Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
GRU’s BlueDelta Targets Energy and Research: Advanced Credential Phishing in 2025
Between February and September 2025, the Russian state-sponsored threat group BlueDelta (APT28/GRU) conducted a series of targeted credential-harvesting attacks, focusing on organizations in Türkiye, Europe, North Macedonia, and Uzbekistan. The attackers deployed sophisticated phishing lures themed as Microsoft Outlook Web Access, Google, and Sophos VPN portals, abusing free hosting and tunneling services such as Webhook.site and ngrok to capture credentials and exfiltrate data. Victims were redirected through multi-stage phishing chains, and legitimate PDF documents were used to enhance believability and evade detection, ultimately supporting Russian intelligence collection. This incident underlines the evolution of state-sponsored phishing techniques, including automation for credential exfiltration and the increasing abuse of legitimate internet infrastructure. The campaign’s focus on energy and defense sectors reflects heightened geopolitical interest and reinforces the urgent need for robust email and identity security practices across sensitive organizations.
8 months ago
Kill Chain
CISA Flags New Code Injection Threats in 2026: HPE OneView & Microsoft Office Under Attack
On January 7, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation of two critical code injection vulnerabilities: CVE-2009-0556 in Microsoft Office PowerPoint and CVE-2025-37164 affecting HPE OneView. Attackers leveraged these vulnerabilities to gain unauthorized code execution, potentially enabling lateral movement and data compromise within federal and enterprise environments. The exploitation highlighted weaknesses in outdated software and emphasized the urgency for immediate remediation to safeguard sensitive systems and data across government agencies and broader sectors. The rapid addition of these vulnerabilities to CISA's KEV Catalog reflects a broader industry trend of threat actors targeting lingering, unpatched software with advanced code injection techniques. Increasing regulatory pressure and new threat intelligence underscore the need for timely vulnerability management as attackers adapt to bypass existing defenses.
8 months ago
Kill Chain
How NoName057(16) Used DDoSia to Drive Hacktivist DDoS Attacks in 2024
In early 2024, the pro-Russian hacktivist group NoName057(16) leveraged their custom DDoS tool, DDoSia, to orchestrate large-scale distributed denial-of-service attacks targeting government, media, and institutional websites in Ukraine and Western countries. By mobilizing a network of volunteer participants through its affiliate model, NoName057(16) was able to coordinate and intensify attacks, resulting in substantial website downtime and service disruptions for organizations with links to Ukraine and the West. The campaign highlighted the effectiveness of modern hacktivist crowd-sourcing tactics and the increasing difficulty of defending against well-organized, politically motivated DDoS operations. This incident is particularly relevant in 2024 as DDoS-as-a-service tools and volunteer-driven hacktivist campaigns are on the rise, blurring the lines between state-driven threats and amateur activism. Organizations should review their DDoS mitigation and incident response defenses amid heightened geopolitical tensions and expanding threat capabilities among hacktivist collectives.
8 months ago
Kill Chain
How the 2020 Venezuelan Power Grid Cyberattack Set a New Precedent for Nation-State Warfare
In May 2020, Venezuela experienced a significant power grid disruption that coincided with an alleged US-backed military incursion. Intelligence sources and public statements, including hints from President Trump, suggested that nation-state cyber actors played a role in disabling critical infrastructure, likely by targeting unencrypted or poorly segmented network traffic in Caracas. The incident demonstrated the attackers’ use of advanced cyber capabilities to disrupt the nation's power supply, contributing to confusion and vulnerability during a period of political unrest. While the precise techniques remain classified, the attack highlighted significant weaknesses in Venezuela’s critical industrial control systems and network segmentation. The relevance of this event endures as cyber operations against power grids and critical infrastructure grow more sophisticated and frequent globally. Recent years have seen a surge in state-sponsored attacks leveraging both advanced persistent threats and rapid lateral movement, making robust east-west security, zero trust practices, and encrypted traffic defenses urgent imperatives for organizations.
