Someone disabled controls to prevent insecure or unauthorized mobile devices from logging on w/o the proper #security settings. There was an interface exposed to the public internet, potentially allowing malicious actors access to #NLRB's systems. Internal alerting & monitoring systems were manually turned off. Multifactor authentication was disabled. And…an unknown user had exported a "user roster," a file w/contact information for outside lawyers who have worked w/the NLRB.