2023
November 2023
October 2023
September 2023
August 2023
July 2023
June 2023
May 2023
April 2023
March 2023
February 2023
January 2023
December 2022
November 2022
October 2022
September 2022
August 2022
July 2022
June 2022
May 2022
April 2022
March 2022
February 2022
January 2022
December 2021
November 2021
October 2021
September 2021
August 2021
July 2021
June 2021
May 2021
April 2021
March 2021
February 2021
January 2021
December 2020
November 2020
October 2020
September 2020
August 2020
July 2020
June 2020
May 2020
April 2020
March 2020
February 2020
January 2020
December 2019
November 2019
October 2019
September 2019
August 2019
July 2019
June 2019
May 2019
April 2019
March 2019
February 2019
January 2019
December 2018
November 2018
October 2018
September 2018
August 2018
July 2018
June 2018
May 2018
April 2018
March 2018
February 2018
January 2018
December 2017
November 2017
October 2017
September 2017
August 2017
July 2017
June 2017
May 2017
April 2017
March 2017
February 2017
January 2017
December 2016
November 2016
October 2016
September 2016
August 2016
July 2016
June 2016
May 2016
April 2016
March 2016
February 2016
January 2016
December 2015
November 2015
October 2015
September 2015
August 2015
July 2015
June 2015
May 2015
April 2015
March 2015
February 2015
January 2015
December 2014
November 2014
October 2014
September 2014
August 2014
July 2014
June 2014
May 2014
April 2014
March 2014
February 2014
January 2014
December 2013
November 2013
October 2013
September 2013
August 2013
July 2013
June 2013
May 2013
April 2013
March 2013
February 2013
January 2013
December 2012
November 2012
October 2012
September 2012
August 2012
July 2012
June 2012
May 2012
April 2012
March 2012
February 2012
January 2012
December 2011
November 2011
October 2011
September 2011
August 2011
July 2011
June 2011
May 2011
April 2011
March 2011
February 2011
January 2011
December 2010
November 2010
October 2010
September 2010
August 2010
July 2010
June 2010
May 2010
April 2010
March 2010
February 2010
January 2010
December 2009
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008
August 2008
July 2008
June 2008
May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
February 2007
January 2007
December 2006
November 2006
October 2006
September 2006
August 2006
July 2006
June 2006
May 2006
April 2006
March 2006
February 2006
January 2006
December 2005
April 2005
March 2005
February 2005
January 2005
December 2004
November 2004
October 2004

Blog*Spot Archives
November 2005
October 2005
September 2005
August 2005
July 2005
June 2005
May 2005

Syndication

RSS Feed 2.0
Comments RSS 2.0




Hosted by MCS SUBSCRIBE to Capitol Fax Advertise Here Mobile Version Contact Rich Miller