USDA said fewer than 30 employees may have been hit by a vendor's MOVEit breach

Organization
U.S. Department of Agriculture
Exploit
Third-Party Data Breach
Industry
Federal Government

The U.S. Department of Agriculture was drawn into the MOVEit Transfer compromise in June 2023, after the Clop group exploited a zero-day flaw in the Progress Software product to steal data from organizations worldwide.

USDA initially said it was aware of a possible data breach at a vendor that might affect a very small number of employees. It subsequently stated that no breach had occurred on the USDA network itself, and estimated that fewer than 30 USDA employees may have been affected through the third party's breach.

The Cybersecurity and Infrastructure Security Agency said several federal agencies had been compromised. CISA director Jen Easterly described the campaign as largely opportunistic and said officials were not aware of Clop threatening to extort or release data taken from U.S. government agencies.

The Department of Energy confirmed that records from two of its entities were involved, Oak Ridge Associated Universities and the Waste Isolation Pilot Plant in New Mexico. A department spokesperson said neither entity engaged with the gang. CNN reported that the Office of Personnel Management was also investigating a possible compromise. At state level, Colorado's Department of Health Care Policy and Financing and the Maryland Department of Human Services said they had been affected.

The State Department offered a reward of up to 10 million dollars for information connecting the attackers to a foreign government.

Sources