Entrust, an ID management company used by the US Treasury, DHS, and others, confirms a ransomware gang breached its network in June 2022 and stole internal data
Lawrence Abrams / BleepingComputer :
Context & Ripple Effects
Entrust sits in an uncomfortable position for a security vendor: it sells identity and certificate services to agencies including the US Treasury and DHS, and it has now confirmed that a June ransomware intrusion reached its own network and exfiltrated internal data. The Treasury angle has history — sources reported in late 2020 that state-sponsored hackers were monitoring internal Treasury emails, so this is a repeat exposure of the same customer base through a different vector.
The breach also set up an unusual public fight with the attacker: within a month of Entrust's confirmation, LockBit claimed responsibility for the intrusion, and its leak sites were then knocked offline by a DDoS attack the gang blamed on Entrust.
First-order effects
- Government customers like the US Treasury and DHS must now assume Entrust's stolen internal data could expose the trust relationships those agencies depend on, turning a vendor incident into a direct audit problem for their own credential chains.
- LockBit's claim of responsibility puts Entrust under active extortion pressure, with publication of the stolen data as the lever.
Second-order effects
- The DDoS attack on LockBit's leak sites shows the dispute escalating beyond a standard extortion negotiation — attribution and retaliation between victim and gang became part of the story itself.
- Rival identity and PKI vendors now face procurement scrutiny where their own breach history is a selling point, since Entrust's customers just learned the trust provider is itself a target.
Third-order effects
- The pattern across this coverage — Entrust, Infosys McCamish's LockBit theft of data on 6M+ people, and Ascension's employee-file-driven ransomware incident — points to attackers systematically prioritizing intermediaries whose compromise cascades to many downstream organizations at once.
- If service-provider breaches keep cascading into client networks, government and enterprise buyers will increasingly treat vendor security posture as a hard procurement gate rather than a checkbox, reshaping how identity and IT outsourcing contracts are awarded.
The trend: Ransomware operators are shifting up the supply chain from individual victims to the identity and service providers that hold trusted access to many organizations simultaneously.