Industry Category

Government Administration

Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.

2818 threat reports
Page 182 of 235

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless
Writing/Editing

Government Administration Threat Reports

Showing 21732184 / 2818 reports
CISA Flags OpenPLC ScadaBR XSS Flaw (CVE-2021-26829) as Actively Exploited in ICS Environments
Impact· low

CISA Flags OpenPLC ScadaBR XSS Flaw (CVE-2021-26829) as Actively Exploited in ICS Environments

In June 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2021-26829—a cross-site scripting (XSS) vulnerability affecting OpenPLC ScadaBR software—to its Known Exploited Vulnerabilities catalog following evidence of active exploitation. The flaw impacts both Windows and Linux versions of ScadaBR, a commonly used open-source SCADA platform. Attackers leveraged the XSS flaw to execute arbitrary scripts, posing significant risk to system integrity and exposing critical infrastructure operators to potential business disruption, data compromise, and malicious control of automation processes. This incident reflects the growing trend of adversaries targeting industrial control systems (ICS) via supply chain and application-layer vulnerabilities. With regulatory scrutiny rising and CISA actively tracking exploited flaws, securing OT and SCADA environments is critical to mitigate operational and safety risks posed by unpatched vulnerabilities.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
November 2025 Cybersecurity Review: Akira, Operation Endgame, and AI Data Exposure
Impact· medium

November 2025 Cybersecurity Review: Akira, Operation Endgame, and AI Data Exposure

In November 2025, the cybersecurity landscape was rocked by a surge of major incidents spanning data exposure at leading AI companies, a high-profile ransomware campaign by the Akira gang, and an unprecedented law enforcement operation targeting prolific malware families. Attackers leveraged advanced lateral movement and encryption bypass techniques, with Akira exfiltrating critical business data and setting new records for ransom hauls. Meanwhile, Operation Endgame—an international collaborative effort—dismantled several prominent malware botnets, arresting key operators and seizing digital infrastructure, all while organizations scrambled to contain threats and patch vulnerabilities across multi-cloud and hybrid environments. This period highlights a convergence of advanced extortion, data privacy, and large-scale coordinated response, reflecting escalating threat sophistication and the increasing pressure on organizations to meet evolving compliance and security demands.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AI-Fueled LLMs Put Advanced Attacks in Reach for Novice Hackers (2024)
Impact· medium

AI-Fueled LLMs Put Advanced Attacks in Reach for Novice Hackers (2024)

In early 2024, cybersecurity researchers observed a surge in the use of malicious, unrestricted large language models (LLMs) such as WormGPT 4 and KawaiiGPT. These AI-powered tools have been weaponized to generate sophisticated attack scripts—including ransomware encryptors and custom code for lateral movement—allowing even low-skilled threat actors to execute complex cyberattacks. Access to these malicious LLMs was facilitated via underground markets, democratizing advanced techniques and increasing the frequency and complexity of attacks targeting organizations across multiple sectors. This incident underscores a growing trend where AI-enabled cyber threats lower the barrier to entry for attackers. As malicious LLMs gain capabilities and proliferation increases, organizations face heightened risks from a new wave of adversaries and must adapt their defenses to address evolving, AI-driven tactics.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
French Football Federation Data Breach 2024: Identity Attack Exposes Admin Systems
Impact· high

French Football Federation Data Breach 2024: Identity Attack Exposes Admin Systems

In June 2024, the French Football Federation (FFF) disclosed a data breach following a targeted cyberattack where threat actors leveraged a compromised administrator account to access the Federation’s administrative management software. The attackers gained unauthorized entry to sensitive systems, exposing personal information of registered club personnel and potentially compromising confidential organizational data. The breach led to heightened security reviews, incident response engagement, and notification of impacted individuals in accordance with regulatory requirements. This incident illustrates the growing prevalence of identity-driven attacks against high-profile organizations, reinforcing the critical need for zero trust controls and robust access governance. As cyber threats opportunistically target sports associations and other public sector bodies, advanced protective measures and continuous monitoring are becoming essential to thwart exploitation.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(high)
I
Impact(high)
Read Report
Tomiris APT 2025: Abuse of Telegram, Discord & Multi-Language Toolkit in Advanced Government Attacks
Impact· low

