Policy & Regulation
Supreme Court hacker also breached AmeriCorps and Veterans Affairs
Nicholas Moore, 24, pleaded guilty to hacking the U.S. Supreme Court, AmeriCorps, and the Department of Veterans Affairs, posting stolen government data on Instagram.
Last week, Nicholas Moore, a 24-year-old resident of Springfield, Tennessee, pleaded guilty to repeatedly hacking into the U.S. Supreme Court’s electronic document filing system. While the initial guilty plea lacked specific details regarding the cybercrimes, a newly filed court document revealed on Friday that Moore’s unauthorized access extended to other federal networks. According to the court document, which was first spotted by Seamus Hughes of Court Watch, Moore also hacked into the networks of AmeriCorps—a U.S. government agency that runs stipend volunteer programs—and the Department of Veterans Affairs, which provides healthcare and welfare to military veterans.
The court filing states that Moore, acting as a hacker, gained entry to these systems by using stolen credentials belonging to authorized users. Once he successfully accessed the victims’ accounts, Moore stole their personal data and posted some of the stolen government data online to his Instagram account, which operated under the handle @ihackthegovernment. The compromised information varied across the targeted agencies. For instance, in the case of a Supreme Court victim identified in the document as GS, Moore posted the individual’s name alongside their current and past electronic filing records.
The exposure of personal data was even more extensive for victims at the other compromised agencies. For an AmeriCorps victim identified as SM, Moore boasted of his access to the organization’s servers and published the victim’s name, date of birth, email address, home address, phone number, citizenship status, veteran status, service history, and the last four digits of their Social Security number. Additionally, Moore targeted a victim at the Department of Veterans Affairs, identified as HW. In this instance, Moore shared HW’s identifiable health information by sending an associate a screenshot from HW’s MyHealtheVet account—the agency’s online personal health record system—which identified HW and showed his prescribed medications.
Following his guilty plea, Moore faces federal penalties for the breaches. According to the court document, he faces a maximum sentence of one year in prison and a maximum fine of $100,000.
Why it matters
This case underscores the vulnerability of government digital infrastructure to credential-based attacks, where a single breach can cascade across multiple agencies and expose sensitive personal information.