US Marshals Service hit by ransomware and data breach
The US Marshals Service (USMS) says it's suffered a ransomware attack in which a threat actor managed to get hold of sensitive information about staff and fugitives.
On February 17, 2023, the attacker infiltrated a system that held information about ongoing investigations, including personally identifiable information (PII) of fugitives, staff, and third parties.
As with most ransomware attacks nowadays, the attacker also exfiltrated data before starting the encryption routine. Ransomware gangs threaten to disclose stolen data on so-called leak sites as extra leverage to get a victim to pay the ransom. One of the tasks of the USMS is to assure the safety of endangered government witnesses and their families. Luckily, according to sources, the attackers didn't gain access to any data related to the witness protection program WITSEC.