Government Administration
Breach intelligence, attack campaigns, and threat reports targeting the Government Administration sector.
Explore Other Sectors
Government Administration Threat Reports
Unpacking the Qilin Ransomware Attack: Lessons from a ScreenConnect Breach
In early 2024, a Qilin ransomware attack demonstrated the risks of third-party remote access tools when threat actors gained entry via ScreenConnect to a corporate endpoint. Leveraging this precarious foothold, attackers navigated the environment, launched failed infostealer payloads, then successfully executed ransomware—all while evading detection due to severely limited log visibility. Despite these blind spots, incident responders from Huntress used endpoint forensics and cross-correlation of minimal artifacts to reconstruct the entire attack path, including lateral movement attempts and the precise ransomware execution timeline. This incident highlights the growing sophistication of ransomware actors using remote IT management software for covert entry. As RMM tool vulnerabilities and minimal logging become more prevalent, organizations face heightened risk and pressure to implement deeper east-west threat detection and robust zero trust network segmentation.
8 months ago
Kill Chain
WhatsApp’s 2024 API Flaw: 3.5 Billion Accounts Exposed via Automated Scraping
In early 2024, a significant data exposure incident affected WhatsApp when researchers discovered and exploited a vulnerability in the platform's contact-discovery API. The API lacked effective rate limiting and permitted mass enumeration of registered user accounts by automating queries, enabling adversaries to harvest data on approximately 3.5 billion mobile phone numbers and associated details. No evidence suggests the involvement of a deliberate threat actor beyond security researchers, but the scale and scope highlight serious privacy and operational risks for both users and WhatsApp’s business integrity. The incident underscores ongoing risks for messaging applications leveraging public-facing APIs without stringent access and abuse controls. This breach is highly relevant as API abuse and large-scale account enumeration techniques are increasingly exploited by attackers seeking personal data. Regulatory scrutiny is poised to intensify, and similar flaws are being reported across numerous communications platforms, making robust API security and anomaly detection critical in today’s threat landscape.
8 months ago
Kill Chain
CISA Flags Critical Oracle Identity Manager Zero-Day as Actively Exploited
In June 2025, a critical zero-day vulnerability (CVE-2025-61757) affecting Oracle Identity Manager was added to CISA’s Known Exploited Vulnerabilities catalog, following credible reports of active exploitation. Attackers leveraged a missing authentication flaw in a critical function, allowing remote, pre-authenticated access and full compromise of affected systems. Organizations using Oracle Identity Manager faced a risk of unauthorized access, credential theft, and lateral movement, with potential for widespread service disruption and data exfiltration across enterprise networks. Remediation required rapid deployment of patches and security controls to prevent further breaches. This incident underscores the rising impact of identity-driven attack vectors targeting core authentication systems, with adversaries increasingly exploiting zero-day flaws in widely-used identity platforms. The exploitation highlights an urgent need for strengthened identity protection, patch management, and zero-trust segmentation as attackers target the intersection of critical infrastructure and identity orchestration.
8 months ago
Kill Chain
Matrix Push C2 Phishing Exposes Fileless Browser Attacks in 2025
In November 2025, a sophisticated phishing campaign was uncovered utilizing a novel command-and-control (C2) platform called Matrix Push C2. The threat actors exploited browser push notifications, fake alerts, and fileless redirection to lure users across multiple operating systems into interacting with malicious links. Researchers observed that the campaign delivered phishing payloads without traditional downloads, thereby evading many endpoint defenses and expanding its cross-platform reach. Impacted organizations reported heightened risks of credential theft, business email compromise, and data exfiltration stemming from the hard-to-detect, browser-native behavior of Matrix Push C2. This incident highlights the escalating threat of fileless attacks and creative social engineering, particularly as businesses increasingly rely on browser-based workflows. The abuse of browser notifications as a phishing vector presents a growing challenge for security teams and underscores the importance of proactive browser and endpoint defenses.
8 months ago
Kill Chain
APT31 Orchestrates Stealthy Cloud-Based Attack on Russian IT Firms (2024–2025)
Between 2024 and 2025, the advanced persistent threat group APT31, linked to China, conducted a series of covert cyberattacks against Russia’s IT sector, specifically targeting firms involved in government contracting. Leveraging cloud services and encrypted traffic, the attackers infiltrated networks while remaining undetected for long periods. APT31 employed sophisticated lateral movement, abuse of multicloud visibility gaps, and zero trust segmentation bypasses, resulting in the exfiltration of sensitive data and potential compromise of government-integrator communication flows. This incident reflects growing tensions and evolving threat tactics in state-sponsored cyberespionage, where cloud infrastructure, stealthy east-west movements, and advanced evasion are exploited. The attack underscores the critical need for enforced segmentation, robust cloud-native security, and proactive anomaly detection to defend against advanced persistent threats targeting the IT supply chain.
8 months ago
Kill Chain
LINE Messaging Bugs Expose Millions to Asian Cyber Espionage in 2024
In June 2024, security researchers disclosed several critical vulnerabilities in the LINE messaging app, widely used across Asia, arising from its use of a proprietary and flawed cryptographic protocol. The bugs enable attackers to intercept and replay message traffic, impersonate users, and siphon sensitive chat data, despite the app's claims of end-to-end encryption. No specific threat actor has been confirmed, but the flaws create opportunities for state-sponsored espionage and criminal data compromise. The weaknesses persist in both in-app and network-level communication, putting millions of users’ private conversations at risk. This incident highlights the dangers of custom security implementations and is of urgent concern given LINE’s importance in business and personal use across Asia. With attackers increasingly targeting messaging platforms and governments ramping up regulatory scrutiny around privacy and secure communications, organizations must prioritize rigorous security architecture and compliance.
