Firewall rule change exposed path to 50M immigration records, researcher says

Government contractor reversed change after demonstration showed VPN access to classified datacenter

By LineZotpaper
Published
Read Time2 min
A government contractor temporarily opened a firewall rule that let anyone with a commercial datacenter VPN reach a classified server holding 50 million immigration records, according to security researcher Joe Brinkley. The change was made while the security officer who flagged it was on vacation, and was reversed only after he demonstrated the vulnerability.

Security researcher Joe Brinkley, a former information system security officer for a government contractor, has described how a firewall rule change created a direct path from a low-security commercial datacenter to a classified server holding about 50 million immigration records.

In the early 2010s, the contractor used a provisioning server to deploy code from development to production. Developers wanted to ease that process by allowing the provisioning server to access production servers in the classified datacenter. Brinkley objected at a Change Review Board, warning that opening a firewall rule from a low-level secured datacenter to a top-secret production environment would let anyone on the commercial VPN — which was shared with non-government tenants like Microsoft and Oracle — potentially reach the high-level datacenter.

While Brinkley was on vacation, the developers took their request directly to the Change Acceptance Board and the rule was changed. Upon his return, Brinkley arranged a demonstration with a company colleague and a government representative. Tethering his laptop to his cell phone, he logged into the dev server over the VPN, then showed he could also reach and control the production server using the same connection.

That server held records on who was coming to the country and who they stayed with — around 50 million entries. According to Brinkley, thousands of people had access to the commercial VPN, but only dozens were supposed to reach the classified datacenter. The production servers still required usernames and passwords, but there was no multi-factor authentication and password standards were low at the time, making brute-force or guessing attacks feasible.

After the demonstration, supervisors immediately reverted the firewall rule. Brinkley told The Register that the incident illustrates how even layered defences like VPNs and passwords are insufficient if organisations sacrifice security for convenience.

§

Analysis

Why This Matters

  • The incident shows how a seemingly routine change for developer convenience can expose highly sensitive government data to a much wider network than intended.
  • It highlights the risk of firewall rules being altered without proper security review — especially when approval can bypass the designated security officer.
  • The lapse occurred years ago, but similar vulnerabilities may persist elsewhere, underscoring the need for strong change-management processes and multi-factor authentication.

Background

Government contractors routinely operate in both classified and unclassified environments, with strict network separation required. Firewall rules are meant to enforce that boundary. This case, from the early 2010s, predates widespread adoption of multi-factor authentication, which is now standard in many federal systems. The exact contractor and agency involved were not named in the report.

Key Perspectives

Developers: Wanted faster code deployment and argued the change was needed for efficiency. Their decision to go directly to the Change Acceptance Board bypassed the security officer's objections. Security researchers/officers: Brinkley and others in security roles view such changes as unacceptable risk, especially when the low-security network is shared with external tenants with much broader access. Contractor and government representatives: After seeing the demonstration, they acted quickly to reverse the change, suggesting an operational preference for security once the risk was made concrete — but also raising questions about why the initial approval was granted. Critics/Skeptics: Could argue that passwords provided some protection, and that the change was reversed without any known breach. However, the ease of access demonstrated and the lack of MFA make the exposure significant.

What to Watch

  • Whether the contractor or other agencies have since audited similar firewall rules for other classified/unclassified boundary pairs.
  • Adoption of MFA and stricter password policies for any remote access to high-security systems.
  • Any future reports of similar bypasses where security officers are overruled or circumvented.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.