Tomiris APT 2025: Abuse of Telegram, Discord & Multi-Language Toolkit in Advanced Government Attacks

In early 2025, the Tomiris APT group launched a sophisticated cyberespionage campaign targeting foreign ministries, intergovernmental organizations, and government entities across Russia and Central Asia. Using spear-phishing emails with password-protected malicious archives, Tomiris delivered a diverse toolkit of implants written in C/C++, Rust, Go, C#, and Python. Their malware leveraged public services like Telegram and Discord for command-and-control (C2), employed open-source frameworks such as Havoc and AdaptixC2, and enabled attackers to perform reconnaissance, maintain persistence, and exfiltrate sensitive data, while evading traditional network defenses by blending illicit traffic with legitimate channels. This incident highlights a clear evolution in APT tradecraft: rapid adoption of multi-language toolchains, creative lateral movement, and the abuse of popular cloud-based services for covert operations. With the continued rise of lawful-shadow C2 channels and open-source post-exploitation kits, organizations face heightened risks from identity-driven, stealthy attacks that challenge conventional segmentation and anomaly detection strategies.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(low)
Read Report
CVE-2021-26829: ScadaBR XSS Exploitation Prompts CISA Catalog Action
Impact· low

CVE-2021-26829: ScadaBR XSS Exploitation Prompts CISA Catalog Action

In November 2025, CISA added CVE-2021-26829, an OpenPLC ScadaBR cross-site scripting (XSS) vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog after observing active exploitation. Adversaries exploited a lack of proper input sanitization in ScadaBR—a widely used industrial automation software—to inject malicious scripts, enabling credential theft or unauthorized actions on affected systems. The vulnerability increases the risk of lateral movement within critical infrastructure and highlights the susceptibility of operational technology (OT) environments to common web-based attacks. Federal agencies are mandated to remediate such vulnerabilities, reflecting their high-risk nature and operational impact. This incident underscores a broader trend: threat actors are increasingly exploiting web application vulnerabilities in industrial and critical network environments. The addition to the KEV catalog reflects regulatory focus on timely remediation, as attacks targeting core OT platforms can cause serious operational disruption and regulatory exposure.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Bloody Wolf's NetSupport RAT Campaign Breaches Kyrgyzstan and Uzbekistan: 2025 Analysis
Impact· medium

Bloody Wolf's NetSupport RAT Campaign Breaches Kyrgyzstan and Uzbekistan: 2025 Analysis

In mid-2025, the threat actor known as Bloody Wolf launched a targeted cyber campaign against government and enterprise entities in Kyrgyzstan, later expanding its operations to Uzbekistan by October 2025. Utilizing sophisticated phishing lures, attackers delivered Java-based loaders that deployed the NetSupport Remote Access Trojan (RAT), allowing persistent access and potential data exfiltration. The campaign featured advanced evasion tactics, encrypted command-and-control traffic, and was attributed by Group-IB and local cybersecurity agencies. Affected organizations faced risks of unauthorized network access and potential compromise of sensitive information. This incident highlights ongoing regional cybercrime escalation, especially the trend of weaponizing legitimate tools like NetSupport RAT through creative malware loaders. With cross-border expansion and zero-day techniques, the event exemplifies how remote access trojans are reshaping threat landscapes and driving demand for advanced network and east-west traffic controls.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
AI Deepfake Fraud Strikes US Government Officials in 2024
Impact· high

AI Deepfake Fraud Strikes US Government Officials in 2024

In 2024, a surge of highly convincing AI-assisted fraud scams targeted prominent U.S. government officials and public figures, exploiting advanced voice and video synthesis technologies to impersonate them. Unknown threat actors used deepfake audio and video to contact senators, governors, and business leaders—at times successfully deceiving recipients into believing they were communicating with senior officials such as the White House Chief of Staff or the Secretary of State. This wave of sophisticated impersonation included fraudulent calls, texts, and deepfake media, causing reputational and operational risks, and prompting federal investigations as well as public warnings from affected parties. This series of attacks underscores the accelerating trend of criminals leveraging generative AI for social engineering and impersonation. The incident has provoked legislative response, highlighted by the AI Fraud Deterrence Act, driving new regulatory focus to combat emerging AI threats and mitigate associated risks to governments and the public.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Anthropic AI Breach: Chinese State-Sponsored Espionage Campaign Shakes Cybersecurity Landscape
Impact· low

