Skip to main content
Back
General Services Administration

General Services Administration Data Breach (2013)

General Services Administration

lowVERIS
Disclosed

January 1, 2013

4833 days ago

Records

Undisclosed

Confirmed

Root Cause

Misconfiguration

Industry

Government

Description

GSA users may have been able to view the financial information and trade secrets of other GSA users due to a security vulnerability. The specific database that was affected is called the System for Award Management (SAM). Contractor and vendor registration records are cataloged by SAM. It is not clear how GSA became aware of the issue or how long it was a problem. Agency officials revealed that users could purposefully or inadvertently view the information of other users after following a series of steps.UPDATE (03/23/2013): Users had Social Security numbers and tax identification numbers exposed.

General Services Administration Data Breach (2013) | ExposedMap