8 months ago
Kill Chain
Hacker Exposes 2.3TB in FS Italiane / Almaviva Supply Chain Breach (2024)
In June 2024, a hacker reportedly breached the systems of Almaviva, an Italian IT provider serving FS Italiane Group, the nation’s railway operator. The attacker claimed to have exfiltrated 2.3TB of sensitive corporate data—including documents, contracts, financial information, and communications—garnered by exploiting weaknesses in the supplier’s defenses. Although FS Italiane’s operational technology was not directly compromised, the breach of Almaviva’s infrastructure exposed highly confidential client and business data, raising concerns about third-party risks and data privacy for an array of Italian public sector organizations. This incident highlights a worrying trend of attackers targeting IT services providers as a conduit for large-scale data breaches against critical infrastructure operators. With supply chain vulnerabilities on the rise, organizations must urgently reassess their vendor risk management and network segmentation strategies to prevent similar cascading impacts.
8 months ago
Kill Chain
Scattered Spider Strikes: 2024 Transport for London Cyber Breach
In August 2024, Transport for London (TfL), the body responsible for the UK's capital city transit system, suffered a major cyber incident allegedly orchestrated by members of the Scattered Spider cybercriminal group. Attackers exploited weaknesses in TfL's digital infrastructure to gain unauthorized access, compromising sensitive customer data and disrupting critical services. The breach, which resulted in millions of pounds in damages and regulatory scrutiny, underscored the growing threat that organized cybercriminal gangs pose to public-sector organizations. Two British teenagers have since been arrested and charged, though they have pleaded not guilty in court. This incident highlights the increasing trend of skilled threat actors leveraging sophisticated tactics—such as social engineering and lateral movement—to target essential services. Heightened regulatory pressure and public concern reinforce the urgent need for robust cybersecurity measures across critical infrastructure sectors.
8 months ago
Kill Chain
ToddyCat APT: How a Persistent Attacker Breached Outlook and Microsoft 365 Email in 2024
Between mid-2024 and early 2025, the ToddyCat advanced persistent threat (APT) group executed a sophisticated campaign targeting organizations' internal infrastructures to covertly access business email. Initially leveraging a new PowerShell variant of their TomBerBil tool to extract credentials, cookies, and encryption keys from browsers via SMB on privileged hosts, the group also introduced additional tools—TCSectorCopy and XstReader—to capture locked Outlook OST files and exfiltrate their contents. When detection increased, ToddyCat shifted to harvesting OAuth 2.0 tokens for Microsoft 365 mail through memory dumping, enhancing their ability to bypass on-host monitoring and access cloud emails externally. This campaign resulted in extensive compromise of sensitive correspondence, credentials, and lateral movement across impacted domains. This incident underscores the rapidly evolving tactics of nation-state groups to overcome modern defenses, highlighting trends in cross-cloud compromise, credential harvesting, and exploitation of endpoint-to-cloud trust boundaries. ToddyCat's use of both system-level and identity-driven attacks mirrors the increasing prevalence of multifaceted cyber threat techniques.
8 months ago
Kill Chain
Grafana 2025: Critical Admin Spoofing Flaw Demands Immediate Response
In June 2025, Grafana Labs disclosed a critical security vulnerability (CVE-2025-41115) affecting its Enterprise platform, enabling attackers to register new users and assign them administrator privileges or escalate existing privileges through crafted requests. This flaw made it possible for unauthorized actors to gain full control over instances, potentially compromising sensitive data dashboards and associated integrations. Grafana responded by releasing urgent patches, issuing advisories, and recommending immediate action to all Enterprise customers to prevent exploitation in production environments. This incident is particularly notable given the increasing threat posed by privilege escalation vulnerabilities in widely deployed SaaS and cloud-native products. Enterprises leveraging Grafana or other observability platforms must remain vigilant as attackers increasingly target misconfigurations and logic flaws to bypass identity-based controls and gain elevated access.
8 months ago
Kill Chain
CrowdStrike Insider Breach: How Scattered Lapsus$ Exploited Trusted Access in 2024
In early 2024, cybersecurity firm CrowdStrike identified an insider threat after discovering that an employee had shared screenshots of internal systems with external threat actors. The images, which were later leaked on Telegram by the Scattered Lapsus$ Hunters group, exposed sensitive details about CrowdStrike’s infrastructure and internal processes. CrowdStrike swiftly conducted an internal investigation, isolated the breach, and collaborated with law enforcement to mitigate potential risks. The incident highlights the growing challenge organizations face in protecting against trusted insiders acting maliciously or under external influence. This breach is particularly relevant given the increasing frequency of insider-driven attacks and the adoption of social engineering by advanced threat groups to bypass traditional perimeter defenses. The incident underscores the need for organizations to enhance their monitoring of internal activities and emphasize zero trust models.
8 months ago
Kill Chain
SolarWinds 2020: Unpacking the Supply Chain Breach and SEC Fallout
In late 2020, SolarWinds experienced a massive supply chain attack when advanced threat actors compromised the company's Orion software update mechanism. Attackers, attributed to Russia’s APT29 (Cozy Bear), injected malicious code into official software updates, giving them covert backdoor access to the systems of approximately 18,000 SolarWinds customers, including U.S. government agencies and Fortune 500 firms. The attack vectors enabled months of undetected lateral movement, extensive data exfiltration, and widespread compromise of critical infrastructure and networks. The breach also triggered broad regulatory and legal scrutiny, including an SEC lawsuit alleging inadequate disclosures and misrepresentation of cybersecurity practices by SolarWinds and top executives. The SolarWinds attack remains highly relevant as it catalyzed global focus on supply chain security, regulatory enforcement, and the rise of sophisticated software supply chain threats. Its legacy informs today’s cyber hygiene mandates and the zero trust adoption trending across both public and private sectors.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports