Docker

NJCCIC Data Breach Notification

Original Release Date: 5/6/2019

Summary

Threat actors have gained access to over 190,000 Docker users’ personal data via a single Docker Hub repository. Docker is a platform that enables developers to develop, deliver, and run applications inside containers. Exposed data includes usernames, hashed passwords, and API tokens which were used by developers with GitHub and Bitbucket. API tokens - an authentication token that replaces a username and password - have also been canceled, forcing users to reconnect manually. Docker has stated that they will “enhance the overall security processes and review policies.” The company does not yet offer multi-factor authentication despite users’ suggestions.

Recommendations

The NJCCIC recommends all Docker users change their password and follow recommendations found in the Docker advisory. We also advise those that have an API token to check API logs found on GitHub and BitBucket.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.