Supply chain β›“ Supply Chain

D.C. Department of Insurance, Securities and Banking (DISB) Third-Party Breach (April 2024)

πŸ“… 2024-04-01 🏒 Tyler Technologies
Primary Source β†—

Incident Details

DC city agency says LockBit claims tied to third-party attack. The Department of Insurance, Securities and Banking (DISB) said the ransomware gang stole data from a contractor, Tyler Technologies. A Washington, D.C., government agency confirmed that data stolen and leaked by the LockBit ransomware gang was taken from a third-party technology provider. On April 13, the LockBit ransomware gang claimed it attacked the D.C. Department of Insurance, Securities and Banking (DISB) and stole 800GB of data. DISB is a regulatory agency designed to protect consumers from abuses by financial institutions like insurance companies, investment firms, banks and mortgage lenders. Third-party company: Tyler Technologies.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Tyler Technologies
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-04-01 Breach occurred
  2. 2024-04-19 Publicly disclosed