Skip to content
safemode.space
All incidents
2020-06-02 (approximate)
ransomware
supply chain

DoppelPaymer ransomware at Digital Management Inc., a former NASA IT contractor, June 2020

Confidence in this reading:
moderate

What happened

On 2 June 2020 the operators of the DoppelPaymer ransomware published a blog post claiming they had breached the network of Digital Management Inc. (DMI), a Maryland company providing managed IT and cyber-security services whose published customer list included NASA. To support the claim they posted twenty archive files on their dark-web leak portal, holding what ZDNet described as everything from HR documents to project plans, with employee details matching public LinkedIn records, and a list of 2,583 servers and workstations they said were part of DMI's internal network and were holding for ransom. NASA stated two days later that it was aware of the report, had coordinated appropriately with law enforcement and its procurement office, and that as of April 2019 the company was no longer performing any contractual services for NASA; a previous $177 million IT support services contract awarded in 2012 had expired in 2018 and been recompeted. DMI stated that on discovering the issue it immediately took all systems offline, engaged third-party security experts, and worked to safely restore systems in a manner that protected the security of information on them. No source reports adversary behaviour directed at any spacecraft, mission ground system, ground station, link or user terminal.

HOLD RECOMMENDED. ONE TECHNIQUE EDGE, AND THIS GLOSS SAID THE RECORD CARRIED NONE FROM 2026-08-05 UNTIL 2026-08-22. It carries EX-0010.01 Ransomware at derived/moderate, whose rationale records that the record "previously carried no edges on the reasoning that no adversary behaviour was directed at a spacecraft, a mission ground system, a ground station, a link or a user terminal, which is the segment restriction the ruling retires". SPARTA's bibliography associates three reconnaissance techniques with this incident; none survives review, and the reason is the same for all three. DoppelPaymer is an extortion operation: it encrypted a contractor's corporate network and published documents to apply pressure. It performed no reconnaissance of a mission, no compromise of a ground system, and no action against a spacecraft. The record's value is as evidence of exposure - a contractor holding NASA project plans and personnel data was breached and that material was published, which is exactly the artefact class SPARTA's reconnaissance techniques describe adversaries seeking - but supplying the input to a technique is not executing it. NASA's statement that DMI had performed no contractual services since April 2019 also removes the live supply-chain path that would be needed for an initial-access mapping. A correction to the secondary literature is recorded here because it is widely repeated: claims that the leaked DMI files included Lockheed Martin equipment designs and SpaceX manufacturing-partner documents belong to a different DoppelPaymer victim, Visser Precision, leaked in March 2020, and are not supported by either source used for this record. SCOPE UNDETERMINED, recorded 2026-08-23. Whether this record belongs in this corpus has not been established. A record is admitted here when a space system, meaning a spacecraft, a mission ground segment, a tracking or command path or a launch system, is in the attack path; the victim being a space-sector organisation is expressly not the test. What the sources establish is that a ransomware operation encrypted a managed IT provider's corporate network and published material taken from it, and that the provider's NASA relationship was already over: NASA's spokesperson is quoted that "As of April 2019, the company identified in the report is no longer performing any contractual services for NASA", and the only NASA scope any source describes is a $177 million IT support services contract for NASA headquarters, awarded in 2012 and expired in 2018. What no cited source establishes is how far the intrusion reached. The primary source says in its own voice that "It is unclear how deep inside DMI's network the DopplePaymer gang made it during their breach, and how many customer networks they managed to breach", and it reads the leaked NASA-related files as suggesting only that DMI's NASA-related infrastructure was reached; the corroborating source likewise records that a number of questions remain about the scope of the breach. The customers those two sources name are the Departments of State, Health and Human Services and Defense, none of them a space organisation, but the same source describes the provider's customer list as including several Fortune 100 companies and many government agencies without enumerating them, so the named list is not the whole of it. That is what leaves the question open rather than closed: the unenumerated part of the path is which customer networks were reached, and an undescribed path is unestablished rather than refuted. A source enumerating the systems reached, or naming a provider-held access route into a spacecraft, a mission ground segment, a tracking or command path, or launch ground support equipment, would settle it one way; a source establishing that the intrusion stayed inside the provider's own corporate estate would settle it the other. The record stays published while the question is open, under decisions entry 189.

Attack vector

Not reported. Neither source describes how DoppelPaymer entered DMI's network; what is reported is the outcome, encryption of hosts and publication of documents for extortion.

Operational impact

None reported at NASA. DMI states it took all systems offline on discovery and worked to restore them. NASA states the company had performed no contractual services for it since April 2019.

Data compromised

Twenty archive files published on the DoppelPaymer leak portal, described by ZDNet as containing HR documents and project plans, with employee details in them matching public LinkedIn records. The group separately published a list of 2,583 servers and workstations it claimed to have encrypted.

Affected segments

supply_chain

Disclosed

2020-06-02

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

  • EX-0010.01Ransomware
    moderate
    derived
    #

    The DoppelPaymer operators posted a list of 2,583 servers and workstations they said were part of DMI's internal network and which they claimed to have encrypted and to be holding for ransom, and DMI states it took all systems offline on discovery and worked to restore them. Ransomware denying an organisation the use of its systems and converting that denial into extortion leverage is EX-0010.01's behaviour. Derived because the encryption is the extortion group's own claim and DMI's statement confirms only the response to it. Recovered per decision 67: this record previously carried no edges on the reasoning that no adversary behaviour was directed at a spacecraft, a mission ground system, a ground station, a link or a user terminal, which is the segment restriction the ruling retires. The five reasoned rejections on this record stand.

    https://www.zdnet.com/article/ransomware-gang-says-it-breached-one-of-nasas-it-contractors/

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • Not SPARTA-cited, and the one that would matter if it held. It does not: IA-0001 is compromise of the supply chain as a path into the mission, and NASA states DMI had performed no contractual services since April 2019. There was no path.

  • HR documents and project plans belonging to a contractor are not the mission data IMP-0006 is about. The same distinction is applied on mckinnon-nasa-dod-intrusions-2001-2002 and noaa-nesdis-intrusion-2014.

  • Cited by SPARTA. No source says the archives contained avionics architecture, interface control documents, block diagrams, SBOMs or any other design artefact. ZDNet, which viewed them, says HR documents and project plans.

  • Cited by SPARTA. The technique is an adversary mapping manufacturers, lots, logistics routes, integrator touchpoints and custody handoffs to find where trust can be abused. DoppelPaymer mapped nothing; it encrypted a corporate network and published what it found. The incident created supply-chain artefacts for others; it did not gather them.

  • Cited by SPARTA. Project plans were published. REC-0009 is the compilation of a CONOPS-level portrait, duty cycles, mode logic, pointing and thermal constraints, contingency concepts, to predict a mission's rhythms. No source characterises the published documents that way, and "project plans" in a managed-IT contractor's file share is not evidence that they were.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

  • ZDNet · Catalin Cimpanu · 2020-06-02

    Tier 2: Named reporting by a security journalist who viewed the leak portal and the published archives directly, rather than reporting on someone else's account of them. Trade press, so Tier 2.

  • FCW (Nextgov/FCW, GovExec) · Derek B. Johnson · 2020-06-04

    Tier 2: Named federal-technology trade reporting carrying on-the-record statements from both the customer agency and the victim company. The statements inside it are first-party; the article is trade press.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.