8 months ago
Kill Chain
State-Sponsored Cyberattack: US Targets Venezuelan Power Grid (2019)
In March 2019, a significant power outage crippled Venezuela’s capital, Caracas, and other major cities, reportedly as part of a broader campaign by the United States involving offensive cyber operations. Although official attribution remains classified, senior U.S. officials and President Trump openly hinted at the use of advanced cyberattacks to disrupt Venezuela’s electrical grid during a period of heightened political instability and efforts to capture President Nicolás Maduro. This unprecedented event marked a rare instance of publicized state-sponsored cyber warfare, raising concerns about the direct targeting of national critical infrastructure and its immediate social, political, and economic impact. This incident highlights a growing trend of nations turning to cyber operations as a tool for geopolitical leverage, targeting vital systems with the intent to destabilize adversaries. The weaponization of cyber capabilities against critical infrastructure sets a precedent for both escalation and regulatory scrutiny worldwide.
8 months ago
Kill Chain
Generative AI Supercharges Active Directory Credential Attacks in 2026
In early 2026, organizations relying on Microsoft Active Directory experienced a significant increase in successful identity attacks fueled by generative AI technology. Threat actors leveraged AI-powered password cracking tools, such as PassGAN, capable of predicting and cracking user passwords with unprecedented speed, particularly by exploiting patterns present in common password creation habits. These attackers combined automated reconnaissance—scraping public data with large language models—to generate highly targeted guesses, accelerating credential compromise, and enabling lateral movement within corporate networks. Weak password policies, reliance on basic MFA, and the wide availability of cost-effective GPU resources contributed to the scale and efficiency of these breaches. This incident highlights the urgent need for organizations to address evolving attack methodologies, as generative AI lowers the technical barrier for credential-focused attacks and shortens breach timetables. The cybersecurity landscape is rapidly shifting towards identity-driven threats facilitated by AI, demanding stronger, adaptive protections to prevent widespread compromise.
8 months ago
Kill Chain
Ransomware at Sedgwick Government Solutions: What the 2026 TridentLocker Breach Reveals
In January 2026, Sedgwick confirmed a security incident at its subsidiary, Sedgwick Government Solutions, a contractor serving over 20 U.S. federal agencies including CISA, DHS, and the U.S. Coast Guard. The breach was perpetrated by the TridentLocker ransomware group, which claimed to have stolen 3.39 GB of sensitive documents and subsequently leaked data on its Tor site. The attackers gained access via an isolated file transfer system; however, Sedgwick asserts no evidence of compromise to core claims servers or operational disruption. External cybersecurity experts and law enforcement were immediately engaged, and affected systems were properly segmented from the wider parent company network. This incident highlights the increased targeting of government contractors by ransomware operators and underscores the importance of network segmentation, prompt incident response, and continuous monitoring. The breach reflects growing regulatory and client demands for transparent reporting and robust data protection as ransomware groups escalate their tactics.
8 months ago
Kill Chain
Tenfold Spike: Chinese State Cyberattacks on Taiwan’s Energy Sector in 2025
In 2025, Taiwan experienced a dramatic surge in cyberattacks against its energy sector, with incidents increasing tenfold compared to the previous year, as reported by the country's National Security Bureau. Chinese nation-state groups, such as BlackTech, Flax Typhoon, Mustang Panda, APT41, and UNC3886, orchestrated targeted campaigns that leveraged hardware and software vulnerabilities, DDoS, social engineering, and supply-chain tactics. These attacks predominantly focused on industrial control systems and aimed to implant malware during key software upgrade windows, affecting vital infrastructure in petroleum, electricity, and natural gas domains and raising geopolitical and operational security concerns. This incident highlights the persistent threat of coordinated nation-state cyber activity against critical infrastructure, especially during politically sensitive periods. The tactics and techniques observed reflect global trends in the exploitation of operational technology and underscore the increasing need for advanced defense and cross-border intelligence sharing.
