Supply chain ⛓ Supply Chain

Multiple U.S. agencies Third-Party Breach (April 2024)

📅 2024-04-01 🏢 Acuity Consulting
Primary Source ↗

Incident Details

State Department investigating reports of data theft allegedly involving federal tech consulting firm. The U.S. State Department said it is investigating claims that a hacker stole government data from a contractor. On Tuesday, a hacker known as “IntelBroker” claimed to have stolen data related to multiple U.S. agencies including the State Department, Defense Department and National Security Agency. The hacker said they breached Acuity — a Virginia-based technology consulting firm that works with federal agencies. Acuity and several of the agencies named in the cybercriminal’s post did not respond to requests for comment. The Cybersecurity and Infrastructure Security Agency declined to comment. Third-party company: Acuity Consulting.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Acuity Consulting
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2024-04-01 Breach occurred
  2. 2024-04-03 Publicly disclosed