U.S. Marshals Service ransomware attack hit a sensitive investigative system

Organization
U.S. Marshals Service
Exploit
Ransomware
Industry
Federal Government

The U.S. Marshals Service discovered a ransomware and data exfiltration event on February 17, 2023 affecting a standalone agency system. The Justice Department designated the breach a major incident on February 22, a classification that obliges federal agencies to notify Congress within seven days.

According to the agency, the compromised system held law enforcement sensitive information, including returns from legal process, administrative records and personally identifiable information relating to subjects of Marshals Service investigations, third parties and certain agency employees. Officials told NBC News that the database supporting the federal witness security program was not among the systems affected.

Marshals Service spokesperson Drew Wade said the agency disconnected the affected system and that the Justice Department opened a forensic investigation. The service set up a workaround so that deputies pursuing fugitives could keep working while the system remained offline.

The agency declined to say how the attackers got in, whether they had been identified, or whether a ransom was demanded or paid. It said remediation work and the criminal and forensic investigations were continuing when the incident became public at the end of February 2023. It was the second significant data incident at the agency in recent years, following a 2020 disclosure involving records on roughly 387,000 prisoners.

Sources