The Justice Department has claimed recently, that the threat actors behind SolarWinds cyberattack have managed to hack 27 state attorneys’ offices in the U.S. and gained access to the email accounts of their employees.
The Justice Department has acknowledged that at least 80% of employees of the department who were using Microsoft 365 accounts were compromised in this fresh cyber attack event.
And all these 80% employees mainly belong to the offices located in the:-
- Eastern Districts of New York
- Northern Districts of New York
- Southern Districts of New York
- Western Districts of New York
However, the Office of the Chief Information Officer identified the malicious activity and immediately terminated the method employed by the hackers to gain access to the data of the employees of the department.
Even, the department also notified the federal agencies, Congress, and the public as warranted according to the FISMA protocol.
Moreover, to reinforce homeland flexibility and make more transparency the Justice Department has also provided additional details about the SolarWinds cyberattack that took place in December 2020.
Compromised State Attorney Offices
Here we have mentioned the full list of compromised state attorney offices below:-
- Central District of California
- Northern District of California
- District of Columbia
- Northern District of Florida
- Middle District of Florida
- Southern District of Florida
- Northern District of Georgia
- District of Kansas
- District of Maryland
- District of Montana
- District of Nevada
- District of New Jersey
- Eastern District of New York
- Northern District of New York
- Southern District of New York
- Western District of New York
- Eastern District of North Carolina
- Eastern District of Pennsylvania
- Middle District of Pennsylvania
- Western District of Pennsylvania
- Northern District of Texas
- Southern District of Texas
- Western District of Texas
- District of Vermont
- Eastern District of Virginia
- Western District of Virginia
- Western District of Washington
While the employees whose accounts were breached in this cyber attack are guided by the U.S. Attorneys’ Executive Office.
Apart from this, the security experts have asserted that the threat actors have used other methods along with the SolarWinds breach method to hack the U.S. federal government’s 9 agencies and other 100 private companies.
During that time frame, the security analysts identified that the hacked data includes the following things:-
- All sent emails
- All received emails
- All stored emails
- All email attachments
However, the Justice Department has acknowledged that they are continuing their investigation, and will continue to provide all the necessary guides and mitigations to evade and block such security breaches.