8 months ago
Kill Chain
Ransomware 2026: Inside the Surge of DDoS, Insiders, and Gig Worker Threats
In early 2026, ransomware groups rapidly adapted their extortion playbooks following a revenue decline, marked by a 47% year-over-year surge in attacks but falling ransom payments. Threat actors broadened tactics—reviving DDoS-for-hire within the Ransomware-as-a-Service (RaaS) model, ramping up recruitment of insiders (including targeting trusted employees and gig workers), and executing data theft via both technical and social attack vectors. Notably, attackers expanded beyond traditional Russian operators, evidencing global proliferation. These methods bypassed conventional defenses, with incidents tracked across multiple sectors and frequently resulting in significant data breaches, operational disruption, and reputational harm. The evolution of ransomware in 2026 highlights a rising urgency for enterprises to harden insider defenses, revisit DDoS mitigation, and validate physical security and third-party access. With attackers exploiting workforce instability, gig economy platforms, and hybrid extortion, a modernized, multi-layered security posture is now critical across all industries.
8 months ago
Kill Chain
Columbia Weather Systems MicroServer Critical Firmware Exploits Threaten US Critical Infrastructure
In January 2026, multiple severe vulnerabilities were disclosed in the Columbia Weather Systems MicroServer, impacting critical infrastructure sectors in the United States. Attackers could exploit these flaws—improper restriction of communication channels (CVE-2025-61939), cleartext storage of credentials (CVE-2025-64305), and an exposed webshell with unrestricted shell access (CVE-2025-66620)—to redirect secure connections to malicious devices, gain admin-level web access, and establish persistent shell access with rights to modify or exfiltrate sensitive data. The affected firmware versions allowed attackers with network or admin privileges to perform high-impact actions, risking both operational continuity and data confidentiality for organizations relying on these devices. This incident underscores the growing challenge to secure Internet of Things (IoT) and Industrial Control Systems (ICS), especially as attackers increasingly target insecure firmware, lateral movement vectors, and privileged machine access. Regulatory attention and attacker focus on supply-chain and device firmware attacks continue to intensify, heightening the urgency for proactive remediation and layered ICS defenses.
8 months ago
Kill Chain
Insider Threat Reality: US Cyber Pros Caught as BlackCat Ransomware Affiliates
In 2023, two U.S.-based cybersecurity professionals—formerly employed by major security firms—pleaded guilty to acting as affiliates for the ALPHV/BlackCat ransomware group. The individuals leveraged their insider knowledge and technical expertise to facilitate the deployment of the ransomware, compromising sensitive systems in targeted organizations. By exploiting weaknesses in internal security protocols and bypassing detection mechanisms, they assisted in the encryption of files and extortion of affected businesses, resulting in operational disruptions and significant reputational damage across multiple sectors. This incident highlights an escalating threat posed by insiders with privileged knowledge and skills, who collaborate with sophisticated ransomware groups like BlackCat. The convergence of advanced ransomware-as-a-service operations and trusted industry insiders signals a dangerous shift, amplifying calls for more robust zero trust strategies, stricter network segmentation, and improved insider threat monitoring.
8 months ago
Kill Chain
Russia-Aligned Group UAC-0184 Breaches Ukrainian Government via Viber Attack
In early 2025, the Russia-aligned cyber-espionage group UAC-0184 undertook a targeted campaign against Ukrainian military and government organizations. Leveraging the popular Viber messaging platform, the threat actors distributed malicious ZIP archives to infiltrate sensitive networks. Security researchers from the 360 Threat Intelligence Center noted that these operations demonstrated continued intelligence-gathering efforts, employing social engineering tactics and the abuse of trusted communication channels. The attack resulted in the unauthorized access and potential exposure of confidential government and defense information, further escalating the cyber hostilities related to the conflict in Ukraine. This incident highlights a growing trend in the weaponization of encrypted messaging apps for cyber-espionage, as nation-state actors increasingly exploit trusted consumer platforms to bypass traditional enterprise security controls. The breach underscores the urgency for robust east-west traffic monitoring, zero trust segmentation, and advanced detection capabilities across critical sectors.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports