Short answer: CISA found no evidence that data was exfiltrated from its Chemical Security Assessment Tool (CSAT), but its investigation could not rule out unauthorized access between January 23 and January 26, 2024. Potentially accessible material included chemical-facility security records, personnel-vetting submissions, and CSAT accounts, including accounts authorized for Chemical-terrorism Vulnerability Information (CVI).
What happened in the CSAT incident?
A malicious actor targeted CSAT from January 23 through January 26, 2024. In a June 20, 2024 notice, the Cybersecurity and Infrastructure Security Agency (CISA) said its investigation found no evidence of data exfiltration. However, CISA said the intrusion may have enabled unauthorized access to records and accounts stored in the system.
That distinction matters: the available notice establishes possible access, not confirmed copying, publication, or removal of the data.
What information may have been accessible?
| Data or account type | Why it is sensitive |
|---|---|
| Top-Screen surveys | Used to assess risks at facilities that possess or use regulated chemicals. |
| Security Vulnerability Assessments | Describe weaknesses and security risks at chemical facilities. |
| Site Security Plans | Contain protective measures and security-planning details for facilities. |
| Personnel Surety Program (PSP) submissions | May contain personally identifiable information used in vetting for terrorist ties. |
| CSAT user accounts | Credentials and account information could provide access to the application or related records. |
| Accounts authorized for CVI | These accounts are associated with Chemical-terrorism Vulnerability Information, a specially protected category of information. |
CISA’s individual notice specifically identified possible access to PSP submissions and accounts for authorized CVI users. The notices do not say that every record in these categories was accessed or that any particular person’s information was definitely taken.
#1 Best Overall
Was chemical-facility data stolen?
There is no confirmed theft in CISA’s public finding. The agency reported no evidence of exfiltration, while acknowledging that unauthorized access may have occurred. Readers should therefore treat this as a potential-access incident rather than a confirmed data-theft event.
The risk is still significant because the potentially reachable material combines facility security information with personnel-vetting data. A security plan or vulnerability assessment could reveal protective arrangements, while a PSP submission can contain personal information used in sensitive screening.
Was your information involved?
CISA notified affected CFATS participants and people whose information had been submitted for vetting. Check notices sent by CISA or your organization’s CFATS/CSAT administrator for a direct determination about your records.
There is no public indication in the available notice that lets an individual determine involvement solely from a public lookup. If you submitted information for PSP vetting or held an authorized CVI account, you were within the groups CISA specifically addressed in its individual notice, but that does not by itself prove your data was accessed.
Rank #3
What CSAT users should do now
- Reset reused passwords. CISA advised CSAT users to change their password on every business or personal account where the CSAT password was reused. Use a unique password for each service.
- Secure related accounts. Turn on multifactor authentication where available, review sign-in history, and revoke unfamiliar sessions or recovery methods.
- Watch for targeted messages. Treat unexpected requests involving chemical facilities, CVI, PSP vetting, password resets, or security plans as possible phishing. Verify through a known CISA or organizational contact route rather than links in the message.
- Follow your organization’s incident process. Facility security officers and administrators should preserve relevant logs, confirm who still has access, and coordinate with their organization’s security and legal teams.
- Use the notice’s identity-protection instructions if applicable. CISA said affected individuals could enroll in identity-protection services through February 2, 2025. That enrollment deadline has passed, and the notice reviewed here does not identify a continuing commercial provider.
Why the expired CFATS program matters
The records were collected under the Chemical Facility Anti-Terrorism Standards (CFATS) framework. CFATS statutory authority expired on July 28, 2023—before the January 2024 intrusion. CISA says it therefore cannot currently enforce CFATS reporting, inspections, or site-security-plan requirements. Voluntary ChemLock assistance remains available.
The lapse does not make the exposed information less sensitive; it changes the legal and operational setting around the system. Facilities may still hold historical plans and vetting submissions even though the federal enforcement program is inactive.
The wider chemical-sector security gap
A Government Accountability Office report published September 8, 2026, estimated that 89 million people lived or worked within two miles of a U.S. facility using high-risk chemicals in 2025, based on a U.S. Department of Homeland Security estimate. GAO also reported that CISA personnel dedicated to chemical-sector activities fell from 214 in fiscal year 2024 to 52 in fiscal year 2025.
GAO said the end of the federal personnel-vetting process removed a critical tool for addressing insider terrorist threats and recommended that CISA develop voluntary vetting options. Those findings provide policy context for the CSAT incident, but they do not establish that the 2024 actor accessed any particular facility or person’s records.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsBest Value
How to interpret the incident
| Question | What the available evidence establishes |
|---|---|
| When did the intrusion occur? | January 23–26, 2024. |
| Was exfiltration confirmed? | No. CISA found no evidence of exfiltration. |
| Could unauthorized access have occurred? | Yes. CISA said it could not rule out potential unauthorized access. |
| Which records were in scope? | Potentially Top-Screen surveys, Security Vulnerability Assessments, Site Security Plans, PSP submissions, CSAT accounts, and authorized CVI accounts. |
| What remediation did CISA announce? | Notifications to affected stakeholders, password-reset advice for reused passwords, and a time-limited identity-protection enrollment opportunity for affected individuals. |
| Was the governing program active? | No. CFATS authority had expired on July 28, 2023. |
Bottom line for affected users
CISA’s statement does not support saying that chemical-facility or personnel-vetting data was stolen. It does support taking the possibility of unauthorized access seriously: change reused passwords, secure related accounts, monitor for phishing, and rely on direct CISA or organizational notifications for confirmation about your records.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

