Supply chain ⛓ Supply Chain

Department of Justice Third-Party Breach (April 2024)

📅 2024-04-01 🏢 Greylock McKinnon Associates
Primary Source ↗

Incident Details

DOJ data on 341,000 people leaked in cyberattack on consulting firm. Medicare and other information belonging to 341,000 people was leaked after a consulting firm working with the Department of Justice was hacked. Greylock McKinnon Associates reported a data breach to regulators in Maine on Friday, telling victims that personal information like Social Security numbers and more were accessed during an incident last May. The company said it provides “litigation support services in civil litigation matters” and said those affected by the breach originally had information obtained by the U.S. Department of Justice “as part of a civil litigation matter.”. Third-party company: Greylock McKinnon Associates.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Greylock McKinnon Associates
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2024-04-01 Breach occurred
  2. 2024-04-08 Publicly disclosed