Law & the Courts

Army Launches Criminal Probe into Possible Database Breach

(Photo: Sergeant First Class Mark Bell)

What began as a computer “glitch” has spiraled into a months-long criminal investigation into how a system containing personal information for most of the U.S. Army Reserve was compromised.

The human resources system, known as the Regional Level Application Software (RLAS), unexpectedly went down in December. Publicly, the Army Reserve announced that it was facing “technical issues” and informed reservists that their paychecks would be delayed by over two weeks. Privately, it was rumored that the system had been hacked. An Army Reserve official now confirms that a criminal investigation is underway, and says that no private information was exposed during the incident. Speaking for the unit conducting that investigation, another official won’t reveal much else.


“The cause of the outage is under investigation by Special Agents from the U.S. Army Criminal Investigation Command’s specialized Computer Crime Investigative Unit,” says Christopher Grey, a spokesman for the Army Criminal Investigations Division. “No further information about the ongoing investigation will be released at this time to protect the integrity of the investigative process.”

A breach of the RLAS system could do massive damage. The system is used to store and process everything from reservists’ paychecks to their orders to where they are deployed. “The security of our soldiers’ personal information is a top priority for the Army Reserve,” says Lieutenant colonel Tad Fichtel, an Army Reserve spokesman, in an e-mail. “As such, RLAS is housed on a restricted network that requires users to provide multiple levels of security validation. Additionally, all RLAS operators require access approval by a system administrator.”




Grey refuses to say whether investigators have determined if a U.S. government employee was involved, or even to confirm that the military believes the “technical issues” were caused by a malicious act. “Our main focus is to get to the bottom of what transpired and who was responsible,” he says. “I’m not characterizing it as anything in the media at this point. As soon as we’re able to release anything, we will.”

The system is used to store and process everything from reservists’ paychecks to their orders to where they are deployed.

Federal officials have blamed China and other foreign governments for a variety of hacks in recent years, but the RLAS case appears to be different. “At this point in the investigation, we don’t believe it was caused by any foreign entity,” says Grey.


That doesn’t necessarily mean that the case has no counter-intelligence ramifications. A government contractor can do plenty of damage, as National Security Agency leaker Edward Snowden proved when he stole a wealth of military secrets and fled the country. No such damage appears to have resulted from the RLAS incident, but the “technical issues” that RLAS faces are still serious, according to a senior congressional aide who specializes in cyber-security issues. The case suggests that, “two years after Edward Snowden we still have problems, potentially, with insider threats that we haven’t resolved,” the aide says.

Even without any link to a foreign government, it would be a surprise if the months-long investigation into such an incident did not result in charges. “There’s a zero percent chance that they’re not going to charge somebody,” says a former Army intelligence analyst who also worked as a contractor for the criminal investigations division. “But if no [personal identifiable information] was accessed, then the question is, did somebody just try to take the system offline?”


— Joel Gehrke is a political reporter at National Review.

Exit mobile version