Supply chain
⛓ Supply Chain
Department of Justice Third-Party Breach (April 2024)
Primary Source ↗Incident Details
DOJ data on 341,000 people leaked in cyberattack on consulting firm. Medicare and other information belonging to 341,000 people was leaked after a consulting firm working with the Department of Justice was hacked. Greylock McKinnon Associates reported a data breach to regulators in Maine on Friday, telling victims that personal information like Social Security numbers and more were accessed during an incident last May. The company said it provides “litigation support services in civil litigation matters” and said those affected by the breach originally had information obtained by the U.S. Department of Justice “as part of a civil litigation matter.”. Third-party company: Greylock McKinnon Associates.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Greylock McKinnon Associates
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2024-04-01 Breach occurred
- 2024-04-08 Publicly disclosed