An editorial piece by Jaded Security on the August 2011 AntiSec law-enforcement data dump and what it revealed about the state of government-website security.
AntiSec went after law enforcement that weekend. Hard.
Over 70 law-enforcement websites were compromised in what they called “Shoot the Sheriff Saturday”. The data dump included personal information on approximately 7,000 law-enforcement officers — names, addresses, phone numbers, Social Security numbers, and passwords.
To be clear before going any further: this is not an endorsement. Leaking SSNs and personal addresses of police officers puts real people and their families at risk. Whatever the politics, that is a line.
The scope
The targets were mostly small to mid-size police department websites. County sheriff offices, municipal police departments, a few state-level law-enforcement sites. The kind of sites that were probably built by the lowest bidder fifteen years earlier and never updated.
The passwords in the dump are illuminating. The usual suspects: “password123”, “police1”, badge numbers, first names followed by birth years. These are the people responsible for protecting communities, and they cannot protect their own accounts.
The political context
AntiSec framed the dump as retaliation for the arrests of Anonymous and LulzSec members. The accompanying statement referenced specific cases — the PayPal 14, Topiary, and others. The message was clear: arrest our people, we come after yours.
This is escalation. And escalation in this space does not end well for anyone.
What this tells us about the state of web security
The fact that 70+ government websites could be compromised in what appears to be a single coordinated operation tells the industry everything it needs to know about the state of government web security. SQL-injection attacks against unpatched CMS installations. Default credentials left in place for years. Databases with plaintext passwords.
This is not sophisticated. This is negligence. And it is negligence at every level — the departments that never funded security, the IT staff who never patched, the vendors who delivered insecure products and walked away, and the oversight bodies that never audited any of it.
Seventy websites. One weekend. By a group of activists with freely available tools.
Think about what a nation-state could do.