Summary

A vulnerability in the new OPM email server allowed anyone to send mass messages to federal employees, exposing poor cybersecurity.

Over 13,000 NOAA staff received spam and vulgar messages, including crude jokes about Trump and bizarre newsletters, causing widespread outrage.

The breach resulted from an overhaul led by Elon Musk that installed underqualified personnel and an insecure in-house system, sparking a class-action lawsuit for cybersecurity failures.

The unsecured system also inadvertently revealed ties to Project 2025 and a plan to gather government employee data as Trump’s loyalists reshape federal operations.

  • Hobbes_Dent@lemmy.world
    link
    fedilink
    arrow-up
    81
    arrow-down
    2
    ·
    2 months ago

    The breach resulted from an overhaul led by Elon Musk that installed underqualified personnel and an insecure in-house system, sparking a class-action lawsuit for cybersecurity failures.

    And y’all let him have access to government.

    The world will burn from climate and war because of American stupidity.

      • PugJesus@lemmy.world
        link
        fedilink
        English
        arrow-up
        45
        arrow-down
        4
        ·
        2 months ago

        As much as I wish otherwise, Trump got a plurality of the vote, and pre-election day polling was clear that such a result was very possible.

        The plurality of the people who bothered to vote put Trump in, who was quite clear about his alliance with Musk.

        This is on us.

        • TrickDacy@lemmy.world
          link
          fedilink
          arrow-up
          6
          arrow-down
          1
          ·
          2 months ago

          “us” being “a bunch of apathetic idiots and idiots deeply opposed to the rest of the country”

        • TropicalDingdong@lemmy.world
          link
          fedilink
          arrow-up
          4
          arrow-down
          9
          ·
          edit-2
          2 months ago

          We can put a significant amount of blame in the laps of Democrats (as in, DNC officials) and their sycophants and defenders in both media and online.

          Lemmy itself worked to become an echo chamber reflecting an uncritical assessment of both Democrat performance from 2021-2024, and as well the legitimate electoral performance of both the Biden, and separately, the Harris campaign.

          Reality: the denialism around how bad and unpopular both Biden and Harris were in their role as Executives in Cheif, did substantial damage to Harris and probably cost them the election.

          That denialism was RAMPANT across lemmy, and still persists today.

          You can not make a convincing argument that your team should be the ones elected when you are asking people to deny the evidence of their lives experience, and that’s exactly what both the Biden and Harris campaign did. Lemmy moderators also worked to suppress any media or users critical of Harris and Biden.

          Harris needed to feel the pressure from the electorate that Americans sensed that the country wasn’t doing well and was going in the wrong direction. She needed to understand and respond to the fact that Americans, in general, wanted a change from how Democrats had been managing.

          Building an echo chamber, in both mainstream media and social media, to shut that view point out, and ultimately leave it unaddressed, is why the Harris campaign failed.

          That echo chamber shielded the campaign from critical information they needed to be aware of to make the right kinds of changes which might have led to success.

          And every moderator here, who suppressed criticism, or who uses bans to create an echo chamber in forums like c/World, c/Politics, and c/PoliticalMemes is in part to blame.

      • Couldbealeotard@lemmy.world
        link
        fedilink
        English
        arrow-up
        10
        arrow-down
        1
        ·
        2 months ago

        Unless you are suggesting that actual election fraud took place, these guys got democratically elected.

        From the outside it seems like this is what the majority of your voting public wanted, and the majority of your adult population were fine with it and chose not to vote. If it were the first time I would consider it as revealing a major flaw in your political system, but this is the second time, non consecutively, that this has happened. That just looks like this is representative of your people. Sorry.

        • timbuck2themoon@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          17
          ·
          2 months ago

          It is. Im tired of people making excuses for the idiots in this country. Idgaf if you thought the Democrats were terrible- theyre clearly far better than these fascists. But enough people decided it wasn’t worth their time anyhow.

          Fuck them and fuck all of us because this is who we are.

                • Quadhammer@lemmy.world
                  link
                  fedilink
                  arrow-up
                  1
                  arrow-down
                  1
                  ·
                  2 months ago

                  what a stupid comment

                  cucked by two fake geniuses 😂😂😂😂😂😂😂😂😂😂😂😂😂😂🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣😭😭😭😭😭😭😭😭😭😭😭😭😭😭😭😭😳🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣🤣😂😂😂😂😂😂😂😂😂😂😂😂😂

  • roofTophopper@lemmy.world
    link
    fedilink
    arrow-up
    12
    ·
    2 months ago

    Expect more of this. Unfortunately, ears will be plugged and eyes will be covered as people just go “lalalalala”

  • towerful@programming.dev
    link
    fedilink
    arrow-up
    10
    ·
    2 months ago

    It’s been 4 days.
    How did people get these email addresses?
    I mean, the domain is known.
    But was the system that president musk broke really holding back this torrent of abuse and garbage?
    Feels like actual email addresses were leaked.
    Unless it was a mailing list that was suddenly exposed.

    Still seems strange that an email that simply says “yo” suddenly came through as part of the spam.
    Feels like email addresses were posted somewhere, and someone jumped on for the lulz. Along with the wall of trolls and abusers jumping on.

    I mean, as soon as I link a domain to an IP, I see all sorts of “security” scans turn up. Till then, firewall is pretty quiet.
    And if I wildcard direct a domain to an ip, the root gets scanned but any sub domains don’t.
    I feel email addresses would follow a similar pattern.

    • MrEff@lemmy.world
      link
      fedilink
      arrow-up
      34
      ·
      2 months ago

      It’s worse than you think. Last week we got an email that looked like strait up fishing spam demanding that we were to email back “yes” confirming that we got the email. So many people even reported it as spam that we had supervisors have to directly tell us that it was legit. Then they sent out a second email with a warning that is was in fact legit and to respond to that email with “yes” if we got that one.

      On the back end at OPM: Musk forced his way in and demanded to redo the email servers. The IT told him it wasn’t possible for what he was asking. So he brought in his own goons to install a non government server with unknown software and unknown security configurations and they plugged it into the OPM network to spoof it as an official OPM server, then sent out those emails.

      And sure enough, the idiot didn’t didn’t configure the security correctly or let official government IT people touch it, it ended up backdooring into the entire government HR system, and it had every active government email that responded “yes” to his stupid email that we were required to. And now we know it was compromised. There is no telling what foreign governments now have all of that info as well as what other backdoors they have installed.

      • towerful@programming.dev
        link
        fedilink
        arrow-up
        26
        ·
        2 months ago

        Holy shit.
        That’s some shit that contravenes every security briefing, every security best practice.
        Then they go and spoof a legit government installation with their own bullshit?!
        Fucking Hilary and her email servers. But like times 10. Legitimately compromising the US government communications.
        Why is this lawsuits, why isn’t this treason?!

        • dhork@lemmy.world
          link
          fedilink
          English
          arrow-up
          10
          ·
          2 months ago

          why isn’t this treason?!

          Because Musk bought the election for Trump, and now Musk do whatever he wants.

        • dx1@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          2 months ago

          Some history on the word “treason”, it’s not the legal definition, it’s whenever you go against whoever is in control.

  • Rhoeri@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    2 months ago

    I wonder how much of the intended damage he wants us to suffer is going to be mitigated as a result of their incompetence, and then I wonder how long can we count on them to continue making these mistakes before people begin to get seriously hurt…

  • nomoredrama@lemmy.world
    link
    fedilink
    arrow-up
    8
    arrow-down
    6
    ·
    2 months ago

    This is glorious. The mess is amazing, but the money that will be saved after it’s all done will be worth it.