The FBI has warned that hackers linked to Anonymous secretly accessed U.S. government computers across multiple agencies and stole sensitive information in a campaign spanning nearly a year, according to an FBI memo first reported by Reuters.
Adobe ColdFusion as the Entry Point
The attackers exploited a vulnerability in Adobe ColdFusion software — widely used to build websites — to launch a wave of intrusions beginning in December 2012. After gaining initial access, the hackers installed backdoors to maintain persistent access to compromised systems, returning as recently as October 2013. The FBI described the situation as a "widespread problem that should be addressed."
Affected agencies included the U.S. Army, Department of Energy, Department of Health and Human Services, and potentially many more. Investigators were still assessing the full scope of the campaign, which they believed was ongoing at the time of the memo's distribution.
104,000 Personal Records Stolen
According to an internal email from Energy Secretary Ernest Moniz's chief of staff, the stolen data included personal information on at least 104,000 individuals — employees, contractors, family members, and others associated with the Department of Energy — along with information on approximately 2,800 bank accounts. Officials expressed serious concern that the compromised banking data could facilitate theft.
Operation Last Resort
The hacking campaign was linked to the case of Lauri Love, a British resident later indicted for unauthorized access to computers at multiple federal agencies. Some of the breaches had been publicly claimed by Anonymous-affiliated individuals as part of "Operation Last Resort" — a campaign launched in retaliation for what the collective perceived as overzealous prosecution of hackers, including the case of Aaron Swartz, who faced federal charges for downloading academic journal articles before his death.
Beyond DDoS: Growing Sophistication
The campaign demonstrated that Anonymous-affiliated actors were capable of operations well beyond the DDoS attacks and website defacements traditionally associated with the collective. The exploitation of enterprise software vulnerabilities, persistent backdoor access, and large-scale data exfiltration across multiple federal agencies represented a meaningful escalation in both ambition and technical capability.
An Adobe spokeswoman noted that the majority of attacks involving its software exploited installations that had not been updated with the latest security patches — reinforcing the critical importance of timely patch management across government systems.