Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - US Govt Network Compromised By Employee Looking At Adult Content
News & Analysis

US Govt Network Compromised By Employee Looking At Adult Content

ISBuzz TeamBy ISBuzz TeamOctober 31, 2018Updated:July 4, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Centrify
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Today, it has been reported that an employee of the US Geological Survey (USGS) viewing adult content at work has led to a government network being compromised by malware. Investigators have since found that the culprit had viewed over 9,000 sites at work.

IT security experts commented below.

Richard Walters, CTO at CensorNet:

“This story is a fable in how the bad actions of one employee can throw an entire network into jeopardy. And before we get on our high horse and start to think that it could never happen in the UK, remember that official data found 160 adult content requests a day from devices connected to the Houses of Parliament. In fact, in a survey we ran of 1000 UK adults, 10% of respondents openly admitted to visiting adult websites on a work device or while connected to a company network. And that’s just scratching the surface of what the average employee is up to. A further 13% admitted to downloading or viewing pirated content. Putting aside the inappropriateness of these activities, adult and pirate websites are often cesspools of malware and viruses.

“The lesson is that all organisations, government or not, cannot just assume their employees are operating appropriately online – they need to deploy solutions that monitor and control what employees are accessing on their work devices to reduce the risk of malware getting onto the corporate system. There is no way that this employee’s consumption of adult content should have only been identified retrospectively – if the USGS had taken the right measures they could have stopped this activity long before malware made it onto the network.”

Fraser Kyne, EMEA CTO at Bromium:

“Not only has this employee earned a stinging HR rebuke, they also laid high value assets bare and put the organisation at risk. Luckily for them, The Earth Resources Observation and Science (EROS) Centre doesn’t operate any classified networks, meaning a major breach of national security was avoided. But hackers still had access to the US Geological Survey network, giving a clear indication of how fundamentally flawed the traditional approach to security is. Investigators have recommended blacklisting unauthorized websites and monitoring web usage, but this doesn’t provide the protection needed. Of course, blocking porn sites at work is a given, but how do you identify them all? Also, locking down uncategorized websites can often lead to denying access to web resources that employees actually need to use for their job. This creates friction, and users will inevitably find ways around restrictions and create black holes for security teams.

“Ultimately, this highlights that users are still the weakest link and can sometimes make stupid decisions. Threats can come anywhere, from dodgy websites to unknown email attachments and downloads. At the moment hackers need to only get it right once, because there will always be someone that will visit the wrong site or click on the wrong link. No amount of blacklisting (or HR chats) will change this, and it’s time to stop putting the burden of security on employees, because it is not their job to be the last line of defence. To do this, federal agencies should adopt layered cybersecurity defences that incorporate virtualisation-based application isolation, which allows users to open web pages, emails and documents in isolation from the host PC and network. This leaves hackers with nowhere to go and nothing to steal, allowing employees to get on with their job.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}