US State Department reportedly hit by serious cyber-attack

Hacker
Image Credit: Geralt / Pixabay (Image credit: Image Credit: Geralt / Pixabay)

The US Department of Defense’s (DoD) Cyber Command has notified Congress that the State Department was hit by a cyber-attack, according to reports -- and security experts told TechRadar Pro that the slow trickle of official information was only making the matter worse.

A series of tweets over the weekend from Fox News White House correspondent Jacqui Heinrich revealed the campaign against the State Department, although it has so far refused to officially comment on the matter.

“The Department takes seriously its responsibility to safeguard its information and continuously takes steps to ensure information is protected. For security reasons, we are not in a position to discuss the nature or scope of any alleged cybersecurity incidents at this time,” a State Department spokesperson told Heinrich. 

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

An anonymous source also told Heinrich that the attack, which supposedly happened a couple of weeks ago, hasn’t had any detrimental impact on the State Department’s ongoing evacuation mission in Afghanistan.

Lack of details don’t help

Security experts TechRadar Pro spoke to weren’t impressed by the department’s stonewalling of information.

“Clarity and transparency are absolutely vital in the aftermath of an attack, but history has shown us that many organizations have attempted to delay or avoid any discussions that may negatively impact them,” said Jake Moore, Cybersecurity Specialist at ESET.

Sam Curry, chief security officer at Cybereason, added that the lack of information about attacks such as these is one of the reasons for the Endpoint Detection and Response (EDR) mandate for the US Federal government agencies in the recent White House Executive Order

“Having a means of finding the attacks, like the one on the State Department as threat actors move in the slow, subtle, stealthy way through networks, is the only option in returning defenders to higher ground above threat actors... Today, it’s not about who we hire or what we buy. It’s about how we adapt and improve every day,” Curry tells TechRadar Pro.

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
An American flag flying outside the US Capitol building against a blue sky
More alleged Chinese intrusions into the US Treasury revealed
China US flags cropped
CISA says ‘no indication’ other US government agencies affected in Treasury hack
US President Donald Trump speaks to the press as he signs an executive order to create a US sovereign wealth fund, in the Oval Office of the White House on February 3, 2025, in Washington, DC.
US set to pause cyber-offensive operations against Russia - but CISA says it won't stop
An American flag flying outside the US Capitol building against a blue sky
US military and defense contractors hit with Infostealer malware
China
US Treasury declares ‘major incident’ after apparent state-sponsored Chinese hack
China
AT&T and Verizon say they're free of Salt Typhoon hacks at last, as further victims identified
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)