Supply chain ⛓ Supply Chain

Police Departments Third-Party Breach (June 2020)

📅 2020-06-01 🏢 NetSentiel
Primary Source ↗

Incident Details

‘BlueLeaks’ Exposes Files from Hundreds of Police Departments. Hundreds of thousands of potentially sensitive files from police departments across the United States were leaked online last week. The collection, dubbed “BlueLeaks” and made searchable via a new website by the same name, stems from a security breach at…. The collection — nearly 270 gigabytes in total — is the latest release from Distributed Denial of Secrets (DDoSecrets), an alternative to Wikileaks that publishes caches of previously secret data. In a post on Twitter , DDoSecrets said the BlueLeaks archive indexes “ten years of data from over 200 police departments, fusion centers and other law enforcement training and support resources,” and that “among the hundreds of thousands of documents are police and FBI reports, bulletins, guides and more.”. Third-party company: NetSentiel.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
NetSentiel
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2020-06-01 Breach occurred
  2. 2020-06-22 Publicly disclosed