
The US Marshals Service (USMS), the oldest US federal law enforcement organization, is looking into a significant ransomware attack that compromised some of its most sensitive data, including law enforcement materials, ongoing legal processes, employee personal information, and potential federal investigation targets.
According to an agency spokesperson, the attack was discovered on February 17 and impacted a stand-alone system within the service, which is not connected to a larger federal network. The spokesperson claimed that the compromised system contained no information about individuals covered by the Federal Witness Protection Program, whose lives might be in danger if made public.
Shortly after the discovery, the USMS disconnected the affected system and initiated a forensic investigation led by the Department of Justice, which oversees the USMS. The cybercriminals obtained administrative data, personal information of certain employees and about wanted fugitives, as well as information on unidentified third parties. The Department’s remediation efforts and its criminal and forensic investigation are underway. It also works swiftly and effectively to mitigate any potential risks from the incident.
The US Marshals Service did not provide additional information about whether the attackers threatened to release stolen data if a ransom was not paid or details on how the agency accessed its records in a workaround following the breach. To avoid delaying ongoing casework, it currently uses a workaround to access sensitive files, including details about investigative targets. Uncertainty exists regarding whether the Marshals could retrieve the files or use backup copies from another computer system or backup server.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543