CISA is warning of potential data theft after the Chemical Safety Assessment Tool (CSAT) was breached in January. It was learned that hackers deployed a webshell on Ivanti’s device, potentially exposing sensitive assessments and security plans.
See also: CoinStats: North Korean hackers breached 1,590 crypto wallets

CSAT is a web portal used by facilities to report possession of chemicals that could be used for terrorism, in order to determine if they are considered high-risk facilities. If they are considered high-risk, the tool will ask them to upload a Security Vulnerability Assessment (SVA) and Site Security Plan (SSP) survey, which contains sensitive information about the facility.
In March, The Record first reported that CISA suffered a breach after the agency's Ivanti appliance was exploited, resulting in two systems being taken offline.
Although CISA did not disclose details about the incident, The Record sources said it involved the infrastructure protection gateway (IP) and the chemical safety assessment tool (CSAT).
CISA confirms the breach
CISA has now confirmed that the Ivanti Connect Secure CSAT was compromised on January 23, 2024, allowing a malicious actor to upload a webshell to the device and warns of potential data theft.
Once CISA discovered the breach, it took the device offline to investigate any actions taken by the malicious actor and what data was potentially exposed.
CISA did not disclose which vulnerabilities were exploited, but it does refer to a document about malicious actors exploiting multiple vulnerabilities in Ivanti Connect Secure and Policy Secure Gateway.
See also: Hacker claims to have source code for Apple tools after breach

This document refers to three vulnerabilities tracked as CVE-2023-46805, CVE-2024-21887 , and CVE-2024-21893, all of which were disclosed prior to the CISA breach on January 23, with malicious actors quickly exploiting them. The vulnerability, CVE-2024-21888, was disclosed on January 22, one day before the CISA Ivanti appliance breach.
While CISA says that all data in the CSAT application is encrypted with AES 256 encryption and there is no evidence of CSAT data being stolen, it has decided to alert companies and individuals to exercise extreme caution.
The data that could possibly have been exposed includes research, security vulnerability assessments, website security plans, personnel security program submissions, and CSAT user accounts. These submissions contain extremely sensitive information regarding security posture and the chemical inventory of facilities using the CSAT tool.
CISA says that the CSAT user accounts contained the following information.
- Nicknames
- Place of birth
- Nationality
- Passport number
- Compensation number
- Number A
- Universal login identifier number
- TWIC ID number
See also: CDK Global: Second breach in a few days
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Data theft, such as that alleged against CSAT, is a serious crime that can have far-reaching consequences for individuals and businesses. It involves the illegal acquisition of personal or corporate data by fraudsters, who may use it for a variety of malicious purposes, such as identity theft or financial gain. Data that is often targeted includes social security numbers, banking details, sensitive business information, and passwords. Unfortunately, with the evolving nature of technology and internet usage, the phenomenon of data theft is becoming increasingly complex, requiring increased security measures to protect information.
Source: bleepingcomputer
