State auditor: Hackers infiltrated agency network

Hackers, apparently from outside the U.S., have made one Kentucky state agency’s computer network their old Kentucky home, according to Kentucky’s state auditor.

In a press conference held in the city of Frankfort Tuesday, State Auditor Ed Hatchett told reporters that hackers who appeared to be from France broke into servers on the internal network of the Kentucky Transportation Cabinet, the state agency for transportation and vehicle-registration functions.

Since at least April, the hackers have been using it as a warehouse for pirated music, electronic games and movies – even new films like “Lara Croft Tomb Raider: The Cradle of Life” and “Spy Kids 3D: Game Over.”

The hackers also probably had access to bill-paying systems and state-held information such as driver’s licenses, the state auditor said.

Harold McKinney, attorney in the state auditor’s office, said the problems were uncovered during a recent vulnerability assessment of the state agency’s computer network done as part of a routine financial audit of records.

There were signs that some activity originated from Canada and Croatia, in addition to France. The state auditor, who has no more specific information about the hackers, immediately notified the Transportation Cabinet staff about the matter and decided to call a press conference to inform the public.

The Kentucky Transportation Cabinet wasn’t aware of the problem until informed Tuesday. Since Tuesday, agency staff have been busy assessing the damage and trying to answer press questions.

Transportation Cabinet spokesman Mark Pfeiffer, who acknowledged some servers at the agency had been hacked, said the agency does not believe internal records and billing systems were compromised.

“The auditor claimed our public records and driver’s license records were in jeopardy, but that’s not true,” said Pfeiffer, because those systems reside on separate networks that are securely separated from the hacked servers.

In addition to its hacker woes, the Kentucky Transportation Cabinet was also coping with another shocking public disclosure by the state auditor yesterday: some Transportation Cabinet employees have been looking at porn sites on the Internet during their working hours.

The Transportation Cabinet has a policy prohibiting such activity, but according to the state auditor, a random check showed that 6,000 porn images were accessed in just four days.