‘Several’ U.S. agencies have been hacked as part of a broader cyberattack that has hit dozens of companies and organizations in recent weeks through a previously unknown vulnerability in popular file sharing software.

The Cybersecurity and Infrastructure Security Agency, the country’s top civilian cybersecurity agency, said Thursday that it is still investigating the scope of the hacks, said Eric Goldstein, the agency’s executive assistant director.

“CISA is providing support to several federal agencies that have experienced intrusions,” Goldstein said. “We are working urgently to understand impacts and ensure timely remediation.”

The hackers exploited a vulnerability in a program called MOVEIt, a popular tool for quickly transferring files.

Charles Carmakal, the chief technology officer of Mandiant, a cybersecurity company owned by Google whose clients include government agencies, said that he was aware of some data theft from federal agencies through the MOVEIt hacks.

It wasn’t immediately clear if the stolen files were sensitive or if the hackers had disrupted government systems

In an interview with NBC News’ Andrea Mitchell on Thursday, CISA Director Jen Easterly said the agency was tracking the hackers “as a well-known ransomware group.”

That appeared to be a reference to an established cybercriminal group called CL0P. 

Last week, CISA and the FBI issued a warning that CL0P was exploiting a previously unknown vulnerability in MOVEIt. In a rapid hacking spree, the group used that flaw to steal files from at least 47 organizations and demand payment to not publish them on their website, said Brett Callow, an analyst at the cybersecurity company Emsisoft.

The Office of the Director of National Intelligence declined to comment. The National Security Council didn’t immediately respond to a request for comment.

Wendi Whitmore, who leads threat analysis for the cybersecurity company Palo Alto Networks, said that CL0P’s campaign of hacking victims through MOVEIt was incredibly widespread.

“I think it’s at least hundreds, if not more,” of total victims, she said.

This is a developing story. Please check back for updates.

Owen Hayes and Dan De Luce contributed.

Source: | This article originally belongs to Nbcnews.com

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Migrants arrive in D.C. on buses sent by GOP Texas Gov. Greg Abbott

WASHINGTON — A group of undocumented migrants arrived in the nation’s capital…

Biden hosts Schumer, Manchin in Delaware as Congress inches towards a spending deal

WASHINGTON — President Joe Biden will host Senate Majority Leader Chuck Schumer…

Washington town hosts large anti-mask rally

Hundreds of people came to the city of Mossyrock, Washington last weekend…

Equinox launches $40,000 membership to help you live longer

High-end fitness chain Equinox is launching one of the most expensive gym…