Tag / 12 entries / page 1 of 2 / feed available

State-Sponsored Attack

12 of the 76 analyses in Data Breaches carry this tag. All 12 are scored against the four invariants; the matrix below is that evidence.

How this tag scores against the four invariants

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

071

U.S. Department of the Treasury BeyondTrust Breach December 2024

A China state-sponsored APT (later attributed to Silk Typhoon) compromised a stolen BeyondTrust Remote Support SaaS API key, using it to reset local application account passwords and remotely access U.S. Treasury Department workstations and unclassified documents. The intrusion, detected by BeyondTrust on December 2, 2024 and disclosed to Congress on December 30, 2024 as a major cybersecurity incident, reached the Office of Foreign Assets Control, the Committee on Foreign Investment in the United States, the Office of Financial Research, and reportedly the Office of the Treasury Secretary. The attack exploited a critical unauthenticated command/argument-injection flaw (CVE-2024-12356, CVSS 9.8) and a second lower-severity flaw (CVE-2024-12686); OFAC later sanctioned contractor Yin Kecheng for his role in the compromise.

070

Salt Typhoon Intrusions into U.S. Telecommunications Carriers (2024)

Prevented by: PEC, EGR

The China-linked Salt Typhoon cyber-espionage campaign compromised at least eight U.S. telecommunications providers, with a ninth operator subsequently identified, and affected providers in more than 20 other countries. Attackers accessed carrier infrastructure and surveillance-adjacent systems and collected customer call data, metadata, law-enforcement surveillance-request data, and selected private communications involving government and politically prominent individuals. The campaign exploited exposed and vulnerable network devices, compromised credentials, and trusted provider relationships; officials and congressional testimony reported that more than one million users may have been affected.

067

Army National Guard Salt Typhoon Network Compromise (March–December 2024)

Prevented by: EGR · Contained by: HSF

A PRC-associated Salt Typhoon actor extensively compromised the Army National Guard network of an unidentified U.S. state from March through December 2024. The actor reportedly accessed or exfiltrated administrator credentials, network configurations and diagrams, a geographic map, and service-member personally identifiable information, while collecting configuration and traffic involving Guard networks in every other state and at least four territories. NJCCIC reported entry through a weakly configured remote-access service, followed by lateral spread and control of several privileged accounts, although the complete attack chain was not publicly established.

054

Microsoft Email Accounts Security Breach

In May 2023, Microsoft suffered a data breach conducted by China-based hackers, Storm-0558, who used forged authentication tokens to access customer email accounts. This breach impacted governmental entities, resulting in the unauthorized access and potential exfiltration of approximately 60,000 unclassified emails, emphasizing the breach’s serious national security implications.

035

Microsoft Exchange Server Breach

Prevented by: PEC, EGR

In January 2021, over 30,000 U.S. companies experienced a cyberattack on Microsoft Exchange email servers. The breach exploited several zero-day vulnerabilities, resulting in unauthorized email access and potentially sensitive data exposure. The attack was primarily attributed to the state-sponsored Hafnium group from China, leveraging server-side request forgery and other sophisticated methods.

031

SolarWinds Supply Chain Attack

Prevented by: PEC, EGR

The SolarWinds Supply Chain Attack involved the compromise of SolarWinds Orion software, leading to malicious updates that were installed by over 18,000 customers. This allowed the attackers, attributed to state-sponsored groups, to steal data and spy on organizations including U.S. government departments. The attack exploited software development vulnerabilities to insert SUNBURST malware, affecting multiple sectors globally.

026

Marriott International Data Breach of 2018

Prevented by: HSF, PEC, EGR

In 2018, Marriott International experienced a data breach affecting approximately 500 million guests with compromised personal information including names, addresses, and passport numbers. The breach, linked to the Starwood reservation system acquired by Marriott, involved unauthorized access dating back to 2014, facilitated by malware known as remote access trojans (RATs). The incident raised concerns about potential involvement of state-sponsored actors and resulted in significant regulatory scrutiny, including fines under GDPR.

022

NotPetya Ransomware Attack

Prevented by: PEC

The NotPetya ransomware attack in June 2017 caused extensive financial damage exceeding $10 billion by utilizing a compromised software update from MeDoc, a Ukrainian accounting software. The malware employed the EternalBlue exploit to propagate widely, primarily acting as a wiper rather than traditional ransomware. It severely disrupted corporate operations globally, affecting numerous high-profile organizations such as Maersk and FedEx, and has been attributed to state-sponsored actors linked to Russian military intelligence.

018

Office of Personnel Management Data Breach 2015

Prevented by: HSF, EGR

In 2015, the Office of Personnel Management (OPM) suffered a major data breach that exposed personal information, including Social Security Numbers and biometric data of approximately 21.5 million individuals. The breach involved sophisticated data exfiltration methods believed to be executed by state-sponsored actors, specifically linked to Chinese hackers. Vulnerabilities in OPM’s legacy systems, coupled with compromised contractor credentials, allowed attackers unauthorized access to sensitive data.

017

Anthem Data Breach Incident Analysis

Prevented by: PEC, EGR · Contained by: HSF

The Anthem Data Breach in 2015 exposed approximately 78.8 million records, including sensitive Personal Identifiable Information (PII) such as names, birthdates, medical IDs, and Social Security numbers. The breach was executed via a phishing campaign linked to a state-sponsored group, reportedly associated with Chinese cyberespionage activities. The attackers utilized sophisticated malware including Mivast and Sakula to infiltrate the network and execute data exfiltration without detection.

RSS feed for this tag →

Now playing Bandcamp