U.S. government caught being careless with "classified" information

The Head of Security Research at a firm focused on cybersecurity and privacy online recently discovered a U.S. government terror watchlist being hosted by a foreign IP address with no protection.

The researcher, Volodymyr “Bob” Diachenko of Comparitech, explains that on July 19, 2021, he found the list of 1.9 million Americans online without password protection or another form of authentication.

Diachenko wrote on LinkedIn, “The watchlist came from the Terrorist Screening Center, a multi-agency group administered by the FBI. The TSC maintains the country’s no-fly list, which is a subset of the larger watchlist. A typical record in the list contains a full name, citizenship, gender, date of birth, passport number, no-fly indicator, and more.”

The list is supposed to be classified and should only be accessible by “agencies and officials who are authorized to conduct terrorist screening in the course of their duties…”

Upon discovering the list, the cybersecurity expert contacted DHS and was thanked for his work.

However, it took three weeks for the list to be removed from the foreign server it was being held on.

The IP address where the database was found oddly came from the Asian country of Bahrain.

Information related to the 1.9 million Americans found on the list contains their full names, a TSC watchlist ID, citizenship, gender, date of birth, passport number, country of issuance, a no-fly indicator and more.

Additional categories were listed as well, but Diachenko was unsure of what they meant.

For example, “tag,” “nomination type,” and “selectee indicator” were fields available in the terror watchlist.

Expressing his concern about the list being in the wrong hands, the security head wrote, “This list could be used to oppress, harass, or persecute people on the list and their families. It could cause any number of personal and professional problems for innocent people whose names are included in the list.”

