Investigation launched after theft of government data — leak hits US State Department

Digital US flag
(Image credit: Shutterstock)

Data relating to the US government has been stolen from a contractor and leaked online, prompting the State Department to launch an investigation.

The threat actor stole and leaked documents from tech consulting firm Acuity, which specializes in cybersecurity, DevSecOps, data analytics and operations support services.

The data allegedly contains a significant amount of personal information relating to the Five Eyes intelligence alliance, according to the threat actor who supposedly conducted the theft known as IntelBroker.

Five Eyes data stolen from right under their nose

The Five Eyes intelligence organization is composed of intelligence organizations from the US, UK, Canada, New Zealand, and Australia, which shares intelligence on state and state-sponsored espionage and cyber incidents.

IntelBroker says that the data contained within the confidential files includes full names, email addresses, office numbers and cell phone numbers of US officials in the Pentagon, military and government.

Speaking in the aftermath of the leak, a State Department spokesperson told BleepingComputer, “The Department is aware of claims that a cyber incident has occurred and is currently investigating. The Department takes seriously its responsibility to safeguard its information and continuously takes steps to improve the Department's cybersecurity posture. For security reasons, we will not provide details on the nature and scope of the claim.”

IntelBroker has gained a reputation for stealing sensitive information from US government agencies, including data on healthcare plans from DC Health Link for US House members alongside roughly 170,000 people, and information from the US Immigration and Customs Enforcement (ICE), and the US Citizenship and Immigration Services (USCIS).

IntelBroker is also responsible for stealing hundreds of thousands of Facebook marketplace accounts, alongside alleged DARPA-related military information, files, SQL files, and documents from US military contractor General Electric.

More from TechRadar Pro

Benedict Collins
Staff Writer (Security)

Benedict has been writing about security issues for over 7 years, first focusing on geopolitics and international relations while at the University of Buckingham. During this time he studied BA Politics with Journalism, for which he received a second-class honours (upper division), then continuing his studies at a postgraduate level, achieving a distinction in MA Security, Intelligence and Diplomacy. Upon joining TechRadar Pro as a Staff Writer, Benedict transitioned his focus towards cybersecurity, exploring state-sponsored threat actors, malware, social engineering, and national security. Benedict is also an expert on B2B security products, including firewalls, antivirus, endpoint security, and password management.

Read more
An American flag flying outside the US Capitol building against a blue sky
US military and defense contractors hit with Infostealer malware
An American flag flying outside the US Capitol building against a blue sky
More alleged Chinese intrusions into the US Treasury revealed
China
US Treasury declares ‘major incident’ after apparent state-sponsored Chinese hack
China US flags cropped
CISA says ‘no indication’ other US government agencies affected in Treasury hack
China
US Government officials urged to lock down devices amid telecoms breach
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Latest in Pro
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
European Union technical background
EU tech companies push for digital sovereignty, reducing reliance on US and others
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
3D version of the Adobe logo
Adobe Summit 2025 - all the news and updates as it happens
Latest in News
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
Nintendo Switch 2
Nintendo Switch 2 expected to have AI upscaling and I can't wait to finally play Tears of the Kingdom with upgraded graphics
PowerColor Red Devil AMD RX 9070 XT graphics card shown side-on
Your next GPU could be from AMD, not Nvidia, if Team Red’s success with PC gamers continues
Intel Lunar Lake concept
Intel's Panther Lake processors won't arrive until Q1 2026 - corroborates previous delay rumors despite former Intel CEO's promise of 2025 launch