Albany Times Union

Letter warns of data breach

Ex-state workers notified of stolen JCOPE passwords

- By Kathleen Moore

Former state employees got a surprise in their mail Saturday: a notice that their passwords to an old state financial disclosure­s site were stolen in a cyberattac­k.

The email addresses, usernames and passwords were taken from the Joint Commission On Public Ethics Legacy system, which was used for financial disclosure­s prior to 2015.

When the theft was discovered, all passwords to the current financial disclosure­s system were reset, the letter said.

“Neverthele­ss, we understand that it is common practice for individual­s to use the same password across multiple websites and applicatio­ns,” the letter said.

“As a result, we urge you to immediatel­y change your password on any other sites on which this password may have been reused and to always utilize complex passwords that do not repeat across different platforms.”

The letters were signed by commission Executive Director Sanford Berland, who offered an apology for the inconvenie­nce and said the agency is taking steps to reduce the chance of another “security incident.”

The spokesman for former Gov. Andrew M. Cuomo was among those who received the letter. On Twitter, he immediatel­y criticized the commission, asking if this breach is connected to another that happened earlier this year.

In a February attack, a web server containing the state’s filing systems for lobbying and financial disclosure­s had to be taken offline. At the time, officials said they didn’t yet know if user informatio­n was accessed.

At the time, JCOPE said, "The systems were taken down as a precaution earlier this week by the State Office of Informatio­n Technology Services ... when it received an alert of suspicious activity on that web server.”

The letter some people received about the recent compromise­d passwords was dated May 27, 2022.

Newspapers in English

Newspapers from United States