Description

General Electric (GE) is currently investigating a potential breach in its development environment following claims by a threat actor named IntelBroker. In November 2023, IntelBroker attempted to sell access to GE's development and software pipelines for $500 on a hacking forum. Failing to find buyers initially, the threat actor subsequently offered both network access and allegedly stolen data, including DARPA-related military information, on the same platform. The breach's authenticity remains unconfirmed, but IntelBroker has a history of successful cyberattacks, notably breaching the Weee! grocery service and pilfering sensitive data from the District of Columbia's D.C. Health Link program. The latter incident, occurring in March 2023, involved the sale of a stolen database containing personal information from numerous individuals. This breach prompted significant media attention and a congressional hearing to investigate the incident. During the congressional hearing, Mila Kofman, Executive Director of the District of Columbia Health Benefit Exchange Authority, revealed that the breach occurred due to a misconfigured server, allowing online accessibility to the data. The alleged breach in GE's development environment has raised concerns, particularly given IntelBroker's track record. The threat actor's claimed possession of DARPA-related military data from GE Aviation further emphasizes the sensitivity of the potentially compromised information. As investigations proceed, GE is actively assessing the situation to determine the validity of the breach and the extent of any potential data compromise. Such incidents underscore the importance of robust cybersecurity measures and vigilant monitoring to safeguard sensitive corporate and military-related information.