2023 CDW / CDW-G — LockBit extortion; Sirius Federal support servers; leaked internal exports
Data compromised
Internal HR/finance-style exports described in leak-site summaries—no consumer census in vendor statement excerpts
Technical writeup
LockBit affiliates claimed a nine-figure ransom against CDW after penetrating non-customer-facing infrastructure used to support CDW-G’s U.S. federal subsidiary Sirius Federal, per contemporaneous reporting. CDW publicly characterized the matter as an isolated IT security event segregated from core commercial networks while acknowledging dark-web publication of alleged employee badge, commission, and audit artifacts following failed negotiations. The case illustrates MSP/distributor-class extortion where federal-adjacent back-office systems still carry reputational and personnel PII risks.
Root cause
Crimeware extortion operation against segmented federal-facing support estate (exact CVE chain not detailed in cited press)