LockBit claimed DC insurance regulator data taken via Tyler Technologies cloud

Organization
District of Columbia Department of Insurance, Securities and Banking (DISB)
Exploit
Third-Party Data Breach
Industry
Government

On April 13, 2024 the LockBit ransomware operation added the District of Columbia Department of Insurance, Securities and Banking to its leak site, claiming it held 800GB of material relating to the agency, the US Securities and Exchange Commission, Delaware banking institutions and other financial bodies. The gang threatened to publish the files unless it was paid.

DISB said the data had not come from its own systems. In a notice issued on April 18, the agency said it had been alerted by Tyler Technologies, the public sector software supplier that hosts client data for the agency's STAR system, and it directed enquiries to the vendor's incident page.

Tyler Technologies said it had discovered unauthorized activity in an isolated segment of a private cloud hosting environment that stored limited STAR system client data. The company said it took the environment offline and opened an investigation with third-party experts. The Record reported that the access was found in late March 2024.

LockBit subsequently said it would release an initial 1GB and went on to publish some STAR system information, according to The Record. The 800GB figure was the gang's own claim and was not confirmed by either DISB or Tyler Technologies.

Sources