Anthropic AI Breach: Chinese State-Sponsored Espionage Campaign Shakes Cybersecurity Landscape

In late 2024, Anthropic disclosed a sophisticated espionage campaign linked to Chinese state-sponsored actors who leveraged the Claude AI platform to automate and scale cyber-operations targeting at least 30 global organizations. Attackers reportedly used Claude to streamline reconnaissance and intrusion tasks, combining AI capabilities with human expertise to enhance operational stealth and impact. The U.S. House Homeland Security Committee responded by summoning Anthropic’s CEO and other tech leaders to testify about the security implications of AI-augmented tradecraft and the risks posed by pairing AI with emerging technologies like quantum computing. This incident underscores how state-sponsored groups are rapidly evolving, using commercially available AI to bypass defenses and accelerate cyber operations. The attack has triggered urgent calls for stronger safeguards, regulatory clarity on AI security, and cross-sector strategies to counter AI-enabled cyber threats.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Crisis24 Shuts Down CodeRED Emergency System Following Ransomware Breach
Impact· high

Crisis24 Shuts Down CodeRED Emergency System Following Ransomware Breach

In early June 2024, Crisis24 permanently shut down its OnSolve CodeRED emergency notification system after a ransomware attack severely damaged the platform's environment. The incident, attributed to the INC ransomware group, involved unauthorized access to and exfiltration of user data, including names, addresses, email addresses, phone numbers, and passwords. Forensic analysis indicated the attack was contained within the legacy CodeRED environment. The shutdown left dozens of municipalities and law enforcement agencies temporarily without emergency notification services, though the U.S. government's Emergency Alert System was unaffected. Crisis24 accelerated rollout of its new platform, conducted a security audit, and notified law enforcement. This breach underscores the increasing risk posed by ransomware groups targeting public safety infrastructure. With attackers leaking sensitive personal data and causing operational disruptions, organizations face mounting pressure to modernize legacy systems and enhance both incident response and segmentation controls in light of sophisticated, persistent threats.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Microsoft Hardens Entra ID Against Script Injection Attacks in 2026
Impact· low

Microsoft Hardens Entra ID Against Script Injection Attacks in 2026

In October 2026, Microsoft announced significant upgrades to the Entra ID authentication platform to address vulnerabilities exposed by script injection attacks targeting the sign-in process. Attackers had exploited weaknesses in the handling of external scripts within the authentication flow, enabling potential bypass of security controls and unauthorized access to user accounts. While no large-scale breaches were publicly disclosed, Microsoft proactively moved to deploy enhanced protections and harden the Entra ID authentication framework, limiting the exploitation window and strengthening controls. The business impact focused on the increased risk to user identity and the need for rapid security enhancements within core authentication infrastructure. This incident underscores the evolving threat landscape facing identity providers, with attackers increasingly leveraging advanced script injection and authentication bypass techniques. It highlights the urgent need for continuous improvement of identity and access management security controls, as threat actors seek novel vectors to compromise critical authentication flows across cloud and enterprise environments.

8 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Ransomware Attack Disrupts Multiple London Councils’ IT Systems in 2024
Impact· high

Ransomware Attack Disrupts Multiple London Councils’ IT Systems in 2024

In June 2024, the Royal Borough of Kensington and Chelsea (RBKC) and Westminster City Council experienced operational disruption following a ransomware cyberattack on their shared IT provider, Westminster City Council Integrated IT (WCCIT). Attackers infiltrated municipal digital infrastructure, encrypted data, and impacted critical online services such as resident portals and payment processing. Public-facing platforms were taken offline as a precaution, and council operations shifted to manual workarounds, affecting both internal processes and citizen-facing services. The incident underscores the vulnerabilities within local government supply chains and highlights the ramifications of targeting shared service models in the public sector. This attack is a sobering reminder of the increasing incidence of ransomware campaigns targeting public entities in the UK and globally. With local authorities managing sensitive citizen data and critical services, the urgency for robust cybersecurity controls and incident response processes has never been more acute.

8 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports