Understanding Blueleaks

With 2020 bringing in many changes that go as quickly as they come, none expected a hack on the American Government system.
Largest Published Hack Of American Law Enforcement Agencies
BlueLeaks refers to 269 gigabytes of internal U.S. law enforcement data obtained by the hacker collective Anonymous and was released on 19th of June, 2020, by the activist group Distributed Denial of Secrets(DDoSecrets), which called it -“the largest published hack of American law enforcement agencies”.
“The BlueLeaks archive indexes, ten years of data from over 200 police departments, fusion centers, and other law enforcement training and support resources and that among the hundreds of thousands of documents are police and FBI reports, bulletins, guides and more”, says DDoSecrets, in a recent tweet.
According to the report by KrebsOnSecurity, the data was taken from Nesential, which is a web developer that works with fusion centers and law enforcement agencies. Fusion centers are state-owned information gathering and analyzing centers that often coordinate between different regional, local, and federal law enforcement divisions. Specifically, the groups and fusion centers affected include the Missouri Information Analysis Center, the Northern California Regional Intelligence Center, the Joint Regional Intelligence Center, the Delaware Information and Analysis Center, the Austin Regional Intelligence Center, and Infragard.
The BlueLeaks collection includes internal memos, financial records, and more from over 200 state, local, and federal agencies. More
than one million documents were leaked from law enforcement fusion centers. In those leaked documents, officers track individuals, groups, and event pages with protests or any anti-law enforcement rhetorics. Some of the documents contain materials related to the attitudes of law enforcement and their response to the BLACK LIVES MATTER MOVEMENT, George Floyd protests, and the COVID-19 pandemic.
Read More: How to Stay Updated with Latest Cybersecurity News
The BlueLeaks data set was released on June 19, also known as “Juneteenth,” the oldest nationally celebrated commemoration of the ending of slavery in the United States. This year’s compliance with the date has been renewed in public interest in the wake of widespread protests against police brutality and the filmed killing of George Floyd at the hands of Minneapolis police.
During the George Floyd protests, law enforcement agencies monitored the protester’s statements and messages over social media. The leaked reports found that the police were aware of the potential for their surveillance to violate the Constitution. They distributed documents to police filled with rumors and warnings that the protests would become violent, sparking fear among police officers.
Read More: Why BlueLeaks Shatters Internal Security
The leaks were released at hunter.ddosecrets.com and announced on the @DDoSecrets Twitter account. The account was banned shortly after for “dissemination of hacked materials” and for the “information that could have put individuals at risk of real-world harm”. The Wired magazine reported that Distributed Denial of Secrets attempted to remove sensitive information from the data before its publication.
National Fusion Center Association (NFCA) officials confirmed the authenticity of the data, according to documents obtained by security journalist Brian Krebs; the organization warned its members that hackers may use this leaked information to target them. German authorities seized a server used by DDoSecrets at the request of U.S. authorities. The server had hosted the BlueLeaks files, but the documents remained available for downloading through BitTorrent and other websites.
Interested and want to know more about similar hacks on government websites? Follow the blog to get the latest trends in the field of cybersecurity.
Mobile Application Penetration Testing for Qatar Government Digital Services: NCSA- Aligned Security Assurance
Key Takeaways: Mobile Application Penetration Testing Qatar must cover the app, device storage, APIs, authentication and third-party components. Qatar’s NCSA assurance environment combines the National Information Assurance (NIA) Standard, the National Information Security Compliance Framework (NISCF) and accredited security assessment services. OWASP MASVS defines mobile security controls, while MASTG supplies practical test methods for Android […]
Qatar Data Protection Law: Implementing PDPPL Data Subject Rights Processes for Businesses
Key Takeaways: The Qatar Data Protection Law (Law No. 13 of 2016) for Personal Data Privacy Protection, grants individuals specific rights such as right to access, correct, erase, object, withdraw consent, and right to be notified of processing or inaccurate disclosure. Beyond having a privacy policy, businesses or controllers, under Article 11 of Personal Data […]
AI Governance for Indian Enterprises: Building Internal Controls Before Key DPDP Obligations Take Effect
Key Takeaways: The DPDP Act does not contain AI-specific provisions. Its requirements, however, apply in situations when an AI system processes digital personal data within its territorial and material scope. India is working on building a broader governance framework around safety, accountability, transparency and trust via programs like the IndiaAI Mission. Indian organizations should inventory […]
Cloud Security Audit for UAE Government Cloud Migration: NCAP and Security Requirements
Key Takeaways: A cloud security audit UAE helps government entities identify security, governance, configuration, access, data-protection and resilience gaps, before and after shifting critical workloads to the cloud. UAE National Cloud Security Policy has defined cloud governance, data security, data sovereignty, IAM, incident management, resilience, portability and cloud operations requirements. The National Cyber Accreditation Program […]
Data Privacy Consulting UAE – Building a PDPL-Compliant Data Governance Program
Key Takeaways: PDPL compliance requires ongoing operational governance that goes beyond policies to demonstrate how personal data is collected, used, protected, transferred, retained, and deleted. Data mapping helps businesses move from reactive compliance to proactive risk management by establishing a comprehensive inventory of the data ecosystem, helping build a mature data privacy and governance program. […]
Saudi Arabia’s Critical Systems Controls: What CSP-Linked Enterprises Must Comply With in 2026
Key Takeaways: The Critical Systems Cybersecurity Controls (CSCC) are more applicable to critical systems than to all IT assets owned or operated by an organization. To be in full compliance or to remain in full compliance with CSCC, organizations must maintain continuous adherence to NCA ECC. CSCC has 32 core controls and 73 sub-controls across […]