NOAA, Other U.S. Agency Security Breaches: Connecting the Dots | eWeek

NOAA, Other U.S. Agency Security Breaches: Connecting the Dots

NOAA security breach
Nov 12, 2014
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The National Oceanic and Atmospheric Administration (NOAA) was breached by attackers, allegedly from China, in an attack that has now been contained. NOAA’s areas of responsibility include the National Weather Service, and its overall operations include U.S.-operated satellites and imaging systems.

In a statement sent to eWEEK by NOAA spokesperson Scott Smullen, the agency notes that in recent weeks, four NOAA Websites were compromised by an Internet-sourced attack.

“NOAA staff detected the attacks, and incident response began immediately,” NOAA states. “Unscheduled maintenance was performed by NOAA to mitigate the attacks. The unscheduled maintenance impacts were temporary, and all services have been fully restored.”

NOAA also noted that the unscheduled maintenance did not prevent the agency from delivering forecasts to the public.

“The investigation is continuing with the appropriate authorities, and we cannot comment further,” NOAA stated.

The NOAA statement makes no claims of attribution as to who might be behind the attack. A Washington Post report points fingers at hackers from China.

The NOAA breach is the third major attack that has been publicly reported against a U.S. federal government-associated agency in recent weeks. Earlier this week, the United States Post Office (USPS) publicly admitted that it was breached, exposing both employee and customer information.

In the USPS incident, no formal attribution has been made about who the attackers are or where they came from, though China is also suspected of being involved in the attack.

At the end of October, the White House network was also breached. In that incident, attackers from Russia are suspected to be involved.

In the USPS, White House and now NOAA breaches, all of the agencies responded by shutting down parts of their network for a period of time in order to remediate the risk.

While NOAA is only today admitting to the breach, its statement indicated that it occurred in “recent weeks,” which might potentially place the attack in the same timeframe as the USPS and White House incidents. While the USPS breach was only disclosed this week, Congress was notified of the attack in September in a classified briefing.

Advertisement

In a statement, Reps. Darrell Issa (R-Calif.), chairman of the House Oversight and Government Reform Committee, and Blake Farenthold (R-Texas), chairman of the House Oversight Committee Subcommittee on Postal Service, took issue with the lack of information about the USPS breach.

“The Committee will also be seeking information about why the Administration waited two months before making the news of this attack public and preventing victims from taking proactive measures to secure their own information,” the Congressmen stated. “We have not been told why the agency no longer considers the information classified.”

Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.