ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

NSC data breach exposes credentials of NASA, Tesla, DOJ, Verizon, and 2K others

The National Safety Council (NSC), a non-profit organization focused on workplace and driving safety training in the United States, has inadvertently exposed the sensitive credentials of thousands of its members, including prestigious entities like NASA, Tesla, the Department of Justice (DoJ), Verizon, and many more.

 

The NSC, boasting a membership of nearly 55,000 individuals spanning diverse industries, serves as a hub for online resources and training materials. The organization’s digital platform fell victim to a critical vulnerability that went undetected for five months.

 

Cybersecurity research team Cybernews unearthed this security lapse when they stumbled upon publicly accessible web directories on the NSC website, unwittingly exposing thousands of credentials.

 

Among the extensive list of compromised accounts were employees representing over 2,000 companies and government entities, representing a broad spectrum of industries:

 

  • Fossil Fuel Giants: Shell, BP, Exxon, Chevron
  • Electronics Manufacturers: Siemens, Intel, HP, Dell, IBM, AMD
  • Aerospace Companies: Boeing, Federal Aviation Administration (FAA)
  • Pharmaceutical Companies: Pfizer, Eli Lilly
  • Car Manufacturers: Ford, Toyota, Volkswagen, General Motors, Rolls Royce, Tesla
  • Governmental Entities: Department of Justice (DoJ), US Navy, FBI, Pentagon, NASA, The Occupational Safety and Health Administration (OSHA)
  • Internet Service Providers: Verizon, Cingular, Vodafone, AT&T, Sprint, Comcast
  • Other Corporations: Amazon, Home Depot, Honeywell, Coca-Cola, UPS

 

These organizations seemingly held accounts on the NSC platform to access training materials and participate in NSC-sponsored events.

 

The consequences of this breach extended beyond the NSC itself, as the exposed credentials could have been exploited in various malicious ways. Threats such as credential stuffing attacks targeting internet-connected tools like VPN portals, HR management platforms, or corporate email systems were among the primary concerns. The leaked credentials might have also served as a gateway for cybercriminals to infiltrate corporate networks, potentially deploying ransomware, pilfering or sabotaging internal documents, or compromising user data.

 

Upon discovering this vulnerability on March 7, Cybernews promptly notified the NSC, which took immediate corrective action to rectify the issue. The security lapse was traced to a subdomain on the NSC website, presumably employed for developmental purposes, inadvertently left open to public access. This subdomain exposed critical web server files and, shockingly, a backup of a database housing user emails and hashed passwords. The data had been accessible to the public for five months, initially indexed by IoT search engines on January 31, 2023.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543