Leidos internal documents leaked online after third-party vendor breach
- Organization
- Leidos Holdings
- Exploit
- Third-Party Data Breach
- Industry
- IT Services
Internal documents belonging to Leidos Holdings, one of the largest IT services contractors to the US government, appeared online in July 2024. Bloomberg reported the leak on July 23, 2024, and other outlets followed the next day. Leidos holds contracts with the Department of Defense, the Department of Homeland Security and NASA, which drew attention to the disclosure.
The material was described as roughly a gigabyte of files in formats including PDF, Word, Excel, image and email archives. The Register reported that the contents were largely internal corporate records: notes and files gathered during internal investigations, along with employee reviews and complaints, rather than classified or militarily sensitive information.
Leidos said the data stemmed from an earlier incident affecting a third-party vendor for which all necessary notifications had been made in 2023, and that the leak did not affect its own network or any sensitive customer data. Reporting linked the source to Diligent Corporation, a governance and compliance software provider whose systems Leidos used to store internal investigation material. The underlying compromise involved Steele Compliance Solutions, a business Diligent acquired in 2021. SiliconANGLE reported that unauthorized access to the Steele network began on May 21, 2022, was detected on May 23 and was contained on May 24.
As of the reporting date Leidos said it was reviewing the matter with outside cybersecurity specialists and law enforcement. The 2024 leak therefore represented publication of records taken more than two years earlier rather than a fresh intrusion.