Supply chain
⛓ Supply Chain
Police Departments Third-Party Breach (June 2020)
Primary Source ↗Incident Details
‘BlueLeaks’ Exposes Files from Hundreds of Police Departments. Hundreds of thousands of potentially sensitive files from police departments across the United States were leaked online last week. The collection, dubbed “BlueLeaks” and made searchable via a new website by the same name, stems from a security breach at…. The collection — nearly 270 gigabytes in total — is the latest release from Distributed Denial of Secrets (DDoSecrets), an alternative to Wikileaks that publishes caches of previously secret data. In a post on Twitter , DDoSecrets said the BlueLeaks archive indexes “ten years of data from over 200 police departments, fusion centers and other law enforcement training and support resources,” and that “among the hundreds of thousands of documents are police and FBI reports, bulletins, guides and more.”. Third-party company: NetSentiel.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- NetSentiel
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2020-06-01 Breach occurred
- 2020-06-22 Publicly disclosed