US federal courts hit by "incredibly significant" cyberattack

Representational image depecting cybersecurity protection
(Image credit: Shutterstock)

A 2020 cyberattack against the US federal court system ended up being far more damaging than initially thought, and has now been labelled, “incredibly significant and sophisticated” by a US congressman.

A hearing at the House Judiciary Committee saw Chairman Jerrold Nadler (D-NY) touch upon a data breach that was first publicly disclosed by the Administrative Office of the Courts, in early January 2021. 

Nadler is now saying that the breach was a lot more impactful.

Impacted cases

"It was only in March of this year the committee first learned of the startling breadth and scope of the court's Document Management System security failure,” Nadler said. “And perhaps even more concerning is the disturbing impact the security breach had on pending civil and criminal litigation, as well as ongoing national security or intelligence matters."

Since then, the incident has had “lingering impacts on the department and other agencies," he added. 

He further asked Justice Department official Matt Olsen about the types of cases, investigations, and attorneys, most impacted by the breach, a question which Olsen couldn’t answer. "This is, of course, a significant concern for us given the nature of information often held by the courts," he said. 

Rep. Sheila Jackson Lee, (D-TX), argued that the findings were a “dangerous set of circumstances,” adding that the Justice Department needs to share more details about the number of cases impacted, and how many of those were dismissed.

While this incident occured at roughly the same time as the notorious SolarWinds attack, the two are apparently unrelated events. 

The SolarWinds attack is generally perceived as one of the most devastating supply chain cyberattacks to ever occur. After investigating the incident, the US government blamed Russian state-sponsored threat actors for the attack. 

The group obtained Microsoft 365 login credentials from some SolarWinds employees through phishing, and used it to taint a patch for one of its products, while in development. The tainted patch was subsequently pushed to hundreds of thousands of endpoints around public and private sectors, infecting government agencies, as well as some of the largest tech companies in the world.

Via: ZDNet

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
An American flag flying outside the US Capitol building against a blue sky
More alleged Chinese intrusions into the US Treasury revealed
China US flags cropped
CISA says ‘no indication’ other US government agencies affected in Treasury hack
An illustration of a silhouetted thief in motion running while carrying a stolen fingerprint
The 5 worst cyberattacks of 2024
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
Salt Typhoon attacks may have hit more US firms than previously thought
A computer being guarded by cybersecurity.
Huge cyberattack found hitting vulnerable Microsoft-signed legacy drivers to get past security
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
Latest in Security
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
These fake GitHub "security alerts" could actually let hackers hijack your account
3d rendering of a submarine power cable on the seabed
Subsea internet cables can now ‘listen’ for sabotage using irregular pulses of light
Dark Web monitoring
A worrying critical security flaw in Apache Tomcat could let hackers take over servers with ease
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
Latest in News
an image of the Samsung Galaxy S24 Ultra
Finally! One UI 7 has a release date - here are the Samsung phones that’ll get it first
Google Cloud logo
Google to acquire cloud security platform Wiz in $32 billion deal
GIMP 3.0 interface from the website
Our favorite free photo editor finally got the update it deserves - and these are the top 5 features designers should know about
FCC filing for the Nothing CMF Buds 2 Plus
Nothing’s next-gen CMF cheap earbuds slated to arrive within the month, but don’t expect hi-res audio support
John Loeffler holding the Ryzen 7 7800X3D
Great news! The best gaming CPU ever made is finally available for it's original MSRP again
Garmin Instinct 3
A new Garmin study hints at the link between burning calories and happiness, and I've got good and bad news