Ion wasn’t deemed a ‘critical’ vendor by most clients

Software firm escaped heavy scrutiny ahead of cyber attack, says US Treasury official

Cyber crime

Ion Group, which suffered a ransomware attack on January 31 that disabled some of its services and initially raised systemic fears, was not classified as a critical third-party vendor by many of its clients, according to a US Treasury official.

“Many firms that were onboarded [by] Ion didn’t use the highest level of scrutiny that they use for their most critical third-party vendors,” said Todd Conklin, deputy assistant secretary in the US Treasury department’s Office of Cybersecurity and

Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.

To access these options, along with all other subscription benefits, please contact or view our subscription options here:

You are currently unable to copy this content. Please contact to find out more.

Sorry, our subscription options are not loading right now

Please try again later. Get in touch with our customer services team if this issue persists.

New to View our subscription options


Want to know what’s included in our free membership? Click here

This address will be used to create your account

You need to sign in to use this feature. If you don’t have a account, please register for a trial.

Sign in
You are currently on corporate access.

To use this feature you will need an individual account. If you have one already please sign in.

Sign in.

Alternatively you can request an individual account here