Cyber Incident Victim: New York State
Date:
Jan 2020
Location:
United States of America
Summary
A breach of government computer networks was discovered in late January, involving unauthorized access to multiple servers and encrypted networking appliances used by various state agencies. The intrusion, believed to originate from outside the United States, led to the deployment of security tunnels and a previously unknown backdoor. While no evidence indicated theft or compromise of resident or employee personal data, over 25 servers were compromised, impacting entities including the State Police and departments of Civil Service and Environmental Conservation. Following the discovery, the state engaged a third-party security firm and collaborated with federal investigators, implementing additional security measures and resetting thousands of employee passwords across agencies.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On January 28, 2020, New York's Office of Information Technology Services (ITS) detected an intrusion into state government computer networks. The attackers had established encrypted communication tunnels across multiple servers, enabling covert data transmission. The breach remained undisclosed to the public until April 2020, when state officials confirmed the incident following inquiries from The Wall Street Journal. Senior adviser Richard Azzopardi stated investigators found no evidence that personal information of residents or state employees was exfiltrated or compromised. Initial internal investigations by ITS revealed a previously unknown backdoor several weeks after detection, prompting the engagement of third-party cybersecurity firm CrowdStrike in mid-February to assess the full scope. New York authorities collaborated with the FBI to identify the perpetrators, with sources attributing the attack to foreign actors based on investigative findings.

CrowdStrike's forensic analysis identified more than 25 compromised servers and encrypted networking appliances across multiple state agencies. Affected entities included the New York State Police and the Departments of Civil Service and Environmental Conservation, indicating broad network penetration. In response, ITS implemented enhanced security measures across government systems and mandated password resets for thousands of state agency employees to contain potential credential-based threats. The incident underscored systemic vulnerabilities in New York's infrastructure, though officials maintained operational continuity throughout the remediation. No ransomware deployment or public data exposure was confirmed during the investigation. The state's containment strategy focused on eliminating attacker persistence mechanisms while preserving evidence for the ongoing federal investigation into the breach's origins and perpetrators.
