EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/idaho-national-laboratory-breach-siegedsec-2023
122/430

File EL-0309HighResolvedData Breach / Employee Data Exfiltration

Idaho National Laboratory Breach

Also filed as INL HR Database Leak · SiegedSec Leak

This incident involved the unauthorized leak of sensitive Human Resources (HR) data from the Idaho National Laboratory (INL). The data dump, claimed by the hacktivist group SiegedSec, exposed personal identifying information (PII) of numerous employees. The breach highlighted significant cybersecurity vulnerabilities within a critical national nuclear research facility.

  • #idaho-national-laboratory
  • #siegedsec
  • #hr-data-leak
  • #ssn-theft
  • #critical-infrastructure
  • #cybersecurity
Notoriety6/10
Event
20 Nov 2023
Disclosed
20 Nov 2023
Target
Idaho National Laboratory
Actor
SiegedSec
Scale
HR Database Dump (Specific size unknown)
Status
Resolved

01Summary

In November 2023, the hacktivist group SiegedSec claimed responsibility for compromising the Idaho National Laboratory (INL), a key facility under the U.S. Department of Energy. The group released a dump of employee records, which included highly sensitive personal data. The leaked information spanned full names, dates of birth, physical addresses, email addresses, and critically, Social Security Numbers (SSNs) and direct deposit bank account details. The leak was primarily used by SiegedSec to demonstrate the lack of robust cybersecurity protections at the facility, thereby achieving a hacktivist objective rather than purely financial gain. The incident prompted immediate scrutiny of data handling protocols at other national critical infrastructure sites.

02Background

The Idaho National Laboratory is a premier research facility focused on nuclear science and energy, making its data highly sensitive and critical to national security. Historically, such facilities are subject to stringent federal cybersecurity regulations. This breach represents a targeted attack against the administrative and personnel systems, rather than the core nuclear research systems.

03Key revelations

  1. 01The vulnerability of critical national infrastructure to non-state hacktivist groups.
  2. 02The exposure of highly sensitive PII, including SSNs and bank details, of federal employees.
  3. 03The potential failure of internal security controls at a major Department of Energy facility.

04Technical analysis

The attack vector likely targeted the HR database or associated network segment, suggesting a failure in network segmentation or access control policies. The exfiltration method involved bulk data transfer, resulting in a comprehensive dump of structured employee records. The data types suggest the attackers gained access to systems managing payroll and personnel files.

Attack vector
Unknown (Likely Phishing or Exploitation of Network Vulnerability)
Attack method
Data Exfiltration and Leakage
Exfiltration
Bulk Data Transfer
Malware type
Stealer/Data Exfiltrator

Vulnerabilities exploited

  • Unknown (Potential lack of network segmentation)

MITRE ATT&CK techniques

  • T1046

05Threat actor

SiegedSec is a hacktivist group that operates by claiming responsibility for data leaks to demonstrate perceived security weaknesses in targeted organizations. Their motivation is typically ideological or political, aiming to generate public awareness and pressure for change rather than financial gain.

Aliases

  • SiegedSec

MITRE groups

  • T1190

Attribution sources

  • SiegedSec (Self-claimed)

06Victims and impact

Countries affected

  • United States

07Data exposed

Data types

  • Full Names
  • Dates of Birth
  • Email Addresses
  • Physical Addresses
  • Social Security Numbers
  • Bank Account Details
  • Payroll Information

Notable documents

  • HR Database Dump

08Financial damage

Damage is primarily assessed in terms of regulatory fines, reputational harm, and the cost of identity theft mitigation.

09Timeline

  1. 2023-11-20SiegedSec claims responsibility and leaks the HR database dump.

10Reaction and fallout

Public reaction

The public reaction focused on the alarming ease with which sensitive federal data could be compromised. Experts immediately called for stricter federal guidelines regarding data segmentation and employee training at critical facilities.

Political impact

The breach placed immediate political pressure on the Department of Energy and federal cybersecurity agencies to review and upgrade security protocols across all national laboratories. It fueled debates regarding the necessary level of federal oversight for critical infrastructure data.

11Legal

No immediate legal action or formal investigation outcome was reported in the source material, but the incident triggered internal reviews and heightened federal scrutiny.

12Aftermath

Policy changes

  • Increased federal scrutiny of data segmentation in national labs.

Regulatory changes

  • Potential updates to federal guidelines for handling PII in critical infrastructure.

Security improvements

  • Mandatory network segmentation between HR/Admin systems and core research networks.
  • Enhanced employee training on phishing and credential hygiene.

13Significance and legacy

Significance

This incident is significant because it demonstrated that even highly secured, critical national infrastructure facilities are vulnerable to non-state actors using administrative data leaks. It shifted the focus of cybersecurity risk assessment from purely physical/operational technology (OT) systems to the often-underestimated administrative technology (IT) systems that hold PII.

Legacy

The leak contributed to a broader industry conversation about the 'attack surface' of federal agencies, emphasizing that the weakest link is often the human element or the poorly segmented administrative network, rather than the core scientific systems.

14Disclosure and media

Authentication
Self-claimed by SiegedSec

Publishing organisations

  • SiegedSec

15Field notes

  1. 01The leak specifically targeted the HR database, indicating a focus on administrative data rather than core nuclear research secrets.
  2. 02The inclusion of SSNs and bank details elevates the risk from mere data exposure to immediate identity theft risk for the affected employees.

16Resolution

The immediate leak was contained by the public disclosure, leading to internal reviews and security upgrades at the facility.

17Sources

References

  1. [1]SiegedSec Leak Report
Fact sheetEL-0309

Dates

Event
20 Nov 2023
Discovered
20 Nov 2023
Disclosed
20 Nov 2023
Ongoing
No

Target

Organisation
Idaho National Laboratory
Type
Government
Sector
Nuclear Research/Critical Infrastructure
Country
United States
Gov. level
Federal

Actor

Name
SiegedSec
Type
Hacktivist Group
Motivation
Hacktivism/Demonstration of Vulnerability
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
HR Database Dump (Specific size unknown)
Sensitivity
Top Secret
Published
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.