Menu
Browse

Cyber Incident Victim: DXC Technology

Date:

Jul 2020

Location:

United States of America

Summary

A ransomware attack targeted systems operated by Xchanging, a subsidiary of DXC Technology, impacting an undisclosed number of clients across insurance, financial services, and other industries. The incident disrupted client access to their operating environments but was contained within the subsidiary's network without evidence of data compromise or broader infrastructure spread. Remediation efforts restored services for most affected customers, with ongoing work focused on remaining cases. The company engaged law enforcement and authorities in the investigation, maintaining that the attack’s financial impact was not material to its overall position. No ransomware group claimed responsibility or disclosed malware specifics.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 5, 2020, DXC Technology disclosed a ransomware attack targeting systems operated by its subsidiary Xchanging, a managed service provider (MSP) primarily serving insurance industry clients alongside customers in financial services, aerospace and defense, automotive, education, consumer packaged goods, healthcare, and manufacturing sectors. The company detected the intrusion within the Xchanging network and promptly initiated containment procedures, asserting the incident did not propagate beyond Xchanging’s infrastructure. DXC Technology filed an 8-K form with the U.S. Securities and Exchange Commission confirming the attack but reported no evidence of data exfiltration or compromise during preliminary investigations. An unspecified number of customers experienced operational disruption, losing access to their managed service environments. Remediation efforts commenced immediately, with DXC prioritizing service restoration while maintaining that compromised customer data remained secure.

Cyber Incident Image

DXC Technology engaged law enforcement and relevant authorities to investigate the ransomware incident, though no threat actor claimed responsibility and the malware variant remained unidentified. The company’s spokesperson emphasized the attack’s isolation to a limited segment of Xchanging’s operations, noting most affected customers had already regained service access by the time of public disclosure. While DXC characterized the financial impact as immaterial to its overall revenue, it acknowledged the seriousness of the breach and continued restoration work for a small residual group of clients. Internal and external forensic analyses found no indication of data loss or lateral movement beyond Xchanging’s systems, though the exact timeline of initial compromise detection remained undisclosed. Ongoing remediation focused on full operational recovery without disclosing technical specifics of containment measures or ransom demands.

Sources
Sources available to members
1 source