NASA updated on Advanced Persistent Threat last week: Hackers stolen MARS mission data

By Nancy Agarwal on June 27, 2019

USA: According to latest science news spread over social media, NASA’s Mars mission data was stolen by hackers from Jet Propulsion Laboratory (JPL) managed by California Institute of Technology (Caltech) for NASA in April 2018.  JPL is one of the leading US research and development firms which is responsible for conducting space-based astronomical missions like the construction of spacecraft for the solar system and examine the functioning of those space-crafts. It also supervises NASA's Deep Space Network (DSN).

Based on the OIG report, consisting of 49 pages, it is believed that hackers entered JPL servers through shared network gateway using ‘a compromised external user system’. Hackers broke into 23 files and collected nearly 500 MB of data which included information related to international traffic in arms regulations of Mars mission. NASA described that the point of entry was a Raspberry Pi device which was connected NASA network. It is probably difficult to predict that they entered without authorization or by following proper security procedure. It seems like system administrators lacked security certifications. However, the Information Technology Security Database (ITSDB), an inventory database is inaccurate to mark risks on JPL server, and also fails to respond to the security occurrences. This issue NASA is facing regarding cybersecurity should not be underestimated as it is inviting future advanced attacks.

Moreover, the justice department of the US charged two Chinese nationals government for hacking NASA, and US Navy network servers in December 2018. Investigators suspected that those 2 persons belonged APT10 which is the hacking unit of the Chinese Government and also they confirmed that this is separate breach from the hack in April 2018. It is the second interruption for JPL network in October 2018.

