ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Hacker selling U.S. Marshals Service data on a Russian-speaking cyber criminal forum

A threat actor has offered to sell data allegedly stolen from U.S. Marshals Service (USMS) servers on a Russian-speaking dark web forum.In February, the U.S. Marshals Service, the oldest US federal law enforcement organisation, suffered a disruptive ransomware attack that compromised some of its most sensitive data, including law enforcement materials, ongoing legal processes, employee personal information, and potential federal investigation targets.According to an agency spokesperson, the ransomware attack, discovered on February 17, impacted a stand-alone system within the service that was not connected to the larger federal network. The spokesperson said that the compromised system contained no information about individuals covered by the Federal Witness Protection Program whose lives could be in danger if made public.USMS disconnected the affected system from its servers and launched an investigation led by the Department of Justice.Drew Wade, the chief of the Marshals Service public affairs office, said, “The affected system contains law enforcement sensitive information, including returns from legal process, administrative information, and personally identifiable information pertaining to subjects of USMS investigations, third parties, and certain USMS employees.”The US Marshals Service did not provide information about whether the attackers threatened to release stolen data if a ransom was not paid or details of how the agency accessed its records in a workaround following the breach. To avoid delaying ongoing casework, it currently uses a workaround to access sensitive files, including details about investigative targets.A threat actor has uploaded a post on a Russian-speaking dark web forum, claiming to be in possession of “350 GB from US Marshal Service (USMS) law enforcement confidential information”.  According to the post, the compromised data dates between 2021 and February 2023 and contains files that are marked as SECRET or TOP SECRET. The hacker is willing to sell the data to anyone paying the quoted price of $150,000.The authenticity of the threat actor’s claims cannot be verified just yet as USMS hasn’t commented on whether the hacker’s claims are genuine or not.

Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543