Supply chain
⛓ Supply Chain
Multiple U.S. agencies Third-Party Breach (April 2024)
Primary Source ↗Incident Details
State Department investigating reports of data theft allegedly involving federal tech consulting firm. The U.S. State Department said it is investigating claims that a hacker stole government data from a contractor. On Tuesday, a hacker known as “IntelBroker” claimed to have stolen data related to multiple U.S. agencies including the State Department, Defense Department and National Security Agency. The hacker said they breached Acuity — a Virginia-based technology consulting firm that works with federal agencies. Acuity and several of the agencies named in the cybercriminal’s post did not respond to requests for comment. The Cybersecurity and Infrastructure Security Agency declined to comment. Third-party company: Acuity Consulting.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Acuity Consulting
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2024-04-01 Breach occurred
- 2024-04-03 Publicly disclosed