Supply chain β›“ Supply Chain

U.S. Government Third-Party Breach (May 2021)

πŸ“… 2021-05-01 🏒 BlueForce
Primary Source β†—

Incident Details

US defense contractor BlueForce apparently hit by ransomware | TechTarget. A Virginia-based U.S. defense contractor has apparently been hit by ransomware, according to a ransomware negotiation chat and Hatching Triage page. U.S. defense contractor BlueForce has apparently been hit in a ransomware attack, according to a Conti ransomware chat and Hatching Triage sample. The Hatching Triage page for the ransomware sample included a ransom note claiming to be from a threat actor who infected the victim with the Conti ransomware strain . The sample was shared with SearchSecurity by TechTarget sister site LeMagIT. Third-party company: BlueForce.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
BlueForce
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2021-05-01 Breach occurred
  2. 2021-05-06 Publicly disclosed