On 17 February 2023 the US Marshals Service discovered a ransomware intrusion into a standalone system holding law-enforcement sensitive information: personally identifiable information relating to the subjects of investigations, agency employees and third parties. Data was exfiltrated before encryption. Officials designated it a major incident.
The affected system was reported as not connected to a wider federal network and was disconnected, with a Department of Justice forensic investigation following. Reporting indicated that data relating to the witness security programme was not accessed. The service was reported still recovering functionality into May.
The Population Cannot Be Notified
Every breach regime this corpus reads assumes a notifiable individual: someone with an address, who can be written to and told to watch their credit.
A person who is the subject of a fugitive investigation is not that. They will not be written to, they would not receive it, and the organisation has no interest in helping them learn what is known about them. We have recorded populations that cannot act at 22-0903, where the affected people were children, and 22-0118, where they were displaced. This is a third kind: a population the holder cannot notify without defeating its own purpose.
A Targeting List, Read Backwards
The value of investigative records is not fraud. It is knowing who is being looked for, by whom, and on what basis.
That is useful to the subjects, to anyone who would sell it to them, and to anyone wishing to interfere with a case. We filed the same inversion at 23-0808, where a rank-and-surname list was dangerous because of who wanted it, and argues at 22-0118 that harm follows the situation of the person rather than the category of the field.
Standalone Was The Control That Worked
The system’s separation from the wider federal network is reported as having limited the blast radius, and it is the one clearly effective control in this file.
We have recorded the same principle failing at 23-0818b, where a migration merged backup networks into the environment they protected, and holding at 23-0724, where the ministries kept off a shared platform were the ones that escaped. Isolation is unfashionable, expensive to operate and repeatedly the thing that limits the damage.
Compiled from contemporaneous reporting of official statements, listed below. No ransomware operation was identified publicly and none is named. No entry route was published, no figure for affected individuals was released, and no ransom demand or payment is established — which together are why this file is graded medium. The reported non-access of witness security material rests on unnamed sources cited in reporting and is recorded as such. Corrections: corrections@forensicpost.com.